請更新您的瀏覽器

您使用的瀏覽器版本較舊,已不再受支援。建議您更新瀏覽器版本,以獲得最佳使用體驗。

本文由AI翻譯

Google:駭客組織 ShinyHunters 擴大對甲骨文 PeopleSoft 的攻擊

Reuters

更新於 1天前 • 發布於 1天前
檔案照:2026年7月1日,美國紐約市 Google 總部展示的 Google 標誌。路透社/Aleksandra Michalska/檔案照FILE PHOTO: Google logo is displayed at Google's headquarters in New York City, U.S., July 1, 2026. REUTERS/Aleksandra Michalska/File Photo
檔案照:2021年10月18日,雲端服務供應商甲骨文(Oracle)位於愛爾蘭都柏林 Eastpoint Business Park 辦公室的公司標誌。照片攝於2021年10月18日。路透社/Tom Bergin/檔案照FILE PHOTO: A logo of cloud service provider Oracle is seen at the company's offices at Eastpoint Business Park, Dublin, Ireland October 18, 2021. Picture taken October 18, 2021. REUTERS/Tom Bergin//File Photo

路透9月25日電——Google 旗下資安部門週五表示,駭客組織 ShinyHunters 已再度「大規模利用」甲骨文(Oracle)PeopleSoft 軟體的一項安全漏洞;該組織先前繞過了夏季攻擊後建立的防禦措施。Sept 25 (Reuters) - Google's cybersecurity unit said on Friday that hacking group ShinyHunters has renewed "mass exploitation" of a security flaw in Oracle's PeopleSoft software, after skirting defenses put up following attacks in the summer.

Mandiant 是在一份威脅情報報告中宣布此事。這份報告發布前數天,聲稱對多起重大資料外洩事件負責的 ShinyHunters 表示,已竊取美國聯邦調查局(FBI)人員資料。Mandiant made the announcement in a threat intelligence report released days after ShinyHunters, which has claimed responsibility for several major data breaches, said it had stolen FBI personnel data.

這波攻擊持續演變,可能讓仰賴 PeopleSoft 處理人力資源及其他關鍵職能的組織警鈴大作,並加深外界對即使資源充足的機構也可能存在弱點的疑慮。The evolving nature of the attack is likely to ring alarm bells at organizations that rely on PeopleSoft for human resources and other critical functions, and heighten concerns about the vulnerability of even well-resourced institutions.

Alphabet 旗下 Google 的這個部門表示,ShinyHunters 在5月27日至6月9日的攻擊中,利用甲骨文 PeopleSoft 企業軟體的一項漏洞,主要影響大學院校。The unit of Alphabet's Google said ShinyHunters exploited a bug in Oracle's PeopleSoft enterprise software in attacks from May 27 through June 9 that mainly affected universities.

Mandiant 表示,駭客因應5月至6月攻擊後發布的防禦指引調整手法,鎖定已導入網頁應用程式防火牆規則、但未套用甲骨文為修補該漏洞而發布更新的組織。Mandiant said the hackers adapted to defensive guidance published after the May-June attacks and targeted organizations that implemented web application firewall rules but did not apply an update that Oracle issued to patch the vulnerability.

Mandiant 未指明受害者,但表示最新攻擊影響全球數十個系統,涉及產業涵蓋高等教育、科技、醫療保健、農業、運輸及政府等不同領域。It said, without identifying victims, that the latest attack affected dozens of systems globally in sectors as varied as higher education, technology, healthcare, agriculture, transportation and government.

ShinyHunters 表示,該組織是利用 PeopleSoft 的漏洞取得 FBI 資料。路透社尚無法證實這項說法。甲骨文未回應採訪請求。ShinyHunters has said it accessed FBI data using a vulnerability in PeopleSoft. Reuters has not been able to corroborate the claim. Oracle did not respond to requests for comment.

美國聯邦調查局週三發布聲明表示,正「積極調查」這起據報外洩事件。In a statement issued Wednesday, the Federal Bureau of Investigation said it was "aggressively investigating" the reported breach.

路透社先前報導,ShinyHunters 曝光了在 FBI 敏感單位工作的人員姓名,並取得醫療與精神科紀錄。ShinyHunters exposed the names of personnel working in sensitive FBI units and acquired medical and psychiatric records, Reuters previously reported.

(Natalia Bueno Rebolledo 與 Mrinmay Dey 墨西哥城、Raphael Satter 華盛頓報導;Christopher Cushing 編輯)(Reporting by Natalia Bueno Rebolledo and Mrinmay Dey in Mexico City, and Raphael Satter in Washington; Editing by Christopher Cushing)

更多國際相關文章

01

AI恐釀10億人死亡! 比爾蓋茲示警「史無前例威脅」:政府一定要出手

鏡週刊
02

24歲女店員「脖纏電線」全裸陳屍租屋處 友曝生前1壞習慣!疑遭性侵殺害

鏡週刊
03

鳥喙遭魚線緊纏只能等死、野鳥陳屍血水 攝影獎的揪心畫面

太報
04

媽媽喊生活費不夠用!他每月匯5萬 返家驚見1幕崩潰:原來錢都給妹妹

鏡報
05

亂葬崗挖出1600顆乳牙!志工控「孩童疑遭販運」 官方全盤否認

CTWANT
06

川普宴請習近平!主桌名單曝光 網見1細節:「2位台灣人」上桌

三立新聞網
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...