CuraSec

Learn active

ShinyHunters claims FBI breach via Oracle PeopleSoft zero-day

2026-09-23 15:27 UTC · BleepingComputer · read the source ↗ #shinyhunters#oracle-peoplesoft#zero-day
  • Engineer — Learn: An alleged Oracle PeopleSoft zero-day with no CVE, PoC, or KEV signals yet; if you run PeopleSoft (common HR/ERP), watch for Oracle’s advisory and be ready to assess patch urgency once technical details surface.
  • SOC/IR — Learn: ShinyHunters is a well-documented extortion actor, but this claim carries no published IOCs or mapped TTPs; monitor threat intel feeds for follow-on disclosures that would enable a hunt or detection build.
  • Leader — Learn: An unverified threat-actor claim against the FBI will likely generate board questions if confirmed; track Oracle’s response, and note that PeopleSoft is widely used for HR — a confirmed zero-day would require a vendor exposure check.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.