ShinyHunters Resume Mass Exploitation Of Oracle PeopleSoft Vulnerability, Google SaysSep 26, 2026, 12:23 IST
Google's cybersecurity unit said that hacking group ShinyHunters has renewed 'mass exploitation' of a security flaw in Oracle's PeopleSoft software, after skirting defenses put up following attacks in the summer. Mandiant made the announcement in a threat intelligence report released days after ShinyHunters, which has claimed responsibility for several major data breaches, said it had stolen FBI personnel data. Apart from that, the evolving nature of the attack is likely to ring alarm bells at organizations that depend on PeopleSoft for human resources and other critical functions, and heighten concerns about the vulnerability of even well-resourced institutions. Google said ShinyHunters exploited a bug in Oracle's PeopleSoft enterprise software in attacks from May 27 to June 9, 2026. Mandiant said that the hackers adapted to defensive guidance published after the May-June attack and targeted organisations that implemented web application firewall rules but did not apply an update that Oracle issued to patch the vulnerability. It said, without identifying the victims, that the latest attack affected dozens of systems globally in sectors as varied as higher education, technology, healthcare, agriculture, government, and transportation. ShinyHunters has also said that it accessed the Federal Bureau of Investigation using a vulnerability in PeopleSoft. FBI also said on the matter that the organisation is aggressively investigating the reported breach. For those who are unaware, ShinyHunters exposed the names of personnel working in sensitive FBI units and acquired medical and psychiatric records as well. Mandiant also said attackers were targeting organisations that had implemented web application firewall rules but had not installed Oracle's security update for the vulnerability. The campaign shows that attackers can adapt after security guidance is published, making timely software updates. The inclusion of government systems raises the stakes because compromised systems could involve sensitive personnel or operational information. To stay safe, firms should not only rely on Web Application Firewall rules. Google observed attackers bypassing certain WAF protections using an encoded version of the vulnerable endpoint. A career journalist who spent six years playing around with smartphones, apps and gaming. As a hobby, Rudra enjoys researching mobile games, watching ... View More





