Itpro FBI Breached via Unpatched Oracle Software Vulnerability
Article Content
- •FBI breach attributed to unpatched Oracle PeopleSoft vulnerability (CVE-2026-35273).
- •ShinyHunters exploited the vulnerability after a three-month delay in applying the patch.
- •Sensitive employee data, including PII, potentially exposed to malicious actors.
The FBI confirmed a breach by the ShinyHunters ransomware group, which exploited a critical vulnerability (CVE-2026-35273) in Oracle's PeopleSoft software. The vulnerability allowed unauthenticated remote code execution, enabling attackers to access sensitive employee data and operational systems. ShinyHunters conducted an automated scan to identify vulnerable systems, targeting the FBI's recruitment portal, FBIjobs.gov, which had not received a critical patch for three months. The breach potentially exposed personal identifiable information (PII) of thousands of FBI employees, including sensitive operational details. The FBI is currently investigating the breach and assessing the extent of the data compromised. Experts warn that the stolen data could have serious real-world implications, especially if sold to malicious actors.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track ShinyHunters, European Commission and CVE-2026-35273 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI Infrastructure Under Siege: Session Hijacking and Exploits Surge Recent cybersecurity incidents have targeted AI platforms and enterprise systems, with significant exploits reported. Notable vulnerabilities include the PaperCut remote code execution flaw (CVE-2026-65105) being actively exploited. Attackers are hijacking authenticated browser sessions for AI services like Claude…