°C
Air:
GOLD73,245 0.25%
SILVER84,520 0.29%
USD83.25 0.12%
EUR90.45 0.08%
GBP105.6 0.15%
ShinyHunters Exploit Oracle PeopleSoft Vulnerability to Target Over 100 Organisations Says Google Th
Cyber Security

ShinyHunters Exploit Oracle PeopleSoft Vulnerability to Target Over 100 Organisations Says Google Th

0 views
Text Size:

Cybersecurity researchers from Google Threat Intelligence Group have raised concerns over a large scale cyberattack campaign carried out by the hacking group known as ShinyHunters. According to the report, the group exploited a significant vulnerability in Oracle PeopleSoft software to target more than 100 organisations globally.

Oracle PeopleSoft is widely used enterprise resource planning software that manages critical business functions such as human resources, finance and administrative operations. Because of its widespread adoption in large organisations, any vulnerability in the system can have serious implications for data security and operational integrity.

The report indicates that the attackers used a previously identified security flaw to gain unauthorized access to enterprise systems. Once inside, they are believed to have attempted to extract sensitive data from affected organisations. The scale of the campaign suggests a coordinated effort targeting multiple sectors that rely on Oracle PeopleSoft infrastructure.

ShinyHunters is a cybercrime group known for conducting data breaches and selling stolen information on underground platforms. The group has previously been linked to several high profile incidents involving corporate databases and user information leaks. Security experts say the latest activity demonstrates a continued focus on exploiting enterprise software vulnerabilities.

Google Threat Intelligence researchers have emphasised that organisations using Oracle PeopleSoft should urgently review their security patches and ensure that all known vulnerabilities are addressed. Failure to apply timely updates can leave systems exposed to exploitation by threat actors.

Cybersecurity specialists also warn that attackers often move quickly after a vulnerability becomes public, scanning for unpatched systems to exploit at scale. In many cases, organisations that delay security updates become prime targets for automated or semi automated attacks.

The incident highlights the growing importance of proactive cybersecurity measures, particularly for large organisations that handle sensitive employee and financial data. Experts recommend continuous monitoring, regular patch management and strong access control policies as essential safeguards.

In addition to technical vulnerabilities, security awareness among employees also plays a critical role in preventing breaches. Phishing attacks and credential theft often accompany such campaigns, making user education an important layer of defence.

The report further underscores the need for collaboration between software vendors, cybersecurity agencies and organisations to respond quickly to emerging threats. Timely sharing of threat intelligence can help reduce the impact of large scale cyberattacks.

As cyber threats continue to evolve, enterprise software systems remain a key target for hacking groups seeking financial gain or data exploitation. The ShinyHunters campaign serves as a reminder of the risks associated with unpatched vulnerabilities in widely used platforms.

Security experts continue to monitor the situation closely and advise organisations to remain vigilant, update their systems regularly and adopt a layered security approach to minimise exposure to such attacks.