Story

ShinyHunters Hackers Renew Attacks on Oracle PeopleSoft Flaw, Google's Mandiant Reports

ENTHMSVIIDZHZH-TWJAKOHI
Sep 26, 20262 min read
ShinyHunters Hackers Renew Attacks on Oracle PeopleSoft Flaw, Google's Mandiant Reports

Summary

Google's cybersecurity unit, Mandiant, reports that the hacking group ShinyHunters has resumed and adapted its exploitation of a known vulnerability in Oracle's PeopleSoft enterprise software, targeting organizations that failed to apply a full security patch.

Text size
Background

The hacking group ShinyHunters has renewed a “mass exploitation” campaign targeting a security flaw in Oracle’s PeopleSoft enterprise software, according to a threat intelligence report released Friday by Google’s cybersecurity unit, Mandiant.

Evolving Attack Methods

Mandiant stated that the hackers have adapted their tactics following an initial wave of attacks between May 27 and June 9, which primarily affected universities. The group is now targeting organizations that implemented defensive web application firewall (WAF) rules but did not apply the official software update Oracle issued to patch the vulnerability.

This evolution in strategy highlights a significant risk for institutions relying on partial mitigation measures instead of comprehensive patching. According to Mandiant, the latest attacks have impacted dozens of systems globally across a wide range of sectors, including:

  • Higher education
  • Technology
  • Healthcare
  • Agriculture
  • Transportation
  • Government

Connection to High-Profile Breaches

Sample IUX Markets – In-articleAd

The report comes just days after ShinyHunters claimed responsibility for a major data breach at the U.S. Federal Bureau of Investigation (FBI), allegedly accessing personnel data by exploiting a vulnerability in PeopleSoft. The FBI confirmed in a statement on Wednesday that it was "aggressively investigating" the reported breach.

Reuters, which first reported on the FBI breach claim, has not been able to independently corroborate that the PeopleSoft flaw was the entry point. The renewed attacks are likely to heighten concerns for the many organizations that use the popular Oracle software for human resources and other critical business functions.

Market and Security Implications

The ongoing exploitation of a known and patched vulnerability underscores the critical importance of timely software updates for corporate and government entities. Relying on intermediary defenses like firewalls can provide a false sense of security, as sophisticated actors can often find ways to circumvent them.

Oracle (NYSE: ORCL) did not respond to requests for comment on the matter, according to Reuters. The situation serves as a stark reminder to investors and IT security professionals of the persistent and adaptive nature of cyber threats targeting widely used enterprise software.

Read next

More on Stocks
Back to latest news

LATEST