Data BreachBleeping Computer
9.0 — CRITICAL
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, with over 300 instances compromised across more than 100 organizations.
⚙️Technical Details
Affected Systems
Oracle PeopleSoft customer instancesPeopleSoft web and application servers
Attack Vectors
Zero-day vulnerabilitiesSSH key-based authenticationCommon administrative accounts such as 'psoft', 'oracle', and 'linuxadm'
💥Impact Assessment
Severity: critical
🛡️Recommended Actions
1Analyze logs for connections from the IP addresses 142.11.200[.]186 to 142.11.200[.]190 and 108.174.202[.]99 to 176.120.22[.]24
2Investigate whether PeopleSoft instances were compromised and consider temporarily removing affected servers from internet access
3Implement incident response and review the environment for security vulnerabilities
📦Affected Products
Oracle PeopleSoft Enterprise Resource Planning software
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
