Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

ShinyHunters resumes large-scale exploitation of Oracle PeopleSoft flaw

Google’s security team reports that the ShinyHunters group has resumed mass attacks on Oracle’s PeopleSoft software, targeting dozens of systems worldwide after evading earlier defenses.

Google’s cybersecurity division announced that the hacker collective ShinyHunters has launched a fresh wave of mass exploitation against Oracle’s PeopleSoft enterprise software. The group modified its approach to sidestep newly published defensive guidance, targeting entities that had implemented firewall rules but had not applied Oracle’s recent security update. The latest intrusion has impacted dozens of systems globally, spanning sectors such as higher education, tech, health care, agriculture, transport and government agencies.

Earlier in the year the same vulnerability affected universities between late May and early June. ShinyHunters has previously asserted that it stole data from FBI personnel, prompting the FBI to state it is aggressively investigating the breach. Oracle has not responded to requests for comment.

Why it matters

The renewed PeopleSoft attacks show that even well-protected institutions remain vulnerable to sophisticated cyber-crime groups.

How this story developed

  1. Sep 22 Hackers calling themselves ShinyHunters claim breach of FBI employee database
  2. Sep 26 The FBI announced an aggressive investigation into the alleged breach.

In this story

PeopleSoft vulnerabilityShinyHunterscyber exploitationweb application firewallOracle patchglobal attackFBI data breachhigher educationtechnology sector
Get the beta ↗