Cybersecurity entity

Mandiant

Company

Of the tracked stories, 2 of 3 also mention Google, the most common co-covered peer. The 115-day window averages about 0.2 stories each week. The busiest single day carried 2. Coverage clusters in vulnerability, which accounts for 2 of those 3, with the remainder spread across 1 other category.

Last mentioned: Jun 12, 2026

Entity pulse

Recent coverage · Mandiant

3 stories
7.3 avg impact
0% positive
100% negative

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 100 percentage points.

  • 100% negative

Figures are computed live from our source-verified story record — see our methodology for how impact and sentiment are derived.

What the coverage shows about Mandiant

Of the tracked stories, 2 of 3 also mention Google, the most common co-covered peer. The 115-day window averages about 0.2 stories each week. The busiest single day carried 2. Coverage clusters in vulnerability, which accounts for 2 of those 3, with the remainder spread across 1 other category. They are less corroborated than the beat average, carrying 2.7 original sources each against 3.1 for the same window. The 7.3 average consequence score is above the beat benchmark of 7 in the same window. This profile follows 3 Cybersecurity stories mentioning Mandiant across the period from February 18, 2026 to June 12, 2026.

Stories tracked
3
Per week
0.2
Sources per story
2.7

Computed from the 3 stories linked to this entity, with beat comparisons drawn from all 504 Cybersecurity stories published in the same date window. Shares are omitted below five stories and comparisons below a twenty-story baseline.

Coverage cohort

Appears alongside

Other entities that clear the same relevance threshold in stories also covering Mandiant. Shared-story counts are live from our verified record — not editorial picks.

Timeline

  1. Google Confirms Exploitation

    Google Threat Intelligence Group publicly confirms zero‑day exploitation by ShinyHunters and notifies over 100 affected organizations.

  2. Google/Mandiant publish findings

    Google’s threat intelligence blog details the campaign, attribution, and sector impact.

  3. Oracle Releases Out‑of‑Band Advisory

    Oracle publishes mitigations for CVE-2026-35273 and warns customers to apply them immediately, but no full patch is provided.

  4. Campaign window closes

    Last observed exploitation activity before Oracle issues its advisory.

  5. Campaign begins

    ShinyHunters starts active scanning and exploitation of the Oracle PeopleSoft zero-day.

  6. Zero‑Day Exploitation Begins

    According to Google and Mandiant, ShinyHunters starts actively exploiting CVE-2026-35273 to compromise PeopleSoft instances.

  7. Patch Release

    Dell issues critical security updates to address the RecoverPoint vulnerability.

  8. Public Disclosure

    Mandiant and GTIG reveal the 18-month-long zero-day exploitation campaign.

  9. Attack Campaign Window

    ShinyHunters targets ~300 instances across 100+ organizations, focusing on education sector. Deploys MeshCentral agents and lateral movement scripts.

  10. Ongoing Espionage

    Attackers maintain persistence and conduct malware campaigns across multiple sectors.

  11. Initial Exploitation

    UNC6201 begins weaponizing CVE-2026-22769 in targeted attacks.

Stories mentioning Mandiant 3

Vulnerabilities Negative

Google: ShinyHunters Hit 100+ Orgs in PeopleSoft Zero‑Day; 68% Were US Universities

Google and Mandiant confirm active exploitation of CVE-2026-35273, a critical unauthenticated RCE flaw in Oracle PeopleSoft. The ShinyHunters group compromised roughly 300 instances, with the higher education sector bearing 68% of the impact. Oracle has only released mitigations, leaving organizations exposed to data theft and extortion.

2 sources

Source: SecurityWeek · SecurityWeek

Threat Intelligence Negative

68% of Targets in Education: ShinyHunters Exploit Oracle Zero-Day Before Patch

An active extortion campaign by ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, with Google notifying over 100 organizations—68% in higher education. The attackers used customized MeshCentral agents for C2, actions occurring before Oracle’s June 10 advisory. This highlights the growing threat of zero-day exploitation in widely used enterprise software and the education sector’s vulnerability.

2 sources

Source: The Star Online (my) · Reuters Last Updated (in)

Vulnerabilities Negative

Chinese State Hackers Weaponize Dell RecoverPoint Zero-Day Since Mid-2024

A sophisticated Chinese cyberespionage group, tracked as UNC6201, has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines for nearly two years. The flaw, identified as CVE-2026-22769, allowed attackers to maintain long-term persistence and conduct stealthy malware campaigns against high-value targets.

4 sources

Source: securityaffairs.co · SecurityWeek

Mandiant is linked from 3 stories on this site, each scored at or above our 35% relevance threshold — see how these pages are built.

See something wrong on this page — a misattributed entity, a wrong stat, a broken source link? Report a data issue.