Mandiant

Company

Last mentioned: 13h ago

Timeline

  1. Google Confirms Exploitation

    Google Threat Intelligence Group publicly confirms zero‑day exploitation by ShinyHunters and notifies over 100 affected organizations.

  2. Oracle Releases Out‑of‑Band Advisory

    Oracle publishes mitigations for CVE-2026-35273 and warns customers to apply them immediately, but no full patch is provided.

  3. Google/Mandiant publish findings

    Google’s threat intelligence blog details the campaign, attribution, and sector impact.

  4. Oracle issues security advisory

    Oracle publishes a patch and advisory for the PeopleSoft vulnerability, closing the zero-day window.

  5. Campaign window closes

    Last observed exploitation activity before Oracle issues its advisory.

  6. Zero‑Day Exploitation Begins

    According to Google and Mandiant, ShinyHunters starts actively exploiting CVE-2026-35273 to compromise PeopleSoft instances.

  7. Campaign begins

    ShinyHunters starts active scanning and exploitation of the Oracle PeopleSoft zero-day.

  8. Patch Release

    Dell issues critical security updates to address the RecoverPoint vulnerability.

  9. Public Disclosure

    Mandiant and GTIG reveal the 18-month-long zero-day exploitation campaign.

  10. Attack Campaign Window

    ShinyHunters targets ~300 instances across 100+ organizations, focusing on education sector. Deploys MeshCentral agents and lateral movement scripts.

  11. Ongoing Espionage

    Attackers maintain persistence and conduct malware campaigns across multiple sectors.

  12. Initial Exploitation

    UNC6201 begins weaponizing CVE-2026-22769 in targeted attacks.

Stories mentioning Mandiant 3

Threat Intelligence Bearish

68% of Targets in Education: ShinyHunters Exploit Oracle Zero-Day Before Patch

An active extortion campaign by ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, with Google notifying over 100 organizations—68% in higher education. The attackers used customized MeshCentral agents for C2, actions occurring before Oracle’s June 10 advisory. This highlights the growing threat of zero-day exploitation in widely used enterprise software and the education sector’s vulnerability.

2 sources
Vulnerabilities Bearish

Chinese State Hackers Weaponize Dell RecoverPoint Zero-Day Since Mid-2024

A sophisticated Chinese cyberespionage group, tracked as UNC6201, has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines for nearly two years. The flaw, identified as CVE-2026-22769, allowed attackers to maintain long-term persistence and conduct stealthy malware campaigns against high-value targets.

4 sources

About Mandiant coverage

This page surfaces every story mentioning Mandiant across our cybersecurity coverage. We track each entity's appearance over time so readers can trace how the narrative evolves — which developments are isolated incidents, which build into longer arcs, and which reframe how operators in the space think about the entity. Story selection uses the same multi-source verification gate applied across the rest of our coverage.

Read our editorial methodology for how we identify, deduplicate, and score entity references. Our glossary defines the technical terms used across stories on this page, and our trends index contextualizes individual developments against the longer-running cybersecurity beat. Cross-entity comparisons live on our compare view.

What you seeWhat it tells you
Story countNumber of distinct stories where Mandiant was a primary or referenced actor.
Recency clusteringWhether mentions are concentrated in a recent window (a news cycle) or distributed (a sustained arc).
Sentiment distributionAggregate sentiment of the stories mentioning this entity, weighted by impact score.
Cross-niche linksWhen the same entity surfaces in our sibling networks, we link to those views to enrich context.