ShinyHunters extortion gang is actively targeting Oracle PeopleSoft servers using a chain of old and zero-day vulnerabilities, claiming to have stolen data from 300 instances across more than 100 organizations. Most victims are in the education sector. Researchers have exposed attack tooling including MeshCentral agents, credential spray scripts, and ransom note deployment scripts. IOC IP addresses have been published. Oracle has not yet responded. Organizations running PeopleSoft are advised to check logs for the listed IPs and initiate incident response if compromised.

4m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
49 Impressions