Mandiant vulnerabilities
8 CVEs tracked
Mandiant (Google Threat Intelligence Group) reporting focuses on an active compromise and extortion campaign by UNC6240 (ShinyHunters) targeting Oracle PeopleSoft infrastructure in the education sector. Another key narrative is Mandiant's transition to a new, unified threat actor naming system, replacing older conventions, which is a policy change and not a vulnerability. Defenders should prioritize inspecting Oracle PeopleSoft environments for actively exploited flaws referenced in the campaign, including CVE-2026-0265, CVE-2026-10523, CVE-2026-33032, CVE-2026-35273, and CVE-2026-50751.
Azərbaycanca: Mandiant (Google Threat Intelligence Group) hesabatları əsas diqqəti UNC6240 (ShinyHunters) qrupunun təhsil sektorunda Oracle PeopleSoft sistemlərinə qarşı aktiv istismar və hədə-qorxu kampaniyasına yönəldir. Digər əsas mövzu Mandiant-ın yeni APT adlandırma sisteminə keçidi və təhlükə aktorlarını izləmə taksonomiyasında baş verən dəyişiklikdir, lakin bu, zəiflik deyil. Müdafiəçilər Oracle PeopleSoft ilə bağlı CVE-2026-0265, CVE-2026-10523, CVE-2026-33032, CVE-2026-35273 və CVE-2026-50751 kimi aktiv istismar olunan zəifliklərə qarşı xüsusilə diqqətli olmalıdırlar.
This vendor's CVEs8
This hub is built from skopnix's own reporting on Mandiant: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.