Mandiant

Company

Last mentioned: 12h ago

Timeline

  1. Google Confirms Exploitation

    Google Threat Intelligence Group publicly confirms zero‑day exploitation by ShinyHunters and notifies over 100 affected organizations.

  2. Google/Mandiant publish findings

    Google’s threat intelligence blog details the campaign, attribution, and sector impact.

  3. Oracle Releases Out‑of‑Band Advisory

    Oracle publishes mitigations for CVE-2026-35273 and warns customers to apply them immediately, but no full patch is provided.

  4. Oracle issues security advisory

    Oracle publishes a patch and advisory for the PeopleSoft vulnerability, closing the zero-day window.

  5. Campaign window closes

    Last observed exploitation activity before Oracle issues its advisory.

  6. Campaign begins

    ShinyHunters starts active scanning and exploitation of the Oracle PeopleSoft zero-day.

  7. Zero‑Day Exploitation Begins

    According to Google and Mandiant, ShinyHunters starts actively exploiting CVE-2026-35273 to compromise PeopleSoft instances.

  8. Intelligence Warning

    Cybersecurity experts warn of 'gloves off' phase in state-sponsored cyber warfare.

  9. Stryker Breach

    Handala group claims responsibility for disrupting systems at U.S. medical giant Stryker.

  10. Infrastructure Probing

    Reports emerge of hackers targeting industrial facilities in Israel and Saudi Arabia.

  11. Conflict Commencement

    War breaks out, triggering a surge in pro-Iranian cyber activity.

  12. Patch Release

    Dell issues critical security updates to address the RecoverPoint vulnerability.

  13. Public Disclosure

    Mandiant and GTIG reveal the 18-month-long zero-day exploitation campaign.

  14. Attack Campaign Window

    ShinyHunters targets ~300 instances across 100+ organizations, focusing on education sector. Deploys MeshCentral agents and lateral movement scripts.

  15. Ongoing Espionage

    Attackers maintain persistence and conduct malware campaigns across multiple sectors.

  16. Initial Exploitation

    UNC6201 begins weaponizing CVE-2026-22769 in targeted attacks.

Stories mentioning Mandiant 4

threat-intel Bearish

68% of Targets in Education: ShinyHunters Exploit Oracle Zero-Day Before Patch

An active extortion campaign by ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, with Google notifying over 100 organizations—68% in higher education. The attackers used customized MeshCentral agents for C2, actions occurring before Oracle’s June 10 advisory. This highlights the growing threat of zero-day exploitation in widely used enterprise software and the education sector’s vulnerability.

2 sources
geopolitics Very Bearish

Iran-Linked Cyber Offensive Targets U.S. Defense and Critical Infrastructure

Pro-Iranian hacking groups have launched a coordinated cyber offensive against U.S. and Middle Eastern targets, including a significant breach of medical technology firm Stryker. These state-linked actors are shifting focus from financial extortion to data destruction and tactical intelligence gathering to support ongoing kinetic warfare.

2 sources
vulnerability Bearish

Chinese State Hackers Weaponize Dell RecoverPoint Zero-Day Since Mid-2024

A sophisticated Chinese cyberespionage group, tracked as UNC6201, has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines for nearly two years. The flaw, identified as CVE-2026-22769, allowed attackers to maintain long-term persistence and conduct stealthy malware campaigns against high-value targets.

4 sources