After its May 27–June 9 campaign, ShinyHunters resumed large-scale exploitation of the same Oracle PeopleSoft flaw, CVE-2026-35273, and broadened its targeting from education to multiple sectors worldwide, according to Google’s Mandiant and Threat Intelligence Group. ShinyHunters’ separate claim tha After its May 27...
Published byEdited with GPT-6 LunaImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: How did ShinyHunters expand its exploitation of an Oracle PeopleSoft vulnerability after its May 27–June 9, 2026 attacks, why did web applic. Article summary: After its May 27–June 9 campaign, ShinyHunters resumed large scale exploitation of the same Oracle PeopleSoft flaw, CVE 2026 35273, and broadened its targeting from education to multiple sectors worldwide, according to G. Topic tags: general web, code, security, marketing, social media. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks
After its May 27–June 9 campaign, ShinyHunters resumed large-scale exploitation of the same Oracle PeopleSoft flaw, CVE-2026-35273, and broadened its targeting from education to multiple sectors worldwide, according to Google’s Mandiant and Threat Intelligence Group. ShinyHunters’ separate claim that it stole sensitive FBI personnel data remains unverified in the evidence available here. 7
15
2
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
After its May 27–June 9 campaign, ShinyHunters resumed large-scale exploitation of the same Oracle PeopleSoft flaw, CVE-2026-35273, and broadened its targeting from education to multiple sectors worldwide, according to Google’s Mandiant and Threat Intelligence Group. ShinyHunters’ separate claim tha
After its May 27–June 9 campaign, ShinyHunters resumed large-scale exploitation of the same Oracle PeopleSoft flaw, CVE-2026-35273, and broadened its targeting from education to multiple sectors worldwide, according to Google’s Mandiant and Threat Intelligence Group. ShinyHunters’ separate claim tha After its May 27–June 9 campaign, ShinyHunters resumed large-scale exploitation of the same Oracle PeopleSoft flaw, CVE-2026-35273, and broadened its targeting from education to multiple sectors worldwide, according to Google’s Mandiant and Threat Intelligence Group. ShinyHunters
**How the attacks expanded:** Mandiant tracks the group as UNC6240 and described the later activity as renewed “mass exploitation,” rather than a continuation limited to the original education targets. [7][15]