# Canvas

Type: Product

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/canvas
Canonical HTML page: https://getcyberbrief.com/entity/canvas

## Timeline

- **2026-06-11**: Google/Mandiant publish findings — Google’s threat intelligence blog details the campaign, attribution, and sector impact.
- **2026-06-10**: Oracle issues security advisory — Oracle publishes a patch and advisory for the PeopleSoft vulnerability, closing the zero-day window.
- **2026-06-09**: Campaign window closes — Last observed exploitation activity before Oracle issues its advisory.
- **2026-05-27**: Campaign begins — ShinyHunters starts active scanning and exploitation of the Oracle PeopleSoft zero-day.

## Recent coverage (1 stories)

### 68% of Targets in Education: ShinyHunters Exploit Oracle Zero-Day Before Patch
2026-06-12 04:54:34 · Sentiment: Bearish · Impact: 7/10 · Sources: 2

An active extortion campaign by ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, with Google notifying over 100 organizations—68% in higher education. The attackers used customized MeshCentral agents for C2, actions occurring before Oracle’s June 10 advisory. This highlights the growing threat of zero-day exploitation in widely used enterprise software and the education sector’s vulnerability.
Full story: https://getcyberbrief.com/story/shinyhunters-oracle-peoplesoft-zero-day-education

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.