news.mlab.sh
Back to the feed
threat-intel

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

CriticalCVSS 9.8
Image: The Hacker News
Summary

Attackers are bypassing WAFs to exploit a critical vulnerability in Oracle PeopleSoft, allowing them to deploy web shells and conduct data theft extortion campaigns. The ShinyHunters group, linked to the FBI breach, is leveraging this flaw to gain persistent access and steal sensitive data, including HR, payroll, and student records. Organizations are urged to apply patches, disable the Environment Management Hub, and monitor for potential data leaks and extortion attempts.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.