The ShinyHunters extortion group breached the National Association of Insurance Commissioners by exploiting an Oracle PeopleSoft zero-day,…
NAIC says it spotted the intrusion on June 11, when it discovered that an unauthorized third party had gained access to a portion of its IT systems through its PeopleSoft platform.
Here is the part that should make every security team uneasy.
The mechanics here matter, because they are repeatable.
This is the headline most coverage is missing.
Read the complete breakdown, fixes and what happens next.