Oracle warns of zero-day bug after 100+ firms hacked – Claril Noticias

Oracle warned corporate customers on Thursday of a critical, unpatched vulnerability in its PeopleSoft software, following claims by cybercrime group ShinyHunters that they exploited the flaw to breach over 100 global organisations.

Active Exploitation of Zero-Day Flaw

The tech giant published the security advisory after the notorious hacking group ShinyHunters declared they had compromised more than 100 entities utilising PeopleSoft servers. This enterprise software is widely used by major corporations and institutions to manage payroll and human resources.

Google-owned cybersecurity firm Mandiant warned in a blog post that this newly identified Oracle security bug is the exact vulnerability being leveraged by ShinyHunters in their ongoing campaign.

No Patch Available for Critical Bug

At the time of writing, Oracle has not released a patch to resolve the vulnerability. The security advisory notes that the flaw can be exploited remotely over the internet without requiring any authentication, such as a username or password. Consequently, the company has urged PeopleSoft users to apply immediate mitigation measures to block potential attacks.

A member of the ShinyHunters group disclosed to TechCrunch on Wednesday that the cybercriminals gained entry by exploiting this unpatched zero-day flaw—meaning Oracle had no prior knowledge of the vulnerability before it was actively exploited in the wild.

Universities and Colleges Under Fire

Mandiant confirmed it has proactively notified more than 100 affected organisations worldwide, predominantly in the United States, to help them secure their systems. According to the security firm, approximately two-thirds of the targeted entities belong to the higher education sector, validating earlier claims made by the hackers.

While some organisations successfully thwarted the intrusion attempts or applied mitigations, others suffered full compromises. This has resulted in stolen proprietary and personal data being published on the ShinyHunters data leak website. Oracle did not respond to requests for comment regarding the breaches.

Massive Theft of Student Records

The hackers shared a ransom communication allegedly sent to one of the victim universities. In the message, the group claimed to have exfiltrated hundreds of thousands of student records. The stolen data reportedly includes full names, home addresses, telephone numbers, email addresses, dates of birth, gender, ethnicity, enrolment status, GPAs, majors, and student identification numbers.

A Systematic Campaign Against Shared Software

This campaign against PeopleSoft is part of a broader, systemic strategy by ShinyHunters. The cybercrime group specialises in identifying and targeting organisations that rely on the same third-party software platforms.

Over the past year, the gang has targeted numerous organisations utilising Salesforce, Gainsight, and Instructure, among other popular enterprise tools. Once a vulnerable software product is identified, the hackers infiltrate the connected networks to exfiltrate corporate and customer data, subsequently demanding a ransom to prevent the public release of the stolen information.

Earlier this year, educational technology provider Instructure admitted to paying a ransom to the group after suffering two separate breaches. During that campaign, ShinyHunters defaced the login portals of several schools using Instructure’s Canvas platform.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *