ShinyHunters Exploits Oracle's PeopleSoft Vulnerability Again
ShinyHunters, a hacking group, has resumed its attacks on Oracle's PeopleSoft software, exploiting a previously patched vulnerability. The attacks, which began in May and targeted universities, have now expanded to various sectors including higher education, technology, healthcare, agriculture, transportation, and government.
The hackers adapted their tactics after the initial attacks were thwarted by defensive guidance published by Oracle. ShinyHunters has claimed responsibility for several major data breaches, including one that allegedly compromised FBI personnel data.
Mandiant, a cybersecurity unit of Alphabet's Google, issued a threat intelligence report warning organizations relying on PeopleSoft to be vigilant and apply the necessary updates to prevent further attacks.