AI Weekly Malaysia

Back to items Summaries

ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

ID
27620
Status
summarized
Published
23 Sep 2026, 1:30 PM
Fetched
23 Sep 2026, 3:29 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
23 Sep 2026, 3:31 PM
Tags
Audience
developerssaas_founders

What happened

ShinyHunters claims to have breached the FBI by exploiting a new Oracle PeopleSoft zero-day RCE vulnerability, defacing FBIjobs.gov and allegedly stealing data on nearly all FBI agents and job applicants. The group says it targeted the FBI in retaliation for a May 2026 PSA about their attacks on Canvas LMS. FBI confirmed it is investigating unauthorized activity on FBIjobs.gov; no CVE has been published for the claimed PeopleSoft pre-auth RCE, though ShinyHunters previously weaponized a similar flaw (CVE-2026-35273) in June 2026.

Why it matters

If your organization runs Oracle PeopleSoft, treat this as a prompt to check patch status and monitor for a pre-auth RCE advisory—ShinyHunters has already demonstrated capability with a similar PeopleSoft flaw (CVE-2026-35273) earlier in 2026. For everyone else, this is a high-profile cybercrime story with no direct action item.

Discussion angle

The PeopleSoft angle is the only actionable thread: how many enterprises and government agencies in the region still run PeopleSoft, and what does the exposure surface look like if a pre-auth RCE goes unpatched?

Top