Mandiant Reports ShinyHunters Renews Global PeopleSoft Attacks
Google’s Mandiant says the ShinyHunters hacking group has resumed mass exploitation of a vulnerability in Oracle PeopleSoft, adapting its tactics to target organizations that added web application firewall rules but did not install Oracle’s security update. The latest campaign affected dozens of systems worldwide across sectors including higher education, technology, health care, agriculture, transportation and government; an earlier wave mainly hit universities. ShinyHunters has claimed it used the flaw to access FBI data, and reports say the group disclosed names of personnel in sensitive units and obtained medical and psychiatric records. The FBI says it is investigating the reported breach, but the claim of access to its data has not been independently verified, and Oracle did not comment.
Where do you stand?
How it spread




