$ 44.79 € 50.98 zł 11.66
+11° Kyiv +11° Warsaw +16° Washington

ShinyHunters resumes mass exploitation of Oracle PeopleSoft vulnerability — Channel NewsAsia

Lev Shevtsov 26 September 2026 05:16
ShinyHunters resumes mass exploitation of Oracle PeopleSoft vulnerability — Channel NewsAsia

In Singapore, Channel NewsAsia reported that Google’s Mandiant cybersecurity unit had detected ShinyHunters resuming the “mass exploitation” of a vulnerability in Oracle PeopleSoft enterprise software. According to Mandiant, the attackers bypassed protective measures introduced after the summer attacks.

Attacks on dozens of systems

Mandiant said that ShinyHunters exploited a vulnerability in PeopleSoft during attacks from May 27 to June 9. At that time, the attacks mainly affected universities.

After protection guidance was published, the hackers changed their approach. Their targets were organizations that had configured web application firewall rules but had not installed the Oracle update released to address the vulnerability.

More current news is available on the UA.News Telegram channel Telegram.

According to Mandiant’s assessment, the latest attack affected dozens of systems in various countries. The organizations involved operate in higher education, technology, healthcare, agriculture, transport and public administration. PeopleSoft is used, among other things, for human resources and other critical functions.

Claim about FBI data

ShinyHunters said it had gained access to US Federal Bureau of Investigation data through a vulnerability in PeopleSoft. Reuters could not independently verify the claim. The FBI said on Wednesday that it was “actively investigating” reports of a possible breach.

Reuters previously reported that the group disclosed the names of FBI employees working in sensitive units and also obtained medical and psychiatric records. Oracle did not respond to requests for comment. The Mandiant report was released several days after ShinyHunters’ claims of access to FBI data.

Read us on
Download our app