联邦调查局(FBI)用于求职者的在线门户(位于 apply.fbijobs.gov )以及特别探员申请者的门户(位于 fbijobs.gov/special-agents )目前仍无法访问,这似乎是网络勒索组织 ShinyHunters 成功入侵所致。
上周,美国国内情报与安全机构确认,其正在调查 ShinyHunters 关于已获取 FBI 员工个人信息的说法。
ShinyHunters 告诉《The Register》,他们利用了一个目前尚未明确且未经证实的 Oracle PeopleSoft 零日漏洞,突破了这些门户系统。
该组织还声称入侵了 AWS GovCloud 上由 FBI 管理的服务器,并窃取了现任、前任以及有意加入 FBI 的人员档案。
他们表示,其目的并非为了金钱;此次攻击及其高调公开披露,是因为他们希望反驳 ShinyHunters 在近期一份公共服务公告中所面临的指控,该公告建议受害组织不要支付赎金。
该组织声称已获取数万名 FBI 探员及潜在 FBI 雇员的个人信息,以及前者的医疗信息。
据 BBC 报道,该组织声称已访问多个平台:FBIJobs、负责员工和申请人背景调查的 FBI BEAST、存储医疗记录的 FBI MedLink,以及包含调查信息的 FBI BICS。
此外,据路透社报道,被盗文件之一是“提供关于 FBI 工作人员在鲜为人知或敏感部门中角色的数据”。
“路透社无法验证所有职位分配是否真实或最新,但能够将八名数据泄露人员的职业细节或头衔与法庭档案、新闻报道、LinkedIn 上的公开资料,或在 Instagram 等网站上的在线帖子进行匹配。”该出版物指出。
ShinyHunters 威胁称,如果 FBI 不撤回“虚假指控”,他们将公布被盗信息。
对 CVE-2026-35273 的重新利用
周五,Google Cloud / Mandiant 的分析人员和事件响应人员发布了一份技术概述,详细说明了 ShinyHunters 如何再次利用 Oracle PeopleSoft 漏洞(CVE-2026-35273)。该组织最初在 2026 年 5 月和 6 月将其作为零日漏洞加以利用,主要目标是学术机构。
当时,Oracle 建议实施紧急补丁,如果无法做到,则应用临时缓解措施,例如将网络访问限制到受信任的内部网络(包括在网络边界或防火墙层面阻止对外部易受攻击端点的访问)。
“仅依赖 Web 应用程序防火墙 (WAF) 的主体检查规则是不够的,因为这些控制措施可以被绕过。”Mandiant 当时指出。
事实证明他们是对的:据分析人员称,ShinyHunters 最近修改了其原始利用程序,以绕过阻止易受攻击的环境管理中心(PSEMHUB)端点的 Web 应用程序防火墙 (WAF) 规则,并将其目标扩大至高等教育、科技、IT 服务、医疗、农业、运输和政府机构。
“威胁行为者通过在请求路径中对单个字符进行 URL 编码,从而绕过了这些基于字符串的 WAF 规则,将 /PSEMHUB/ 替换为 /%50SEMHUB/ 。这允许威胁行为者访问那些运营商可能认为其 WAF 规则已缓解暴露的系统上的端点。”Mandiant 的分析人员指出。
“当前的活动表明 [ShinyHunters] 适应了已发布的防御指南,针对实施了 WAF 规则但未修补漏洞的组织。”
在获得访问权限后,该勒索组织部署了 Web shell、合法的远程管理工具(MeshAgent),并执行无文件命令。
订阅我们的突发新闻电子邮件警报,不错过任何最新的安全漏洞、脆弱性和网络安全威胁。立即订阅!
The FBI’s online portals for job applicants (at apply.fbijobs.gov ) and special agent applicants (at fbijobs.gov/special-agents ) are still unavailable, following what appears to be successful compromises by the ShinyHunters cyber extortion group.
Last week, the United States’ domestic intelligence and security service confirmed it was investigating ShinyHunters’ claim of having compromised personal information of FBI employees.
ShinyHunters told The Register they leveraged a currently unspecified and unconfirmed Oracle PeopleSoft zero-day vulnerability to breach the portals.
They also claimed to have breached FBI’s managed servers on AWS GovCloud and stole personnel files of current, former, and aspiring FBI employees.
They aren’t after money, they said: the attack and their very public disclosure of it was because they wanted to contest the allegations made against ShinyHunters in a recent public service announcement , which advised victim organizations not to pay the ransom.
The group claims to have gotten their hands on personal information of tens of thousands of FBI agents and prospective FBI employees, as well as medical information of the former.
According to the BBC , the group claims to have gained access to multiple platforms: FBIJobs, FBI BEAST (which handles background checks on employees and applicants), FBI MedLink (which stores medical records), and FBI BICS (which contains investigative information).
Also, according to Reuters , among the documents stolen is one that “provides data on roles of FBI staff in little-known or sensitive FBI units.”
“Reuters could not verify that all the job assignments were authentic or up-to-date, but it was able to match the career details or titles of eight people whose data was leaked to information in court filings, news articles, or public profiles on LinkedIn or to online posts on sites such as Instagram,” the publication noted.
ShinyHunters threatened to release the stolen information if the FBI doesn’t retract the “false allegations.”
Renewed exploitation of CVE-2026-35273
On Friday, Google Cloud / Mandiant’s analysts and incident responders published a technical rundown of how ShinyHunters are once more exploiting an Oracle PeopleSoft vulnerability (CVE-2026-35273) they initially exploited in May and June 2026 as a zero-day to target mostly academic institutions.
At the time, Oracle advised implementing the emergency patch and, if unable to do so, applying temporary mitigations such as restricting network access to PeopleSoft application and web servers to trusted internal networks (including blocking external access to the vulnerable endpoints at the network perimeter or firewall level).
“Relying solely on Web Application Firewall (WAF) body-inspection rules is insufficient, as these controls can be bypassed,” Mandiant noted at the time.
And they were right: according to the analysts, ShinyHunters recently modified their original exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint, and expanded their targeting to higher education, technology, IT services, healthcare, agriculture, transportation, and government institutions.
“The threat actor bypassed these string-based WAF rules by URL-encoding a single character in the request path, requesting /%50SEMHUB/ in place of / PSEMHUB/ . This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure,” Mandiant’s analysts noted .
“The current campaign demonstrates that [ShinyHunters] adapted to published defensive guidance, targeting organizations that implemented WAF rules but did not patch the vulnerability.”
Ofter gaining access, the extortion group deploys web shells, a legitimate RMM tool (MeshAgent) and performs fileless command execution.
Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
首次收录 · 2026-09-29 · 7.54 分