# Mandiant

Type: Company

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/mandiant
Canonical HTML page: https://getcyberbrief.com/entity/mandiant

## Timeline

- **2026-06-12**: Google Confirms Exploitation — Google Threat Intelligence Group publicly confirms zero‑day exploitation by ShinyHunters and notifies over 100 affected organizations.
- **2026-06-11**: Google/Mandiant publish findings — Google’s threat intelligence blog details the campaign, attribution, and sector impact.
- **2026-06-11**: Oracle Releases Out‑of‑Band Advisory — Oracle publishes mitigations for CVE-2026-35273 and warns customers to apply them immediately, but no full patch is provided.
- **2026-06-10**: Oracle issues security advisory — Oracle publishes a patch and advisory for the PeopleSoft vulnerability, closing the zero-day window.
- **2026-06-09**: Campaign window closes — Last observed exploitation activity before Oracle issues its advisory.
- **2026-05-27**: Campaign begins — ShinyHunters starts active scanning and exploitation of the Oracle PeopleSoft zero-day.
- **2026-05-27**: Zero‑Day Exploitation Begins — According to Google and Mandiant, ShinyHunters starts actively exploiting CVE-2026-35273 to compromise PeopleSoft instances.
- **2026-02-18**: Patch Release — Dell issues critical security updates to address the RecoverPoint vulnerability.
- **2026-02-17**: Public Disclosure — Mandiant and GTIG reveal the 18-month-long zero-day exploitation campaign.
- **2026**: Attack Campaign Window — ShinyHunters targets ~300 instances across 100+ organizations, focusing on education sector. Deploys MeshCentral agents and lateral movement scripts.
- **2025-01-01**: Ongoing Espionage — Attackers maintain persistence and conduct malware campaigns across multiple sectors.
- **2024-06-01**: Initial Exploitation — UNC6201 begins weaponizing CVE-2026-22769 in targeted attacks.

## Recent coverage (3 stories)

### Google: ShinyHunters Hit 100+ Orgs in PeopleSoft Zero‑Day; 68% Were US Universities
2026-06-12 08:12:19 · Sentiment: Bearish · Impact: 7/10 · Sources: 2

Google and Mandiant confirm active exploitation of CVE-2026-35273, a critical unauthenticated RCE flaw in Oracle PeopleSoft. The ShinyHunters group compromised roughly 300 instances, with the higher education sector bearing 68% of the impact. Oracle has only released mitigations, leaving organizations exposed to data theft and extortion.
Full story: https://getcyberbrief.com/story/shinyhunters-peoplesoft-zero-day-100-orgs-68-percent-education

### 68% of Targets in Education: ShinyHunters Exploit Oracle Zero-Day Before Patch
2026-06-12 04:54:34 · Sentiment: Bearish · Impact: 7/10 · Sources: 2

An active extortion campaign by ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, with Google notifying over 100 organizations—68% in higher education. The attackers used customized MeshCentral agents for C2, actions occurring before Oracle’s June 10 advisory. This highlights the growing threat of zero-day exploitation in widely used enterprise software and the education sector’s vulnerability.
Full story: https://getcyberbrief.com/story/shinyhunters-oracle-peoplesoft-zero-day-education

### Chinese State Hackers Weaponize Dell RecoverPoint Zero-Day Since Mid-2024
2026-02-18 19:36:46 · Sentiment: Bearish · Impact: 8/10 · Sources: 4

A sophisticated Chinese cyberespionage group, tracked as UNC6201, has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines for nearly two years. The flaw, identified as CVE-2026-22769, allowed attackers to maintain long-term persistence and conduct stealthy malware campaigns against high-value targets.
Full story: https://getcyberbrief.com/story/chinese-hackers-dell-recoverpoint-zero-day

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.