ShinyHunters (UNC6240)

hacker_group

Last mentioned: Jun 12, 2026

Share

Across the most recent 1 story covering ShinyHunters (UNC6240) — 100% negative sentiment, averaging 7/10 impact.

This entity profile aggregates every story where the entity meets our minimum relevance threshold before it is linked here — a story naming this entity only in passing, as competitive context for an unrelated subject, does not qualify. That threshold exists because earlier testing surfaced entity pages cluttered with tangential mentions: a story about two unrelated companies merging could otherwise populate a third company's page simply because it was named once for comparison, with no real event of its own. The timeline below reflects genuine milestones and developments specific to this entity, cross-referenced against the same source-verification standard applied to every story on this site. Sentiment measures the directional read of each development for this entity specifically, not the overall tone of the reporting, and impact weights how consequential a development is rather than how widely it was syndicated across outlets.

Figures are computed live from our source-verified story record — see our methodology for how impact and sentiment are derived.

Timeline

  1. Google Confirms Exploitation

    Google Threat Intelligence Group publicly confirms zero‑day exploitation by ShinyHunters and notifies over 100 affected organizations.

  2. Oracle Releases Out‑of‑Band Advisory

    Oracle publishes mitigations for CVE-2026-35273 and warns customers to apply them immediately, but no full patch is provided.

  3. Zero‑Day Exploitation Begins

    According to Google and Mandiant, ShinyHunters starts actively exploiting CVE-2026-35273 to compromise PeopleSoft instances.

  4. Attack Campaign Window

    ShinyHunters targets ~300 instances across 100+ organizations, focusing on education sector. Deploys MeshCentral agents and lateral movement scripts.

Stories mentioning ShinyHunters (UNC6240) 1

Vulnerabilities Bearish

Google: ShinyHunters Hit 100+ Orgs in PeopleSoft Zero‑Day; 68% Were US Universities

Google and Mandiant confirm active exploitation of CVE-2026-35273, a critical unauthenticated RCE flaw in Oracle PeopleSoft. The ShinyHunters group compromised roughly 300 instances, with the higher education sector bearing 68% of the impact. Oracle has only released mitigations, leaving organizations exposed to data theft and extortion.

2 sources

Source: SecurityWeek · SecurityWeek

About ShinyHunters (UNC6240) coverage

This page surfaces every story mentioning ShinyHunters (UNC6240) across our cybersecurity coverage. We track each entity's appearance over time so readers can trace how the narrative evolves — which developments are isolated incidents, which build into longer arcs, and which reframe how operators in the space think about the entity. Story selection uses the same multi-source verification gate applied across the rest of our coverage.

Read our editorial methodology for how we identify, deduplicate, and score entity references. Our glossary defines the technical terms used across stories on this page, and our trends index contextualizes individual developments against the longer-running cybersecurity beat. Cross-entity comparisons live on our compare view.

Entities only appear on this page once the classifier scores them at a minimum 35 percent relevance to the story, filtering out passing mentions. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong on this page — a misattributed entity, a wrong stat, a broken source link? Report a data issue.

What you seeWhat it tells you
Story countNumber of distinct stories where ShinyHunters (UNC6240) was a primary or referenced actor.
Recency clusteringWhether mentions are concentrated in a recent window (a news cycle) or distributed (a sustained arc).
Sentiment distributionAggregate sentiment of the stories mentioning this entity, weighted by impact score.
Cross-niche linksWhen the same entity surfaces in our sibling networks, we link to those views to enrich context.