Cross-Sector entity

Mandiant

Company
7.5

Mandiant is most often covered alongside Google, which appears in 2 of these 4 stories. Across a 115-day span, the pace is roughly 0.2 stories per week. The busiest single day carried 2. Coverage clusters in vulnerability, which accounts for 2 of those 4, with the remainder spread across 2 other categories.

4 verified stories tracked

Last mentioned: Jun 12, 2026

Entity pulse

Recent coverage · Mandiant

4 stories
7.5 avg impact
0% positive
100% negative

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 100 percentage points.

  • 100% negative

Figures are computed live from our source-verified story record — see our methodology for how impact and sentiment are derived.

What the coverage shows about Mandiant

Mandiant is most often covered alongside Google, which appears in 2 of these 4 stories. Across a 115-day span, the pace is roughly 0.2 stories per week. The busiest single day carried 2. Coverage clusters in vulnerability, which accounts for 2 of those 4, with the remainder spread across 2 other categories. The tracked stories average 2.5 original sources each. This profile follows 4 Cross-Sector stories mentioning Mandiant across the period from February 18, 2026 to June 12, 2026.

Stories tracked
4
Per week
0.2
Sources per story
2.5

Computed from the 4 stories linked to this entity. Beat comparisons are omitted because no baseline was available for this window.

Coverage cohort

Appears alongside

Other entities that clear the same relevance threshold in stories also covering Mandiant. Shared-story counts are live from our verified record — not editorial picks.

Timeline

  1. Google Confirms Exploitation

    Google Threat Intelligence Group publicly confirms zero‑day exploitation by ShinyHunters and notifies over 100 affected organizations.

  2. Google/Mandiant publish findings

    Google’s threat intelligence blog details the campaign, attribution, and sector impact.

  3. Oracle Releases Out‑of‑Band Advisory

    Oracle publishes mitigations for CVE-2026-35273 and warns customers to apply them immediately, but no full patch is provided.

  4. Campaign window closes

    Last observed exploitation activity before Oracle issues its advisory.

  5. Campaign begins

    ShinyHunters starts active scanning and exploitation of the Oracle PeopleSoft zero-day.

  6. Zero‑Day Exploitation Begins

    According to Google and Mandiant, ShinyHunters starts actively exploiting CVE-2026-35273 to compromise PeopleSoft instances.

  7. Intelligence Warning

    Cybersecurity experts warn of 'gloves off' phase in state-sponsored cyber warfare.

  8. Stryker Breach

    Handala group claims responsibility for disrupting systems at U.S. medical giant Stryker.

  9. Infrastructure Probing

    Reports emerge of hackers targeting industrial facilities in Israel and Saudi Arabia.

  10. Conflict Commencement

    War breaks out, triggering a surge in pro-Iranian cyber activity.

  11. Patch Release

    Dell issues critical security updates to address the RecoverPoint vulnerability.

  12. Public Disclosure

    Mandiant and GTIG reveal the 18-month-long zero-day exploitation campaign.

  13. Attack Campaign Window

    ShinyHunters targets ~300 instances across 100+ organizations, focusing on education sector. Deploys MeshCentral agents and lateral movement scripts.

  14. Ongoing Espionage

    Attackers maintain persistence and conduct malware campaigns across multiple sectors.

  15. Initial Exploitation

    UNC6201 begins weaponizing CVE-2026-22769 in targeted attacks.

Stories mentioning Mandiant 4

Cyber vulnerability Negative 7

Google: ShinyHunters Hit 100+ Orgs in PeopleSoft Zero‑Day; 68% Were US Universities

Google and Mandiant confirm active exploitation of CVE-2026-35273, a critical unauthenticated RCE flaw in Oracle PeopleSoft. The ShinyHunters group compromised roughly 300 instances, with the higher education sector bearing 68% of the impact. Oracle has only released mitigations, leaving organizations exposed to data theft and extortion.

2 sources

Source: SecurityWeek · SecurityWeek

Cyber threat intel Negative 7

68% of Targets in Education: ShinyHunters Exploit Oracle Zero-Day Before Patch

An active extortion campaign by ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, with Google notifying over 100 organizations—68% in higher education. The attackers used customized MeshCentral agents for C2, actions occurring before Oracle’s June 10 advisory. This highlights the growing threat of zero-day exploitation in widely used enterprise software and the education sector’s vulnerability.

2 sources

Source: The Star Online (my) · Reuters Last Updated (in)

Space & Defense geopolitics Strongly negative 8

Iran-Linked Cyber Offensive Targets U.S. Defense and Critical Infrastructure

Pro-Iranian hacking groups have launched a coordinated cyber offensive against U.S. and Middle Eastern targets, including a significant breach of medical technology firm Stryker. These state-linked actors are shifting focus from financial extortion to data destruction and tactical intelligence gathering to support ongoing kinetic warfare.

2 sources

Source: The Associated Press (ca) · Associated Press (ph)

Cyber vulnerability Negative 8

Chinese State Hackers Weaponize Dell RecoverPoint Zero-Day Since Mid-2024

A sophisticated Chinese cyberespionage group, tracked as UNC6201, has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines for nearly two years. The flaw, identified as CVE-2026-22769, allowed attackers to maintain long-term persistence and conduct stealthy malware campaigns against high-value targets.

4 sources

Source: securityaffairs.co · SecurityWeek