Photo by Vitaly Gariev on Unsplash. Source: https://unsplash.com/photos/man-working-late-at-a-dimly-lit-office-desk-l12wb6pAzuQ (Unsplash License). A man working alone in a dimly lit office at night.

ShinyHunters defaced the FBI job application portal on 22 September and says an unpatched Oracle PeopleSoft flaw was the way in. The Bureau has confirmed only that it is investigating claims of unauthorized activity affecting fbijobs.gov.

  • What is established. The recruitment portal was defaced, the Bureau is investigating, and 404 Media verified part of a 5,000 record sample against public records.
  • What is only claimed. The zero day, the two to three terabytes, records on almost every agent, and the move into an AWS GovCloud environment all come from the attackers.
  • Why patching would not have helped. A zero day has no patch when it is used, and Oracle needed two weeks to answer the group’s June PeopleSoft flaw.
  • What would have. Blocking the PSEMHUB and PSIGW endpoints at the perimeter, segmenting the web tier from HR and justice systems, watching egress, and monitoring for new binaries in the deployment directory.
  • Who else is exposed. The same group hit over 100 organizations in June, 68 percent of them universities, and says it is moving on to larger enterprises.

Read the full analysis.

By Ivan Tarin

Ivan Tarin is a Principal Product Marketing Manager at SUSE, where he owns go-to-market strategy and positioning for a seven-product cloud-native portfolio spanning Kubernetes, virtualization, storage, security, and observability. A former full-stack developer who shipped production code for enterprise and public-sector clients including U.S. national laboratories, Ivan translates complex infrastructure and AI technology into messaging that lands with developers, platform teams, and enterprise buyers. He has presented at KubeCon, SUSECON, and AWS Developer Week, and is currently pursuing an MS in Artificial Intelligence at the University of Colorado Boulder.

Leave a Reply

Your email address will not be published. Required fields are marked *

Get the next one before it is old news

Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.