ShinyHunters Hackers Resume Exploiting Oracle's PeopleSoft Security Flaw
Hackers from ShinyHunters have resumed exploiting a security flaw in Oracle's PeopleSoft software, according to Google's cybersecurity unit.
The attacks, which began on May 27 and continued through June 9, mainly targeted universities. However, the hackers adapted to defensive guidance published after the initial attacks by targeting organizations that implemented web application firewall rules but did not apply an update to patch the vulnerability.
Mandiant reported that the latest attack affected dozens of systems globally in various sectors, including higher education, technology, healthcare, agriculture, transportation, and government. ShinyHunters claimed responsibility for stealing FBI personnel data using a vulnerability in PeopleSoft.
The Federal Bureau of Investigation is aggressively investigating the reported breach. Oracle did not respond to requests for comment. The evolving nature of the attack raises concerns about the vulnerability of well-resourced institutions that rely on PeopleSoft for critical functions.