Google’s cybersecurity unit Mandiant says the ShinyHunters hacking group has resumed mass exploitation of a security vulnerability in Oracle’s PeopleSoft software after adapting to defenses introduced following attacks earlier this year.
Mandiant disclosed the renewed activity in a threat intelligence report on Friday, just days after ShinyHunters claimed it had stolen sensitive data belonging to FBI personnel. Reuters has not independently verified the hackers’ claim about the FBI data.
According to Mandiant, ShinyHunters previously exploited a vulnerability in Oracle PeopleSoft between May 27 and June 9, with universities among the main targets. The attackers have now changed their approach to get around security measures introduced after those incidents.
Mandiant said the latest attacks targeted organizations that had deployed web application firewall rules based on security guidance released after the earlier campaign but had not installed an Oracle update designed to fix the vulnerability.
The renewed campaign has reportedly affected dozens of systems around the world across a wide range of industries. The victims identified by Mandiant’s analysis include organizations in higher education, technology, healthcare, agriculture, transportation and government.
The activity is raising concerns for organizations that depend on PeopleSoft for human resources and other critical business operations. The attacks also highlight the risk of relying on defensive measures such as firewall rules without applying the underlying software security update.
ShinyHunters has also claimed that it used a PeopleSoft vulnerability to access FBI data. Reuters has not been able to independently confirm that claim, while the FBI said on Wednesday that it was aggressively investigating the reported breach.
Reuters previously reported that data allegedly exposed by the hackers included the names of personnel working in sensitive FBI units as well as medical and psychiatric records.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Oracle did not respond to requests for comment on the latest reports.
ShinyHunters Resumes Mass Exploitation of Oracle PeopleSoft Flaw



