ShinyHunters claims it breached the FBI with an Oracle PeopleSoft zero-day and says it is now hitting Fortune 500 firms
BleepingComputer (corroborated by 404 Media via Techmeme and Infosecurity Magazine)·high signal
ShinyHunters says it used an unpatched PeopleSoft remote-code-execution flaw to get into FBI jobs and applicant systems, then moved laterally into FBI-managed AWS GovCloud and took 2-3TB of employee and applicant data. 404 Media verified parts of a 5,000-record sample, and the group says it is using the same zero-day against Fortune 500 companies. Anyone running internet-facing PeopleSoft should treat it as exposed until Oracle ships a patch.