Saturday, September 26, 2026, 12:22 PM
×

Google Warns ShinyHunters Renewed Widespread Attacks on Oracle PeopleSoft Flaw

Saturday 26 September 2026 06:30
Google Warns ShinyHunters Renewed Widespread Attacks on Oracle PeopleSoft Flaw

Google’s cybersecurity unit warned on Friday that the hacking group 'ShinyHunters' has renewed widespread exploitation of a vulnerability in Oracle's PeopleSoft software, successfully bypassing defensive measures implemented following summer attacks. Mandiant, Google's threat intelligence arm, stated in a newly released report that the sophisticated nature of these attacks raises concerns for organizations relying on PeopleSoft for human resources and other critical operations. The report also highlighted mounting worries over whether even well-resourced institutions can adequately secure their systems. Attacks Targeted Universities and Global Institutions Mandiant revealed that ShinyHunters previously leveraged a flaw in Oracle’s PeopleSoft enterprise software between May 27 and June 9, primarily targeting universities. The intelligence unit added that the hackers adapted their tactics following the issuance of defense advisories after the initial late-spring attacks. They subsequently targeted entities that had implemented Web Application Firewall (WAF) rules but failed to deploy Oracle's security patch to remediate the vulnerability.