# ShinyHunters (UNC6240)

Type: hacker_group

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/shinyhunters-unc6240
Canonical HTML page: https://getcyberbrief.com/entity/shinyhunters-unc6240

## Timeline

- **2026-06-12**: Google Confirms Exploitation — Google Threat Intelligence Group publicly confirms zero‑day exploitation by ShinyHunters and notifies over 100 affected organizations.
- **2026-06-11**: Oracle Releases Out‑of‑Band Advisory — Oracle publishes mitigations for CVE-2026-35273 and warns customers to apply them immediately, but no full patch is provided.
- **2026-05-27**: Zero‑Day Exploitation Begins — According to Google and Mandiant, ShinyHunters starts actively exploiting CVE-2026-35273 to compromise PeopleSoft instances.
- **2026**: Attack Campaign Window — ShinyHunters targets ~300 instances across 100+ organizations, focusing on education sector. Deploys MeshCentral agents and lateral movement scripts.

## Recent coverage (1 stories)

### Google: ShinyHunters Hit 100+ Orgs in PeopleSoft Zero‑Day; 68% Were US Universities
2026-06-12 08:12:19 · Sentiment: Bearish · Impact: 7/10 · Sources: 2

Google and Mandiant confirm active exploitation of CVE-2026-35273, a critical unauthenticated RCE flaw in Oracle PeopleSoft. The ShinyHunters group compromised roughly 300 instances, with the higher education sector bearing 68% of the impact. Oracle has only released mitigations, leaving organizations exposed to data theft and extortion.
Full story: https://getcyberbrief.com/story/shinyhunters-peoplesoft-zero-day-100-orgs-68-percent-education

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.