Google’s cybersecurity unit has reported that the ShinyHunters hacking group has resumed widespread exploitation of a security flaw in Oracle’s PeopleSoft software after adapting to defensive measures introduced following earlier attacks.
The group previously exploited the vulnerability between May 27 and June 9, with universities among the main organisations affected. According to the latest threat intelligence report, attackers later targeted organisations that had installed web application firewall protections but had not applied Oracle’s security update for the flaw.
The latest campaign has affected dozens of systems worldwide across sectors including higher education, technology, healthcare, agriculture, transportation and government. The renewed activity has raised concerns among organisations that depend on PeopleSoft for human resources and other critical operations.