ShinyHunters renews attacks on Oracle's PeopleSoft, Google reports

Summary

On September 25, Google's cybersecurity unit reported that the hacking group ShinyHunters has intensified its exploitation of a security flaw in Oracle's PeopleSoft software, following a period of defenses implemented after earlier attacks. ShinyHunters, which has been linked to several significant data breaches, is believed to have adapted its methods to target organizations that had implemented web application firewalls but failed to apply Oracle's patch for the vulnerability. This resurgence in attacks has raised concerns among institutions relying on PeopleSoft, impacting various sectors including higher education, technology, healthcare, agriculture, transportation, and government. Law enforcement is currently investigating claims that ShinyHunters accessed sensitive FBI personnel data through this vulnerability.

Tokens

$ORCL$GOOGL

Analysis

Google: Google, through its Mandiant cybersecurity unit, delivers threat intelligence reporting and analysis on evolving cyber threats. Mandiant released details on ShinyHunters' renewed attacks on Oracle PeopleSoft, noting the group's adaptation to web application firewall rules without full patching. The unit is part of Alphabet and focuses on identifying active exploitation campaigns. Oracle: Oracle Corporation develops and provides enterprise software solutions, including the PeopleSoft platform used for human resources and other critical business functions. The company's software has been targeted in recent attacks by ShinyHunters exploiting a known vulnerability that persisted despite published defensive guidance. Oracle issued a patch for the flaw following earlier incidents in May and June. ShinyHunters: ShinyHunters is a cybercriminal hacking group known for claiming responsibility for large-scale data breaches targeting organizations across sectors. The group has renewed mass exploitation of a security flaw in Oracle PeopleSoft software after adapting to prior defensive measures. In the reported incidents, ShinyHunters claimed access to FBI personnel data through the same vulnerability. Federal Bureau of Investigation: The Federal Bureau of Investigation serves as the primary federal law enforcement and domestic intelligence agency in the United States, handling investigations into cyber incidents and data breaches. The agency stated it is aggressively investigating ShinyHunters' claimed access to personnel data via the PeopleSoft vulnerability. The FBI has not had its claim corroborated in public reporting. Sector Impact: The renewed exploitation has affected organizations across higher education, technology, healthcare, agriculture, transportation, and government sectors. Threat Adaptation: Attackers like ShinyHunters have demonstrated the ability to modify tactics in response to published defensive recommendations from prior campaigns. Investigation Status: Law enforcement is actively pursuing claims of unauthorized access to sensitive federal personnel records through enterprise software vulnerabilities.

Categories

tech
View Original Tweet