# oracle exploit — X 热门讨论 (2026-09-23 04:03 UTC)

## @IceSolst (solst/ICE of Astarte) · 09-23 03:46 · ♥32 ↻4 💬5 ShinyHunters compromised the FBI via an Oracle PeopleSoft exploit, and stole employee data.

It’s not confirmed whether it was via a 0day (as they’ve claimed), or exploiting the known recent vulnerability below.

They also claim to have pivoted to aws govcloud. It’s not confirmed if all the data was stolen solely from PeopleSoft, or from elsewhere.

It’s also not clear how they defaced the recruitment site. It is not obvious to me how PeopleSoft would give you access to modify a website, so some lateral movement was likely.

Defacement here was to send a message. They could have silently modified the site’s data and misled visitors, eg getting to sign up and collecting their data. But their motive was to demand the FBI “correct or simply REMOVE the 2026 Quarter 2 FLASH report on us that includes several FALSE allegations”

Overall an interesting compromise, I’m a fan of defacement esp when they could have chosen to silently alter it instead. I respect the boldness. (Btw don’t compromise the fbi, im pretty sure it’s illegal, but I’m not a lawyer) > 引用 @mattjay: When CISA adds a vuln to KEV it starts a clock for government agencies to patch fast.

It seems the FBI didn’t abide by that timeline on a known exploited CVSS 9.8 vuln. https://t.co/csiccBeuFu https://x.com/IceSolst/status/2102605537946837062