ShinyHunters hackers are going after Oracle systems once again


ShinyHunters have found a way to bypass a mitigation for a zero-day they previously exploited – so now, not only are they back to abusing the same bug, they’ve even expanded their scope to target a much larger pool of organizations.

In June 2026, it was reported that ShinyHunters, the infamous data extortionists, found a Java deserialization vulnerability in Oracle’s PeopleSoft Environment Management Hub (PSEMHUB) servlet that allowed them to achieve web shell deployment or fileless command execution on vulnerable servers.

Oracle PeopleSoft is a suite of enterprise business software used mainly by large organizations, universities, governments, and corporations to manage things like human resources, finance, supply chain, and student administration.

Read more…
Source:  TechRadar News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Two years after WannaCry, a million computers remain at risk

    May 12, 2019

    Two years ago today, a powerful ransomware began spreading across the world. WannaCry spread like wildfire, encrypting hundreds of thousands of computers in more than 150 countries in a matter of hours. It was the first time that ransomware, a malware that encrypts a user’s files and demands cryptocurrency in ransom to unlock them, had spread across ...

  • ScarCruft APT Adds Bluetooth Harvester to its Malware Bag of Tricks

    May 11, 2019

    The ScarCruft Korean-speaking APT is changing up its espionage tactics to include an unusual piece of malware devoted to harvesting Bluetooth information – while also showing some overlap with the DarkHotel APT. An analysis of ScarCruft’s binary infection procedure by Kaspersky Lab shows that in a campaign that continued over the course of 2018, the group used ...

  • North Korea debuts new Electricfish malware in Hidden Cobra campaigns

    May 10, 2019

    The Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI) have released a joint security advisory warning of a new strain of malware being used in North Korean cyberattacks. Dubbed Electricfish, the malware was uncovered while the departments were tracking the activities of Hidden Cobra, a threat group believed to be state-sponsored and ...

  • Lax Telco Security Allows Mobile Phone Hijacking and Redirects

    May 9, 2019

    As anyone who has called into a bank or utility provider lately knows, security for customer service routines – the prescribed ways in which support reps verify the identity of customers that call in – are being continually upgraded. Two-factor authentication, voice passwords, various security questions (“what was the name of your first pet,” for ...

  • FIN7.5: the infamous cybercrime rig “FIN7” continues its activities

    May 8, 2019

    On August 1, 2018, the US Department of Justice announced that it had arrested several individuals suspected of having ties to the FIN7 cybercrime rig. FIN7 operations are linked to numerous intrusion attempts having targeted hundreds of companies since at least as early as 2015. Interestingly, this threat actor created fake companies in order to ...

  • Surge of MegaCortex ransomware attacks detected

    May 6, 2019

    UK cyber-security firm Sophos reported detecting a spike in ransomware attacks at the end of last week from a new strain named MegaCortex. Sophos said the ransomware appears to have been designed to target large enterprise networks as part of carefully planned targeted intrusions –in a tactic that is known as “big-game hunting.” The modus operandi is ...