Cybersecurity entity

ShinyHunters (UNC6240)

hacker_group

vulnerability is the sole category represented across all 1 tracked stories. Google is the most frequent co-covered peer, appearing in 1 of the 1 tracked story. The tracked stories average 2 original sources each. ShinyHunters (UNC6240) appears in 1 tracked Cybersecurity story from June 12, 2026.

Last mentioned: Jun 12, 2026

Entity pulse

Recent coverage · ShinyHunters (UNC6240)

1 story
7 avg impact
0% positive
100% negative

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 100 percentage points.

  • 100% negative

Figures are computed live from our source-verified story record — see our methodology for how impact and sentiment are derived.

What the coverage shows about ShinyHunters (UNC6240)

vulnerability is the sole category represented across all 1 tracked stories. Google is the most frequent co-covered peer, appearing in 1 of the 1 tracked story. The tracked stories average 2 original sources each. ShinyHunters (UNC6240) appears in 1 tracked Cybersecurity story from June 12, 2026.

Stories tracked
1
Sources per story
2

Computed from the 1 stories linked to this entity, with beat comparisons drawn from all 6 Cybersecurity stories published in the same date window. Shares are omitted below five stories and comparisons below a twenty-story baseline.

Coverage cohort

Appears alongside

Other entities that clear the same relevance threshold in stories also covering ShinyHunters (UNC6240). Shared-story counts are live from our verified record — not editorial picks.

Timeline

  1. Google Confirms Exploitation

    Google Threat Intelligence Group publicly confirms zero‑day exploitation by ShinyHunters and notifies over 100 affected organizations.

  2. Oracle Releases Out‑of‑Band Advisory

    Oracle publishes mitigations for CVE-2026-35273 and warns customers to apply them immediately, but no full patch is provided.

  3. Zero‑Day Exploitation Begins

    According to Google and Mandiant, ShinyHunters starts actively exploiting CVE-2026-35273 to compromise PeopleSoft instances.

  4. Attack Campaign Window

    ShinyHunters targets ~300 instances across 100+ organizations, focusing on education sector. Deploys MeshCentral agents and lateral movement scripts.

Stories mentioning ShinyHunters (UNC6240) 1

Vulnerabilities Negative

Google: ShinyHunters Hit 100+ Orgs in PeopleSoft Zero‑Day; 68% Were US Universities

Google and Mandiant confirm active exploitation of CVE-2026-35273, a critical unauthenticated RCE flaw in Oracle PeopleSoft. The ShinyHunters group compromised roughly 300 instances, with the higher education sector bearing 68% of the impact. Oracle has only released mitigations, leaving organizations exposed to data theft and extortion.

2 sources

Source: SecurityWeek · SecurityWeek

ShinyHunters (UNC6240) is linked from 1 story on this site, each scored at or above our 35% relevance threshold — see how these pages are built.

See something wrong on this page — a misattributed entity, a wrong stat, a broken source link? Report a data issue.