Back Mezha Oracle warns customers after ShinyHunters exploited PeopleSoft vulnerability and exposed ...
A mass exploitation campaign by the ShinyHunters group has targeted PeopleSoft servers, prompting Oracle to urge customers to implement mitigations while a patch is developed.
As highlighted by Techcrunch
Oracle warned its corporate clients a critical vulnerability in the PeopleSoft software, used for payroll and HR management, a day after a cybercriminal group claimed responsibility for exploiting the flaw in a mass hacking campaign.
The company published a security advisory on Thursday after the ShinyHunters group claimed it had breached more than 100 organizations applying PeopleSoft servers.
Mandiant, Google’s security unit that investigates cyberattacks, warned in a blog that the new Oracle vulnerability is the same flaw used by the ShinyHunters group in its campaign against PeopleSoft customers.
Oracle said that at the time of publication a patch for this vulnerability had not yet been released; the flaw could be exploited over the Internet without authentication, including without a password.
The company advised customers who use PeopleSoft to implement precautions to reduce the risk of exploitation.
“While several organizations managed to block activity or fix vulnerabilities, others were compromised, resulting in stolen data being posted on the ShinyHunters data-leak site.”
On Wednesday a representative from the ShinyHunters group said that the breaches occurred due to an unpatched vulnerability on PeopleSoft servers. The attackers claim they stole “hundreds of thousands of student records” containing data such as full name, address, phone, email address, date of birth, gender, ethnicity, enrollment status, GPA, major, and student number across all campuses.
PeopleSoft and its customers have become the latest victims in a long-running series of breach campaigns where the ShinyHunters group targets organizations using the same vulnerable version of software.
Over the past year the group has targeted several companies using Salesforce and Gainsight, as well as educational technology providers and other vendors.
After hackers discover a vulnerability and target companies, they attempt to steal corporate or client data and threaten to publish it if victims do not pay a ransom.
Earlier this year, the educational technology company Instructure said it paid hackers after two intrusions into its systems. As part of the ShinyHunters campaign, the attackers also impersonated login pages for several educational institutions using Instructure’s Canvas portal.
Oracle is currently holding off on releasing patches, while experts advise monitoring for updates and applying the recommended security measures to reduce risks.
This wave of incidents underscores the need for rapid system updates and strengthened defense for organizations using the same solutions.
Don’t miss other news:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
