ShinyHunters claims responsibility for a breach of FBI job applicant portals and related systems, allegedly exposing personal, medical, and sensitive staff information. Google Cloud / Mandiant says the group is again exploiting Oracle PeopleSoft vulnerability CVE-2026-35273 by bypassing WAF rules and targeting organizations that failed to patch. #ShinyHunters #FBI #OraclePeopleSoft #CVE-2026-35273
Keypoints
- FBI applicant portals remain offline after the suspected breach.
- ShinyHunters claims access to FBI employee and applicant data.
- The stolen data allegedly includes medical and background-check records.
- Mandiant says the group is exploiting CVE-2026-35273 again.
- The attackers bypass WAF rules and deploy web shells and MeshAgent.
Read More: https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/