ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability

The ShinyHunters group has exploited a critical zero-day vulnerability in Oracle PeopleSoft, impacting numerous universities and potentially exposing sensitive data.

The ShinyHunters group has exploited a critical zero-day vulnerability in Oracle PeopleSoft, impacting numerous universities and potentially exposing sensitive data.

Reports indicate that Chinese agents are leveraging technology, including American AI, to gather data and influence public opinion regarding AI datacenters in the U.S.

Ivanti, Fortinet, and SAP have issued security updates addressing multiple critical vulnerabilities that could lead to arbitrary code execution and information disclosure.

The JDY botnet, linked to Chinese state-sponsored actors, has significantly increased its size and capabilities, now comprising over 1,500 compromised devices, primarily targeting SOHO and IoT infrastructures.

Microsoft's June Patch Tuesday release addressed a record 206 CVEs, with significant implications for system administrators and vulnerability management teams.

A phishing campaign linked to North Korea has targeted developers with over 250 fraudulent job offers, aiming to steal credentials and cryptocurrency.

Check Point has reported active exploitation of a significant vulnerability in its VPN products, allowing attackers to bypass authentication requirements in specific configurations.

A significant security oversight has been revealed involving the storage of passwords in Active Directory description fields, leading to severe consequences for an organization.

Dutch law enforcement has successfully dismantled a botnet that compromised at least 17 million devices, including IoT products, to conduct cyber attacks.

A recent cyber incident highlights the use of a large language model (LLM) agent in post-exploitation activities after exploiting a critical vulnerability in Marimo software.