ESPN DeportesQué sabemos de los cargos contra Man CityPunchObi, Momodu condemn El-Rufai’s prolonged detentionDaily MaverickRETIRE IN STYLE: Over 60 and going places — how to see the world without roughing itThe Jerusalem PostUS investigating how sensitive F-35 parts diverted to Hong Kong ended up in China's hands - reportInquirerGroups to DOE chief: Quit over Visayas power woesESPNNBA Rank's hottest hot-button topics -- and what league execs think about the three-player battle for No. 1한겨레다이빙 김나현·문나윤, 여자 싱크로 10m 동메달…한국 역사상 첫 메달CNN TürkHAFTA SONU HAVA DURUMU NASIL OLACAK? 26-27 Eylül 2026 Yağışlar Devam Edecek mi? MGM Türkiye Hafta Sonu Hava DurumuSCMP ChinaChina’s first lady Peng Liyuan shines during Xi-Trump summit: everything you missedRapplerOpenAI works to understand full scope of agent activity as user data leak emergesn-tvWieduwilts Woche: Was in den Landtagen passiert ist, blüht ganz DeutschlandNew Straits TimesOpenAI AI agents go rogue, post 53 user images online
The Daily Newsstand · Free, Always
Saturday, September 26, 2026

ShinyHunters hackers expanded attacks on Oracle's PeopleSoft, Google says

Translate

Sept 25 : Google's cybersecurity unit said on Friday that hacking group ShinyHunters has renewed "mass exploitation" of a security flaw in Oracle's PeopleSoft software, after skirting defenses put up following attacks in the summer.

Mandiant made the announcement in a threat intelligence report released days after ShinyHunters, which has claimed responsibility for several major data breaches, said it had stolen FBI personnel data.

The evolving nature of the attack is likely to ring alarm bells at organizations that rely on PeopleSoft for human resources and other critical functions, and heighten concerns about the vulnerability of even well-resourced institutions.

The unit of Alphabet's Google said ShinyHunters exploited a bug in Oracle's PeopleSoft enterprise software in attacks from May 27 through June 9 that mainly affected universities.

Mandiant said the hackers adapted to defensive guidance published after the May-June attacks and targeted organizations that implemented web application firewall rules but did not apply an update that Oracle issued to patch the vulnerability.

It said, without identifying victims, that the latest attack affected dozens of systems globally in sectors as varied as higher education, technology, healthcare, agriculture, transportation and government.

ShinyHunters has said it accessed FBI data using a vulnerability in PeopleSoft. Reuters has not been able to corroborate the claim. Oracle did not respond to requests for comment.

In a statement issued Wednesday, the Federal Bureau of Investigation said it was "aggressively investigating" the reported breach.

ShinyHunters exposed the names of personnel working in sensitive FBI units and acquired medical and psychiatric records, Reuters previously reported.

View the original on Channel News Asia →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.