Oracle Warns of Critical PeopleSoft Bug Abused by ShinyHunters in Mass Breach
Oracle has issued a critical security warning for its PeopleSoft software after the ShinyHunters cybercrime group claimed to have exploited a zero-day vulnerability to breach over 100 companies, primarily in higher education. The flaw allows unauthorized remote access, leading to the theft of sensitive data.
A
··2 min readAgent
Newsroom

Oracle has issued a stern warning to its corporate clientele regarding a critical security vulnerability within its widely used PeopleSoft software. This advisory comes just a day after the notorious cybercrime group ShinyHunters publicly claimed responsibility for exploiting this flaw in a large-scale hacking campaign that has reportedly compromised over 100 organizations. PeopleSoft, a cornerstone for many large enterprises, is crucial for managing essential functions like payroll and human resources.
The tech giant published its security advisory on Thursday, following ShinyHunters' assertion of breaching numerous PeopleSoft servers. Mandiant, the Google-owned security firm renowned for investigating cyberattacks, corroborated these claims in a blog post, confirming that the newly identified Oracle flaw is indeed the same zero-day bug being actively exploited by ShinyHunters. Oracle has yet to release a patch for this vulnerability, noting in its advisory that the bug can be exploited remotely over the internet without requiring any authentication, such as a password, making it particularly dangerous. The company has urged its PeopleSoft customers to immediately apply available mitigations to prevent further exploitation.
The scope of this cyberattack is extensive. Mandiant has proactively notified more than 100 global organizations, predominantly located in the United States, about their potentially vulnerable systems. The cybersecurity group highlighted that approximately two-thirds of these affected entities are in the higher education sector, a detail that aligns with earlier statements from ShinyHunters. While some organizations managed to block the malicious activity or remediate the vulnerabilities, many others suffered compromises, leading to sensitive data being stolen and subsequently published on ShinyHunters' data leak website. A member of the hacking group revealed that stolen data from universities includes "hundreds of thousands of student records containing full name, home address, phone, email, date of birth, gender, ethnicity, enrollment status, GPA, major, and student ID across all campuses," among other personal information.
This incident marks another chapter in ShinyHunters' persistent campaign of targeting organizations that rely on shared vulnerable software. In the past year alone, the group has successfully exploited flaws in software from Salesforce, Gainsight, and the education technology provider Instructure. Their typical modus operandi involves identifying vulnerable systems, exfiltrating corporate or customer data, and then demanding a ransom, threatening to release the stolen information if payment is not made. Earlier this year, Instructure reportedly paid a ransom after being breached twice by ShinyHunters, which also involved defacing login pages of schools using their Canvas portal. Oracle, meanwhile, has remained silent on TechCrunch's request for comment regarding the ongoing situation.
The repeated success of groups like ShinyHunters underscores the critical need for robust cybersecurity practices and timely patching. Organizations using enterprise software must remain vigilant and proactive in applying security updates and mitigations, especially when dealing with zero-day vulnerabilities that are actively being exploited. The financial and reputational damage from such breaches, particularly involving sensitive student and employee data, can be severe and long-lasting.




