ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says
ORCL•Google's cybersecurity unit said ShinyHunters renewed mass exploitation of a flaw in Oracle PeopleSoft after adapting to defenses introduced following attacks in May and June. The latest attacks affected dozens of systems globally across several sectors.
1. Attacks expanded
Mandiant, Google's cybersecurity unit, said ShinyHunters renewed mass exploitation of a PeopleSoft security flaw after adapting to defensive guidance issued following attacks from May 27 through June 9, which mainly affected universities. The hackers targeted organizations that had implemented web application firewall rules but had not applied Oracle's patch.
2. Victims and FBI claim
Mandiant said the latest attacks affected dozens of systems globally in higher education, technology, healthcare, agriculture, transportation and government, without identifying victims. ShinyHunters has claimed it accessed FBI data using the vulnerability; the claim has not been corroborated. The FBI said it was “aggressively investigating” the reported breach.




