Introduction As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. In June, the threat actor exploited this vulnerability as a zero-day predominantly against academic institutions.
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
About this summary. This is a short, independently written summary of an article first published by Google Threat Intelligence Group. Cyber Security News did not report or verify the underlying story. Read the original: https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft/
Source attribution: headline and facts are from Google Threat Intelligence Group (cloud.google.com). Summary method: excerpt of the source description. See our source attribution policy.






