ShinyHunters Exploits Oracle PeopleSoft Vulnerability for Second Time
Google's cybersecurity unit has announced that hacking group ShinyHunters has resumed its attacks on Oracle's PeopleSoft software, exploiting a security flaw to gain access to sensitive data. This is not an isolated incident, as ShinyHunters had previously claimed responsibility for several major data breaches, including one targeting the FBI.
The latest attack, which began on September 25, has affected dozens of systems globally across various sectors such as higher education, technology, healthcare, agriculture, transportation, and government. Mandiant, Google's cybersecurity unit, reported that ShinyHunters adapted to defensive guidance published after the initial attacks in May and June by targeting organizations that implemented web application firewall rules but failed to apply an update issued by Oracle to patch the vulnerability.
The FBI has confirmed that it is 'aggressively investigating' the breach, which exposed sensitive data including personnel records. The exact nature of the attack is still unclear, but experts warn that even well-resourced institutions are vulnerable to such attacks if they fail to implement robust security measures.