ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
A ShinyHunters ransomware group exploited a zero-day vulnerability in Oracle's PeopleSoft software suite to compromise over 300 instances across more than 100 organizations, primarily targeting higher education institutions. The attack leveraged a remote code execution flaw within the Environment Management Hub (EMHub) and involved techniques like MeshCentral for C2 operations and Zstandard compression for data exfiltration. Oracle patched the vulnerability following notification from Mandiant and Google Threat Intelligence Group, but the incident highlights the ongoing threat to the education sector.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
