The Jerusalem PostTwo years after Hassan Nasrallah's assassination in Beirut, Hezbollah is still trying to rebuildESPNThere's a palpable sense of excitement surrounding the USMNT's young guns한겨레미국으로 공 넘어간 대미 투자, 닷새째 발표 없어…산업부 “한·미 협의는 완료”Inquirer18 dengue deaths reported in Camarines SurCNN TürkSON DAKİKA... Fon soruşturmasında yeni gözaltıХабрЗачем модели делать больно?SözcüKanada’da helikopter faciası: Kalkıştan kısa süre sonra düştü, kimse kurtulamadıSky TG24Pagine, la rassegna stampa di Sky TG24 del 27 settembreThe Straits TimesSingapore’s new Primary 1 rules: Who lives around the 12 schools getting a wider catchment?Rappler[Tech Thoughts] How bad actors weaponize copyright to silence journalism onlineNU.nlUniversiteit was nalatig rond veiligheidsmaatregelen bij toespraak Charlie KirkRolling Stone‘SNL’: Watch Katseye Perform ‘Animal,’ ‘Hootie Frutti’
The Daily Newsstand · Free, Always
Sunday, September 27, 2026

ShinyHunters hackers expanded attacks on Oracle’s PeopleSoft, Google says

Translate

On the pretext of taking the order and issuing bill, stores obtain personal details of consumers and retain it, and the said data is prone to leakage or hacking. (File Photo)

Google’s cybersecurity unit said on Friday that hacking group ShinyHunters has renewed “mass exploitation” of a security flaw in Oracle’s PeopleSoft software, after skirting defenses put up following attacks in the summer.

Mandiant made the announcement in a threat intelligence report released days after ShinyHunters, which has claimed responsibility for several major ⁠data ​breaches, said it had stolen FBI personnel data.

The evolving nature of the attack is likely to ring alarm bells at organizations that rely on PeopleSoft for ​human resources and ​other critical functions, and heighten ⁠concerns about the vulnerability of even well-resourced institutions.

The unit of Alphabet’s Google said ShinyHunters exploited ‌a bug in Oracle’s PeopleSoft enterprise software in attacks from May 27 through June 9 that mainly affected universities.

Mandiant said the hackers adapted to defensive guidance published after the May-June attacks and targeted organizations that implemented web application firewall rules ⁠but did not apply ⁠an update that Oracle issued to patch the vulnerability.

It said, without identifying ⁠victims, ‌that the latest attack affected dozens of ​systems globally in sectors as ‌varied as higher education, technology, healthcare, agriculture, transportation and government.

ShinyHunters has said it accessed FBI data ‌using a vulnerability in ​PeopleSoft. ​Reuters has ​not been able to corroborate the claim. Oracle did not respond to requests ​for comment.

Story continues below this ad

In a statement issued Wednesday, the ⁠Federal Bureau of Investigation said it was “aggressively investigating” the reported breach.

ShinyHunters exposed the names of personnel working in sensitive ‌FBI ⁠units and acquired medical and psychiatric records, Reuters previously reported.

View the original on The Indian Express →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.