Skip to content

ABC Tool

  • Home
  • About / Contect
    • PRIVACY POLICY
PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data

PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data

Posted on June 12, 2026 By safdargal12 No Comments on PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data
Blog


“While several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, resulting in stolen data being published on the ShinyHunters DLS,” Mandiant said. (DLS is short for data leak site.)

An analysis of a bash script left in the staging environment shows the attackers performed reconnaissance on compromised organizations, including mapping the PeopleSoft configurations, viewing process scheduler, and WebLogic server XML configurations. Eventually, the threat actors established an outbound SSH connection to 176.120.22.24, the IP address hosting ShinyHunters’ DLS. The stolen data was first compressed using the zstd tool. The DLS claimed to have recovered 48GB of data from a single victim.

A partially redacted section of the ShinyHunters’ DLS.

Credit:
Mandiant

A partially redacted section of the ShinyHunters’ DLS.


Credit:

Mandiant

ShinyHunters has been active since at least 2019. Over the past several years, it has executed scores of hacks against some of the world’s largest companies, affecting millions of people downstream. A small sample of victims includes Ticketmaster (through the breach of Snowflake, which hosted the data), Spain’s biggest bank, Santander, and Salesforce (and, through it, Google and, reportedly, many other companies). ShinyHunters uses various techniques to gain initial access, including exploiting cloud misconfigurations and software vulnerabilities, stealing OAuth tokens, supply chain attacks, voice phishing, and other forms of social engineering.

Mandiant and Rapid7 are providing detailed indicators of compromise. They are also advising PeopleSoft customers on the steps they should take immediately. Given ShinyHunters’ success rate, all PeopleSoft users would do well to heed the calls.



Source link

Post Views: 1

Post navigation

❮ Previous Post: Chinese cybercrime operation that used AI to scam ‘hundreds of thousands of victims’ sued by Google
Next Post: Mozilla’s CEO Knows You Might Not Want AI in Firefox ❯

You may also like

Google quietly kills Project Mariner as the AI agent race shifts gears
Blog
Google quietly kills Project Mariner as the AI agent race shifts gears
May 6, 2026
Galaxy Tab S12 series? Samsung app reveals Dimensity 9500 device is coming
Blog
Galaxy Tab S12 series? Samsung app reveals Dimensity 9500 device is coming
May 15, 2026
Google I/O 2026: Gmail’s fancy AI Inbox is coming to more users
Blog
Google I/O 2026: Gmail’s fancy AI Inbox is coming to more users
May 20, 2026
GM Adds Google Gemini for Drivers to Rev Up With AI Assistant
Blog
GM Adds Google Gemini for Drivers to Rev Up With AI Assistant
April 30, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Nothing CEO says phone prices are going to keep going up
  • On Eve of SpaceX IPO, Protesters Roast Grok With Giant Elon Musk Inflatable
  • World of Claudecraft
  • I’m Letting Siri See My Life on Vision Pro, and It’s a Sign of Things to Come
  • Trump Mobile T1 Phone teardown confirms it's an HTC in disguise

Recent Comments

  1. Last Chance for Big Savings on TechCrunch Disrupt 2026 Tickets – Artiverse on 5 days left: Save up to $410 on Disrupt 2026 passes

Archives

  • June 2026
  • May 2026
  • April 2026

Categories

  • Blog

Copyright © 2026 ABC Tool.

Theme: Oceanly News by ScriptsTown