Mandiant reports ShinyHunters' renewed exploitation of PeopleSoft flaw

Reuters

Google's Mandiant said ShinyHunters resumed mass exploitation of a flaw in Oracle PeopleSoft, affecting dozens of systems worldwide. The hackers targeted organizations that had added web application firewall rules but had not installed Oracle's security update, the report said.

Mandiant said the first wave exploited the bug from May 27 to June 9 and mainly affected universities. The renewed attacks reached systems in higher education, technology, health care, agriculture, transportation and government.

ShinyHunters has claimed it accessed FBI data through the PeopleSoft vulnerability, but Reuters has not corroborated the claim. The FBI said Wednesday it was “aggressively investigating” the reported breach. Reuters previously reported that the group exposed names of personnel in sensitive FBI units and acquired medical and psychiatric records.

#ShinyHunters-PeopleSoft-attacks #Oracle-PeopleSoft-vulnerability
Share