# Mandiant

Type: Company

Source: GetYourBrief — https://getyourbrief.com/entity/mandiant
Canonical HTML page: https://getyourbrief.com/entity/mandiant

## Timeline

- **2026-06-12**: Google Confirms Exploitation — Google Threat Intelligence Group publicly confirms zero‑day exploitation by ShinyHunters and notifies over 100 affected organizations.
- **2026-06-11**: Google/Mandiant publish findings — Google’s threat intelligence blog details the campaign, attribution, and sector impact.
- **2026-06-11**: Oracle Releases Out‑of‑Band Advisory — Oracle publishes mitigations for CVE-2026-35273 and warns customers to apply them immediately, but no full patch is provided.
- **2026-06-10**: Oracle issues security advisory — Oracle publishes a patch and advisory for the PeopleSoft vulnerability, closing the zero-day window.
- **2026-06-09**: Campaign window closes — Last observed exploitation activity before Oracle issues its advisory.
- **2026-05-27**: Campaign begins — ShinyHunters starts active scanning and exploitation of the Oracle PeopleSoft zero-day.
- **2026-05-27**: Zero‑Day Exploitation Begins — According to Google and Mandiant, ShinyHunters starts actively exploiting CVE-2026-35273 to compromise PeopleSoft instances.
- **2026-03-12**: Intelligence Warning — Cybersecurity experts warn of 'gloves off' phase in state-sponsored cyber warfare.
- **2026-03-11**: Stryker Breach — Handala group claims responsibility for disrupting systems at U.S. medical giant Stryker.
- **2026-03-05**: Infrastructure Probing — Reports emerge of hackers targeting industrial facilities in Israel and Saudi Arabia.
- **2026-02-28**: Conflict Commencement — War breaks out, triggering a surge in pro-Iranian cyber activity.
- **2026-02-18**: Patch Release — Dell issues critical security updates to address the RecoverPoint vulnerability.
- **2026-02-17**: Public Disclosure — Mandiant and GTIG reveal the 18-month-long zero-day exploitation campaign.
- **2026**: Attack Campaign Window — ShinyHunters targets ~300 instances across 100+ organizations, focusing on education sector. Deploys MeshCentral agents and lateral movement scripts.
- **2025-01-01**: Ongoing Espionage — Attackers maintain persistence and conduct malware campaigns across multiple sectors.

## Recent coverage (4 stories, network-wide)

### Google: ShinyHunters Hit 100+ Orgs in PeopleSoft Zero‑Day; 68% Were US Universities
2026-06-12 08:12:19 · Sector: cyber · Sentiment: Negative · Impact: 7/10 · Sources: 2

Google and Mandiant confirm active exploitation of CVE-2026-35273, a critical unauthenticated RCE flaw in Oracle PeopleSoft. The ShinyHunters group compromised roughly 300 instances, with the higher education sector bearing 68% of the impact. Oracle has only released mitigations, leaving organizations exposed to data theft and extortion.
Full story: https://getcyberbrief.com/story/shinyhunters-peoplesoft-zero-day-100-orgs-68-percent-education

### 68% of Targets in Education: ShinyHunters Exploit Oracle Zero-Day Before Patch
2026-06-12 04:54:34 · Sector: cyber · Sentiment: Negative · Impact: 7/10 · Sources: 2

An active extortion campaign by ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft, with Google notifying over 100 organizations—68% in higher education. The attackers used customized MeshCentral agents for C2, actions occurring before Oracle’s June 10 advisory. This highlights the growing threat of zero-day exploitation in widely used enterprise software and the education sector’s vulnerability.
Full story: https://getcyberbrief.com/story/shinyhunters-oracle-peoplesoft-zero-day-education

### Iran-Linked Cyber Offensive Targets U.S. Defense and Critical Infrastructure
2026-03-13 00:22:25 · Sector: space · Sentiment: Strongly negative · Impact: 8/10 · Sources: 2

Pro-Iranian hacking groups have launched a coordinated cyber offensive against U.S. and Middle Eastern targets, including a significant breach of medical technology firm Stryker. These state-linked actors are shifting focus from financial extortion to data destruction and tactical intelligence gathering to support ongoing kinetic warfare.
Full story: https://getspacebrief.com/story/iran-linked-cyber-offensive-stryker-attack

### Chinese State Hackers Weaponize Dell RecoverPoint Zero-Day Since Mid-2024
2026-02-18 19:36:46 · Sector: cyber · Sentiment: Negative · Impact: 8/10 · Sources: 4

A sophisticated Chinese cyberespionage group, tracked as UNC6201, has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines for nearly two years. The flaw, identified as CVE-2026-22769, allowed attackers to maintain long-term persistence and conduct stealthy malware campaigns against high-value targets.
Full story: https://getcyberbrief.com/story/chinese-hackers-dell-recoverpoint-zero-day

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getyourbrief.com/guides/methodology for the full editorial methodology.