INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters Exploits Oracle PeopleSoft Flaw via WAF Bypass
| 2026-09-26 11:46 CRITICAL HIGHExecutive Summary AI-generated
The ShinyHunters extortion gang has been exploiting a zero-day vulnerability in Oracle PeopleSoft servers, allowing them to steal data from 100 organizations. The threat actors use an executable named 'Ple64.exe' that masquerades as a signed Light Alloy media player installer but installs a backdoor tracked by Google as SIDEEYE. ShinyHunters also deploy web shells on dozens of systems worldwide in higher education, technology, IT services, healthcare, agriculture, transportation, and government organizations using compromised Windows servers. The gang is targeting vulnerable Oracle PeopleSoft servers with the CVE-2026-35273 flaw, which allows unauthenticated remote code execution. Mandiant urges organizations to install the latest security update to protect against this vulnerability.
Technical Mitigations AI-generated
* Use the latest security update to protect against CVE-2026-35273, as it allows unauthenticated remote code execution and provides a more robust defense against WAF bypass tricks.
* Implement additional remediation and hardening guidance for Oracle PeopleSoft systems running vulnerable versions of the software, including:
- Searching WebLogic access logs for requests to '/PSEMHUB/' and encoded variants such as '/%50SEMHUB/'.
- Monitoring for signs of exploitation, such as POST requests containing serialized Java objects returning information about the host operating system without writing files or disrupting service.
* Consider implementing a web application firewall (WAF) bypass mitigation strategy that detects and blocks percent-encoded versions of URLs like '/PSEMHUB/', rather than relying solely on WAF rules designed to block literal paths.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Neo-reGeorgNeo-reGeorg
CVE-2026-35273CVE-2026-35273
Target & Sectors
Global Scope
educationeducation
healthcarehealthcare
technologytechnology
transportationtransportation
mediamedia
governmentgovernment
Incident Timeline
May 2026
The ShinyHunters group targeted the FBI after a May 2026 public advisory detailing its tactics and warning victims against paying stole about 2-3 TB of sensitive data from the U.S. Federal Bureau of Investigation's FBIJobs.gov portal.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
The disclosure comes as the ShinyHunters group
broke
into the U.S. Federal Bureau of Investigation's FBIJobs.gov portal (which
remains inaccessible
as of writing) and stole about 2-3 TB of sensitive data to contest allegations made by the agency against the group in a May 2026 alert.
ShinyHunters said the FBI was targeted in response to a
May 2026 public service announcement
(PSA) that detailed the threat actor's targeting of
Canvas
, an online Learning Management System (LMS), while urging victims not to pay.
data_breach
2 TB
The disclosure comes as the ShinyHunters group
broke
into the U.S. Federal Bureau of Investigation's FBIJobs.gov portal (which
remains inaccessible
as of writing) and stole about 2-3 TB of sensitive data to contest allegations made by the agency against the group in a May 2026 alert.
attribution
FBI
The group says it targeted the FBI after a May 2026 public advisory describing its tactics and warning victims against paying.
ShinyHunters said the FBI was targeted in response to a
May 2026 public service announcement
(PSA) that detailed the threat actor's targeting of
Canvas
, an online Learning Management System (LMS), while urging victims not to pay.
attribution
Learning Management System
ShinyHunters said the FBI was targeted in response to a
May 2026 public service announcement
(PSA) that detailed the threat actor's targeting of
Canvas
, an online Learning Management System (LMS), while urging victims not to pay.
attribution
LMS
ShinyHunters said the FBI was targeted in response to a
May 2026 public service announcement
(PSA) that detailed the threat actor's targeting of
Canvas
, an online Learning Management System (LMS), while urging victims not to pay.
June 10
ShinyHunters used a zero-day vulnerability in Oracle PeopleSoft to breach the systems of 100 global organizations on June 10.
Click on any entity below to view its context and source!
tactic
Extortion
On June 10,
BleepingComputer first reported
that the ShinyHunters extortion gang was targeting Oracle PeopleSoft servers using a zero-day vulnerability, allowing them to steal data from 100 organizations.
threat_actor
ShinyHunters
On June 10,
BleepingComputer first reported
that the ShinyHunters extortion gang was targeting Oracle PeopleSoft servers using a zero-day vulnerability, allowing them to steal data from 100 organizations.
victims
100 global organizations
On June 10,
BleepingComputer first reported
that the ShinyHunters extortion gang was targeting Oracle PeopleSoft servers using a zero-day vulnerability, allowing them to steal data from 100 organizations.
organisation
BleepingComputer
On June 10,
BleepingComputer first reported
that the ShinyHunters extortion gang was targeting Oracle PeopleSoft servers using a zero-day vulnerability, allowing them to steal data from 100 organizations.
June 2026
ShinyHunters exploited a previously unknown vulnerability in PeopleSoft, CVE-2026-35273.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-35273
However, ShinyHunters weaponized a similar flaw (
CVE-2026-35273
) in June 2026 to break into enterprise networks and extort victims.
threat_actor
ShinyHunters
However, ShinyHunters weaponized a similar flaw (
CVE-2026-35273
) in June 2026 to break into enterprise networks and extort victims.
September 22
ShinyHunters used a zero-day attack to gain remote code execution on the FBI Jobs platform, allowing them to access and spread laterally into the FBI's AWS GovCloud infrastructure.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
ShinyHunters told BleepingComputer on September 22 that the alleged vulnerability allowed remote code execution and was used to access the FBI Jobs platform, then spread laterally into the FBI's AWS GovCloud infrastructure.
threat_actor
ShinyHunters
ShinyHunters told BleepingComputer on September 22 that the alleged vulnerability allowed remote code execution and was used to access the FBI Jobs platform, then spread laterally into the FBI's AWS GovCloud infrastructure.
The claim surfaced on September 22 and quickly drew attention after ShinyHunters said it had obtained data on a large number of current and former FBI personnel.
attribution
FBI
ShinyHunters told BleepingComputer on September 22 that the alleged vulnerability allowed remote code execution and was used to access the FBI Jobs platform, then spread laterally into the FBI's AWS GovCloud infrastructure.
The claim surfaced on September 22 and quickly drew attention after ShinyHunters said it had obtained data on a large number of current and former FBI personnel.
data_breach
23 September
"
"One small operational clue is the September 23 timestamp on the group's post, while the news emerged on September 22 in the U.S.
Sep 23, 2026
Threat actors used a zero-day exploit in PeopleSoft to gain unauthorized access to ShinyHunters' system.
September 23, 2026
ShinyHunters used a PeopleSoft zero-day attack to breach the FBI.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack
Pierluigi Paganini
September 23, 2026
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet.
attribution
FBI
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack
Pierluigi Paganini
September 23, 2026
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet.
Sep 26, 2026
Threat actors exploited a previously unknown vulnerability in PeopleSoft, allowing them to gain unauthorized access and breach the FBI's internal systems.
2026/09/26
ShinyHunters claimed to have breached the U.S. Federal Bureau of Investigation (FBI) and stolen sensitive information belonging to FBI employees and job applicants via a zero-day vulnerability in Oracle PeopleSoft.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Google also reported that same day that ShinyHunters, whom they track as UNC6240, was exploiting the CVE-2026-35273 flaw in attacks on the education sector, confirming BleepingComputer's reporting.
Google and Mandiant later linked exploitation of that flaw to ShinyHunters activity targeting organizations, particularly in the education sector.
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
Ravie Lakshmanan
Sep 23, 2026
Data Breach / Cybercrime
The cyber extortion group known as
ShinyHunters
on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.
The ShinyHunters-linked activity involves the weaponization of
CVE-2026-35273
(CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution.
"
A ShinyHunters spokesperson told The Register that the group exploited a new Oracle PeopleSoft zero-day vulnerability to gain remote code execution and deface the FBI's jobs site with a "This site has been seized by ShinyHunters" banner.
"We want to reiterate and emphasise that we are NOT extorting the FBI," a ShinyHunters spokesperson told The Hacker News.
In a separate statement shared with The Register, the group
said
they
started off
as
GnosticPlayers
before rebranding to ShinyHunters in 2020.
On compromised Windows servers, ShinyHunters used these shells to deploy an executable named 'Ple64.exe', which masquerades as a signed Light Alloy media player installer but installs a backdoor tracked by Google as SIDEEYE.
Mandiant also observed ShinyHunters using the legitimate MeshAgent remote management software to maintain access to compromised Linux systems.
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks.
However, in a
new report
, Google says ShinyHunters has now modified its exploit to bypass WAF rules that look for this literal path, rather than encoded versions of it.
PSEMHUB WAF bypass
Source: Mandiant
Google warns ShinyHunters may not always use the '%50' bypass variation, and could switch to other percent-encoded, mixed-case, or other variations of '/PSEMHUB/' to bypass WAFs.
On vulnerable systems, these requests return information about the host operating system without writing files or disrupting the service, allowing ShinyHunters to determine whether a server can be exploited quietly.
ShinyHunters previously claimed a new PeopleSoft zero-day
These new attacks come after
ShinyHunters claimed that they breached FBI systems
using what they described as a new Oracle PeopleSoft zero-day vulnerability.
ShinyHunters has confirmed to BleepingComputer that they used this WAF bypass against FBI Jobs, but continue to claim that they also exploited "NEW unknown vulnerability in the same PSEMHUB component.
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack.
The popular cybercrime group ShinyHunters
is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants.
The agency has not confirmed that its internal systems were compromised or that ShinyHunters obtained the data it claims to possess.
ShinyHunters has provided a possible technical explanation for the alleged intrusion.
The claim is notable because ShinyHunters has already been linked to attacks exploiting a real PeopleSoft zero-day earlier this year.
There is also a clear motive behind the operation claimed by ShinyHunters.
ShinyHunters disputes the FBI’s characterization of its activities and is reportedly demanding that the Bureau retract or correct the warning.
ShinyHunters has recently claimed responsibility for several major breaches and has been involved in a public dispute with the
Clop cybercrime operation
.
Until investigators confirm the intrusion, the extent of access and the origin of the leaked records, the ShinyHunters account should remain a claim rather than an established FBI breach.
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants.
Kindly excuse our unprofessionalism."
"ShinyHunters; claim of an FBI breach is an unusually provocative move in the ongoing contest between law enforcement and cybercrime groups and should absolutely be taken seriously," Etay Maor, VP of threat intelligence at Cato Networks, said.
"
Maor also described ShinyHunters as a resilient criminal brand that has managed to outlast takedowns, arrests, and forum seizures by evolving its methods and attracting new operators, suggesting it's more than a "fixed set of people or infrastructure.
organisation
Google
Google also reported that same day that ShinyHunters, whom they track as UNC6240, was exploiting the CVE-2026-35273 flaw in attacks on the education sector, confirming BleepingComputer's reporting.
Google and Mandiant later linked exploitation of that flaw to ShinyHunters activity targeting organizations, particularly in the education sector.
Ravie Lakshmanan
Sep 26, 2026
Vulnerability / Web Security
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.
organisation
Mandiant
Google and Mandiant later linked exploitation of that flaw to ShinyHunters activity targeting organizations, particularly in the education sector.
At that time, Google-owned Mandiant said it initiated notifications to over 100 global organizations whose IP addresses matched vulnerable endpoints, most of them located in the U.S.
"This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint," Mandiant
said
.
At the time, Mandiant advised organizations that could not immediately install the security updates or disable the Environment Management Hub to block external access to the vulnerable `/PSEMHUB/*` endpoint.
organisation
MeshCentral
The vulnerability was
first exploited
as a zero-day in attacks against academic institutions to conduct reconnaissance, deploy remote access software like MeshCentral agent for persistence, move laterally over SSH, run a shell script to connect via SSH to other internal PeopleSoft machines using known username/password combinations, and steal data.
organisation
SSH
The vulnerability was
first exploited
as a zero-day in attacks against academic institutions to conduct reconnaissance, deploy remote access software like MeshCentral agent for persistence, move laterally over SSH, run a shell script to connect via SSH to other internal PeopleSoft machines using known username/password combinations, and steal data.
organisation
PeopleSoft
The vulnerability was
first exploited
as a zero-day in attacks against academic institutions to conduct reconnaissance, deploy remote access software like MeshCentral agent for persistence, move laterally over SSH, run a shell script to connect via SSH to other internal PeopleSoft machines using known username/password combinations, and steal data.
The next day,
Oracle fixed the PeopleSoft zero-day
as CVE-2026-35273, stating that it allows unauthenticated remote code execution.
There are currently no details of a PeopleSoft pre-authenticated RCE zero-day.
organisation
CVE-2026-35273
The next day,
Oracle fixed the PeopleSoft zero-day
as CVE-2026-35273, stating that it allows unauthenticated remote code execution.
organisation
Data Breach / Cybercrime
Ravie Lakshmanan
Sep 23, 2026
Data Breach / Cybercrime
The cyber extortion group known as
ShinyHunters
on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.
organisation
the U.S. Federal Bureau of Investigation
Ravie Lakshmanan
Sep 23, 2026
Data Breach / Cybercrime
The cyber extortion group known as
ShinyHunters
on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.
organisation
The Register
In a separate statement shared with The Register, the group
said
they
started off
as
GnosticPlayers
before rebranding to ShinyHunters in 2020.
organisation
GnosticPlayers
In a separate statement shared with The Register, the group
said
they
started off
as
GnosticPlayers
before rebranding to ShinyHunters in 2020.
infrastructure
Windows
On compromised Windows servers, ShinyHunters used these shells to deploy an executable named 'Ple64.exe', which masquerades as a signed Light Alloy media player installer but installs a backdoor tracked by Google as SIDEEYE.
infrastructure
Linux
Mandiant also observed ShinyHunters using the legitimate MeshAgent remote management software to maintain access to compromised Linux systems.
"To establish persistent access after web shell placement on Linux systems, UNC6240 deployed the legitimate RMM tool MeshAgent.
organisation
MeshAgent
Mandiant also observed ShinyHunters using the legitimate MeshAgent remote management software to maintain access to compromised Linux systems.
"To establish persistent access after web shell placement on Linux systems, UNC6240 deployed the legitimate RMM tool MeshAgent.
organisation
Oracle PeopleSoft
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks.
Ravie Lakshmanan
Sep 26, 2026
Vulnerability / Web Security
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.
organisation
JSP
Drop two JSP web shells in the PSEMHUB.war directory with an aim to minimize WAF detections during post-exploitation: "x.jsp" enables cross-platform command execution, while "u.jsp" allows chunked file uploads to the server and command execution via "cmd.exe.
Once they determine a system is vulnerable, the threat actors exploit the flaw again to execute commands directly in memory or deploy JSP web shells.
organisation
TCP
"
Use "u.jsp" to upload a valid, signed trojanized installer ("Ple64.exe") that loads in memory SIDEEYE, a C++ backdoor that communicates with an external server ("162.219.30[.]165") over TCP to facilitate browser and desktop application credential theft, process and file management, interactive reverse shell and reverse proxy capabilities.
organisation
RMM
"To establish persistent access after web shell placement on Linux systems, UNC6240 deployed the legitimate RMM tool MeshAgent.
data_breach
2 TB
The group claimed it stole between 2TB and 3TB of data related to current and former FBI employees, job applicants, and other internal systems.
They allegedly said that between 2 TB and 3 TB of data had been taken and that the FBI jobs infrastructure had been compromised.
data_breach
3 TB
The group claimed it stole between 2TB and 3TB of data related to current and former FBI employees, job applicants, and other internal systems.
They allegedly said that between 2 TB and 3 TB of data had been taken and that the FBI jobs infrastructure had been compromised.
organisation
IP
At that time, Google-owned Mandiant said it initiated notifications to over 100 global organizations whose IP addresses matched vulnerable endpoints, most of them located in the U.S.
"This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint," Mandiant
said
.
victims
100 global organizations
At that time, Google-owned Mandiant said it initiated notifications to over 100 global organizations whose IP addresses matched vulnerable endpoints, most of them located in the U.S.
"This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint," Mandiant
said
.
organisation
the Environment Management Hub
At the time, Mandiant advised organizations that could not immediately install the security updates or disable the Environment Management Hub to block external access to the vulnerable `/PSEMHUB/*` endpoint.
organisation
POST
The entire attack chain is as follows -
Identify susceptible targets by sending POST requests to "/%50SEMHUB/hub" containing a serialized Java object.
Before attempting exploitation, the attackers typically send between five and 15 POST requests to `/%50SEMHUB/hub` containing serialized Java objects.
organisation
WebLogic
The remaining commands have been found to be run under PeopleSoft or WebLogic service accounts.
Organizations are also advised to search WebLogic access logs for requests to '/PSEMHUB/' and encoded variants such as '/%50SEMHUB/' to detect signs of exploitation.
organisation
Disable the Environment Management Hub
Disable the Environment Management Hub (EMHub) service in multi-server configurations, or, remove the PSEMHUB application entirely in single-server configurations.
organisation
Rotate
Rotate credentials readable by the PeopleSoft application service account.
organisation
Reuters
Reuters and other media outlets confirmed the recruitment website did experience disruption around the time of the claim.
organisation
Oracle WebLogic
Oracle WebLogic, on the other hand, decodes the encoded 'P' and routes the request to the vulnerable endpoint, bypassing the WAF rule.
organisation
HTTPS
This toolkit allows SOCKS5 proxy traffic to be tunneled over normal HTTP and HTTPS connections, letting the compromised PeopleSoft server be used to spread laterally into the internal network.
organisation
NFL
"
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
"
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
OAuth
"
"Its recent playbook has emphasized abusing trusted identity paths through help-desk social engineering, malicious OAuth applications, and stolen SaaS integration tokens, rather than simply breaking through a technical perimeter.
organisation
Social Security
The group reportedly offered a sample of around 5,000 records as evidence and claimed that the stolen information could include names, addresses, phone numbers, Social Security numbers, assignments and, in some cases, family details.
data_breach
5,000 records
The group reportedly offered a sample of around 5,000 records as evidence and claimed that the stolen information could include names, addresses, phone numbers, Social Security numbers, assignments and, in some cases, family details.
organisation
the white board
Get your bosses in front of the white board in the war room.
organisation
Clock
Clock is ticking moron.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
"To establish persistent access after web shell placement on Linux systems, UNC6240 deployed the legitimate RMM tool MeshAgent.
Mandiant also observed ShinyHunters using the legitimate MeshAgent remote management software to maintain access to compromised Linux systems.
Metrics
victims
100
Global Organizations
At that time, Google-owned Mandiant said it initiated notifications to over 100 global organizations whose IP addresses matched vulnerable endpoints, most of them located in the U.S.
"This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint," Mandiant
said
.
On June 10,
BleepingComputer first reported
that the ShinyHunters extortion gang was targeting Oracle PeopleSoft servers using a zero-day vulnerability, allowing them to steal data from 100 organizations.
Metrics
data_breach
2
Tb
The disclosure comes as the ShinyHunters group
broke
into the U.S. Federal Bureau of Investigation's FBIJobs.gov portal (which
remains inaccessible
as of writing) and stole about 2-3 TB of sensitive data to contest allegations made by the agency against the group in a May 2026 alert.
The group claimed it stole between 2TB and 3TB of data related to current and former FBI employees, job applicants, and other internal systems.
They allegedly said that between 2 TB and 3 TB of data had been taken and that the FBI jobs infrastructure had been compromised.
Metrics
infrastructure
Windows
Affected Product
On compromised Windows servers, ShinyHunters used these shells to deploy an executable named 'Ple64.exe', which masquerades as a signed Light Alloy media player installer but installs a backdoor tracked by Google as SIDEEYE.
Metrics
data_breach
3
Tb
The group claimed it stole between 2TB and 3TB of data related to current and former FBI employees, job applicants, and other internal systems.
They allegedly said that between 2 TB and 3 TB of data had been taken and that the FBI jobs infrastructure had been compromised.
Metrics
data_breach
5,000
Records
The group reportedly offered a sample of around 5,000 records as evidence and claimed that the stolen information could include names, addresses, phone numbers, Social Security numbers, assignments and, in some cases, family details.
Metrics
data_breach
23
September
"
"One small operational clue is the September 23 timestamp on the group's post, while the news emerged on September 22 in the U.S.
Intelligence Sources
The Hacker News
2026-09-23
Security Affairs
2026-09-23
The Hacker News
2026-09-26
BleepingComputer
2026-09-26
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-27T07:38
Comprehensive Tactical Telemetry
Highly Correlated Entities
32x
organisation
Identified Entity
MeshCentral
entity
24x
attribution
Attributing Entity
FBI
authority
10x
timeline
Temporal Reference
Sep 26, 2026
date
8x
tactic
Cyber Operation Type
Reconnaissance
tactic
6x
industry
Targeted Sector
Education
sector
2x
infrastructure
Affected Product
Linux
software
2x
data breach
Tb
2
tb
2x
general metric
%
50
%
Contextual Telemetry
Context Block
13 METRICS
vulnerability
Exploited CVE
CVE-2026-35273
cve
threat actor
APT Group
ShinyHunters
actor
general metric
Score
10
score
malware
Malware Payload
Neo-reGeorg
tool
general metric
Sep
26
sep
victims
Global Organizations
100
global organizations
general metric
Cve-2026
35,273
cve-2026
data breach
Records
5,000
records
general metric
District
4
district
general metric
Instances
10
instances
general metric
Media
404
media
general metric
Sep
23
sep
data breach
September
23
september
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.