Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Your home connection could be routing traffic for strangers.
Your home connection could be routing traffic for strangers. Here's how residential proxy networks work, how devices get enrolled and what our telemetry reveals about the risks for consumers.
Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure.
Mandiant and Google Threat Intelligence Group identified a campaign by ShinyHunters exploiting CVE-2026-35273, a critical zero-day in Oracle PeopleSoft. The attackers targeted over 100 organizations, primarily in higher education, using MeshCentral agents to move laterally and steal data.
Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component.
Mandiant and Google Threat Intelligence Group identified a campaign by ShinyHunters exploiting CVE-2026-35273, a critical zero-day in Oracle PeopleSoft. The attackers targeted over 100 organizations, primarily in higher education, using MeshCentral agents to move laterally and steal data.