#mandiant
2 cases
ShinyHunters (UNC6240) bypass a WAF with one URL-encoded character to mass-exploit PeopleSoft CVE-2026-35273Data BreachMalwareExtortion & Blackmail
GTIG tracked UNC6240 (linked to ShinyHunters) mass-exploiting PeopleSoft's CVE-2026-35273 (CVSS 9.8 unauth RCE). Defenders who blocked /PSEMHUB at a WAF instead of patching were bypassed: the actor requested /%50SEMHUB/, one URL-encoded character, then dropped web shells and the SIDEEYE backdoor.
Data BreachMalwareExtortion & Blackmail
Shai-Hulud via a hijacked AI coding-assistant session: Mandiant's case of a poisoned recommendation that spread a wormSupply Chain AttackAI & Machine LearningMalware
Mandiant documents an intrusion where an AI coding assistant recommended attacker-poisoned software; a developer accepted it, and the attacker used the live session to steal GitHub OAuth tokens and spread the Shai-Hulud worm across ~100 internal repos. How the session was taken over is undisclosed.
Supply Chain AttackAI & Machine LearningMalware