Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Security updates for Wednesday

Security updates have been issued by AlmaLinux (coreutils, postgresql18-postgis, and postgresql:16), Debian (memcached), Fedora (chromium, cyrus-imapd, dotnet10. 0, dotnet8. 0, dotnet9. 0, freeipmi, kernel, libxmp, perl-Net-DNS, and postgresql16-anonymizer), Mageia (cpio, diffutils, perl-Dancer2, and rest), Oracle (389-ds-base and firefox), Red Hat (opentelemetry-collector and osbuild-composer), SUSE (amazon-cloudwatch-agent, amazon-ssm-agent, apko, apptainer, bazel-rules-python-source, bind, cups, firefox, freeipmi, gdb, google-osconfig-agent, kernel, kyverno, libipa_hbac-devel, libsoup, libsoup-3_0-0, libtpms, openssl-certs, perl-Authen-SASL, php-composer2, python313-PyMuPDF, thunderbird, and util-linux), and Ubuntu (gzip, linux-aws, linux-aws-5. 15, linux-aws-fips, linux-nvidia-tegra-igx, linux-azure, linux-oracle, linux-azure-7. 0, linux-azure-fde-6.

·LWN.net
Read →
DFIR
Emerging1 src

InfoSec News Nuggets – 09/23/2026

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach The ShinyHunters extortion gang says it broke into FBI systems through a new, unpatched Oracle PeopleSoft zero-day. It claims it then moved into FBI-managed AWS GovCloud infrastructure and took 2 to 3TB of data on current and former employees and job applicants. The group defaced the FBI Jobs site with its logo, and the FBI has confirmed it is investigating “claims regarding unauthorized activity affecting FBIjobs. gov.” It has not confirmed a breach. ShinyHunters calls the attack retaliation for a May 2026 FBI FLASH report about the group and has given the bureau a week to correct or remove it. It also says it is now using the same PeopleSoft flaw against Fortune 500 companies. None of these claims has been independently verified, so organizations running PeopleSoft should watch closely for an Oracle advisory.

·AboutDFIR
Read →
Vulnerabilities & Patches
Emerging1 src

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [... ]

·BleepingComputer
Read →
Vulnerabilities & Patches
Emerging1 src

ShinyHunters claims FBI breach via new Oracle PeopleSoft zero-day

The ShinyHunters cybercrime group is now claiming it breached FBI systems after discovering and immediately exploiting a previously unknown vulnerability in Oracle PeopleSoft. This allegedly gave them access to several internal services and allowed them to steal between 2TB and 3TB of data. The FBI has not yet confirmed the intrusion, and CyberInsider has contacted … The post ShinyHunters claims FBI breach via new Oracle PeopleSoft zero-day appeared first on CyberInsider .

·CyberInsider
Read →
Vulnerabilities & Patches
Emerging1 src

Security updates for Monday

Security updates have been issued by AlmaLinux (kernel, perl-Net-DNS, sudo, tomcat, and tomcat9), Debian (chromium, gimp, libde265, libevent, linux-6. 12, ruby-jwt, and unbound), Fedora (asterisk, chromium, doctl, dovecot, evolution, firefox, forgejo, freeciv, freeipa, gegl04, gimp, libheif, nss, opkssh, parted, ruby, stb, thunderbird, unbound, and webkitgtk), Mageia (bind, gawk, gdk-pixbuf2. 0, graphicsmagick, gstreamer1. 0-plugins-base, libde265, libpcap, libssh, mpg123, ntfs-3g, ntpsec, patch, perl-YAML, postfix, python-configargparse, and python-httplib2), Oracle (. NET 10. 0, . NET 8. 0, . NET 9.

·LWN.net
Read →
Vulnerabilities & Patches
Emerging1 src

Security updates for Friday

Security updates have been issued by AlmaLinux (. NET 10. 0, coreutils, kernel, libevent, libsoup3, microcode_ctl, perl-Net-DNS, postgresql18, postgresql:16, postgresql:18, tomcat, and unbound), Debian (bind9, chromium, libapache2-mod-auth-openidc, nginx, xz-utils, and zip), Fedora (chromium, freeipmi, GitPython, gnatcoll, nodejs-undici, parted, python-django5, and sblim-cmpi-base), Mageia (imagemagick and python-starlette), Oracle (. NET 10. 0, . NET 8. 0, . NET 9. 0, coreutils, corosync, firewalld, kernel, libevent, libsoup, microcode_ctl, nginx:1. 24, perl, perl:5.

·LWN.net
Read →
Policy & Regulation
Emerging1 src

Best IGA Tools for Every Business Size (2026)

Quick Answer: A generational split defines 2026 governance: SaaS-first companies start with Lumos or ConductorOne (app requests and reviews that deploy in weeks), M365 estates switch on Entra ID Governance , and the deep-audit years belong to SailPoint and Saviynt with IBM , Oracle , and EmpowerID serving estates their heritage matches. Identity governance used to arrive only at enterprise scale, carried by year-long deployments and consultant armies. A new generation changed that: SaaS-native tools now deliver access requests, reviews, and offboarding evidence to two-hundred-person companies in a sprint while the deep incumbents still own the certification-and-SoD summit that regulated enterprises genuinely need. Aligning your identity program with a broader Zero Trust security architecture ensures continuous validation across all applications.

·CyberPress
Read →
Phishing
Emerging1 src

8 Best IAM Solutions for Every Business Size (2026)

Quick Answer: Identity should grow with the org chart: startups get IAM as a byproduct of Rippling -style HR-IT platforms or free Keycloak engineering; growth companies anchor on Entra ID or Okta as the app estate demands lifecycle automation; complex and regulated stages bring Ping , CyberArk (security-first), and Oracle (app-estate-driven), with miniOrange solving budget and odd-connector corners throughout. The IAM decision isn’t really about vendors it’s about which stage of organizational chaos you’re in. At ten employees, identity is whoever runs the HR system; at two hundred, it’s lifecycle automation or onboarding drowns; at two thousand, it’s orchestration, privilege, and audit. This scorecard maps eight IAM options to those stages including the unconventional entries (an HR platform, an open-source server) that legacy vendor lists skip but real startups actually use.

·CyberPress
Read →
Vulnerabilities & Patches
Emerging1 src

Oracle’s September patches put Fusion Middleware back in the hot seat

Oracle’s September 2026 Critical Security Patch Update has arrived with 673 new security patches spanning 17 Oracle product families, with Oracle E-Business Suite accounting for the largest share at 159 patches, followed by Fusion Middleware with 153. Of these, 19 E-Business Suite vulnerabilities and 78 Fusion Middleware vulnerabilities can be remotely exploited without authentication. Other product categories with 50 or more issues fixed in the rollout include Oracle Database Server, Oracle Communications, and Oracle Analytics. Oracle recently accelerated its patching rhythm from quarterly to monthly . It advised customers to apply the September patches immediately, warning that it continues to receive reports of successful attacks on its software where customers had not applied available fixes.

·CSO Online
Read →
Vulnerabilities & Patches
Emerging1 src

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways • The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates • 104 issues (15.5% of all patches) were assigned a critical severity rating • Oracle E-Business Suite received the highest number of patches at 159, accounting for 23.6% of all patches Background On September 15, Oracle released its Critical Security Patch Update (CSPU) for September 2026 . Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 672 unique CVEs in 673 security updates across 17 Oracle product families.

·Tenable Blog
Read →
Vendors & Market
Emerging1 src

Oracle layoffs: staff told today is their last working day - Cybernews

Oracle layoffs: staff told today is their last working day Cybernews

·Cybernews
Read →
Vulnerabilities & Patches
Emerging1 src

Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks

A critical zero-day vulnerability in Oracle PeopleSoft exposed the Council of Europe and scores of other organizations to data theft and extortion in May and early June 2026. The ShinyHunters hacking group exploited the flaw across about 100 organizations and 300 instances worldwide, according to reports cited by The Register. The attackers targeted the management and configuration layers of enterprise resource-planning systems, stealing sensitive records. Among these were employees’ and students’ personal data, payroll, tax and financial information, health records and immigration and passport documents. AgentCypher. ai estimates extortion demands of $400,000 to $2. 3 million per victim – often in Bitcoin although the total remains undisclosed. The Council of Europe refused to negotiate or pay. Why are traditional perimeter-based security models no longer sufficient?

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

Security updates for Thursday

Security updates have been issued by AlmaLinux (389-ds-base, ansible-core, buildah, expat, glib2, gpsd, gpsd-minimal, gzip, kernel, kernel-rt, opentelemetry-collector, osbuild-composer, perl-DBI, python-lxml, python3. 12-lxml, qt5-qtbase, thunderbird, valkey, vim, and xz), Debian (pyasn1), Fedora (darktable, freeipa, freerdp2, gdk-pixbuf2, GitPython, libsoup3, openssl, perl-Net-DNS, rust-ppmd-rust, samba, and valkey), Mageia (ceph, firefox, nss, perl-DBI, thunderbird, and wget), Oracle (389-ds-base, buildah, expat, git-lfs, glib2, glibc, gpsd, gpsd-minimal, grafana-pcp, kernel, libssh, nginx, perl-GD, python3.

·LWN.net
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-635: Oracle Outside In Technology PDF File Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must open a malicious file or visit a malicious page. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-60392.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-643: Oracle VirtualBox VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6. 1. The following CVEs are assigned: CVE-2026-60162.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-642: Oracle VirtualBox IDisplay Out-Of-Bounds Read Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7. 5. The following CVEs are assigned: CVE-2026-60159.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-636: Oracle Outside In Technology PostScript File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-60412.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-641: Oracle VirtualBox VirtioSCSI Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6. 1. The following CVEs are assigned: CVE-2026-71114.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-638: Oracle Outside In Technology WPS File Parsing Memory Corruption Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-60414.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-644: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7. 5. The following CVEs are assigned: CVE-2026-60155.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-640: Oracle VirtualBox VirtioSCSI Uninitialized Memory Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5. 3. The following CVEs are assigned: CVE-2026-71132.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-639: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7. 5. The following CVEs are assigned: CVE-2026-71116.

·Zero Day Initiative (Published)
Read →
Vulnerabilities & Patches
Emerging1 src

ZDI-26-637: Oracle Outside In Technology GEM File Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7. 8. The following CVEs are assigned: CVE-2026-60413.

·Zero Day Initiative (Published)
Read →
Threat Actors & Campaigns
Emerging1 src

Anti-DDoS research part 4: an information-gain oracle. Practical Python example

﷽ Hello, cybersecurity enthusiasts and white hackers! In part 1 and part 2 , I looked at wavelet-based traffic anomalies. In part 3 , I used handshake asymmetry to detect SYN-flood campaigns. Today the question is different: which question should a detector ask next? We will build a small tree of questions about network flows, run it against the local CICDDoS2019 CSV files, and measure the trade-off between detection quality and the number of questions. The code and the measurements below use completed flow records. This is an offline classifier experiment, not a measurement of detection latency during a live flood. idea - what is our oracle? Call any yes/no probe that narrows down a set of hypotheses an oracle : it answers one question, and the algorithm keeps only the hypotheses consistent with that answer before asking the next one.

·Malware.news
Read →
Vulnerabilities & Patches
Emerging2 srcs

Bimbo Bakeries confirms data stolen in Oracle EBS zero-day attack

Bimbo Bakeries USA, the American arm of the world’s largest baking company, has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS), joining a growing list of organizations swept up in the Clop ransomware gang’s global extortion campaign against Oracle customers. In a notification letter dated August 31, 2026, and filed with the California Attorney General’s office on September 4, as detailed in the official filing published by the California Attorney General’s Office , the bakery giant said the incident traced back to a third-party vendor that relied on Oracle EBS. Bimbo Oracle EBS Data Breach The company disclosed that its investigation determined on December 6, 2025, that attackers had exploited the zero-day to acquire files stored within the platform.

·CyberInsider
Read →
Vulnerabilities & Patches
Emerging1 src

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP. NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

Security updates for Tuesday

Security updates have been issued by AlmaLinux (gzip, iperf3, libxml2, mingw-sqlite, mysql:8. 4, nginx:1. 26, nodejs:24, php, and tar), Debian (expat and libdbd-csv-perl), Fedora (apache-ivy, bind, bluez, bubblewrap, curl, emacs, epiphany, expat, freerdp, gdk-pixbuf2, GitPython, hcloud, kbd, kernel, lego, libopenmpt, mqttcli, nebula, opkssh, python-mkdocs-git-revision-date-localized-plugin, python-pip, rpki-client, rubygem-mechanize, srt, and subfinder), Mageia (c-ares, clamav, expat, mingq-expat, firefox, nspr, nss, flatpak, hplip, jbig2dec, nodejs, openssl, perl-Catalyst-Plugin-Authentication, perl-Date-Manip, perl-HTML-FormHandler, perl-HTTP-Date, perl-Mojolicious, perl-Plack, postgresql15, postgresql18, python-hpack, redis, roundcubemail, thunderbird, varnish, and vim), Oracle (golang and libxml2), Red Hat (bind, bind9.

·LWN.net
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw - Hackread

CISA Warns Agencies to Patch Actively Exploited Oracle WebLogic Proxy Flaw Hackread

·Hackread
Read →
Vulnerabilities & Patches
Emerging1 src

U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog . Gitea is an open-source platform for hosting and managing Git repositories. Think of it as a self-hosted alternative to GitHub or GitLab. CVE-2026-60004 is a critical remote code execution flaw that allows an attacker with write access to a repository to execute arbitrary shell commands as the Gitea service user. The flaw affects Gitea versions from 1. 17 and was fixed in 1. 27. 1. The vulnerable diffpatch API can be abused to plant and execute a malicious Git hook.

·Security Affairs
Read →
Phishing
Emerging1 src

CISA is running on empty.

Lawmakers request an investigation into cuts at CISA. Threat actors actively exploit a Zimbra Collaboration Suite vulnerability. A Chinese AI lab preps release of a powerful open-weight model. A new phishing toolkit deploys attacker-controlled passkeys. Using audio hardware to fingerprint browsers. A DDoS attack knocks Norwegian government services offline. CISA orders patching of a critical Oracle vulnerability. Taiwanese prosecutors charge nine people over the alleged illegal export of high-end AI servers to mainland China. Operation Jackal IV cracks down on West African cybercrime networks. On our Industry Voices segment, Christy Wyatt, CEO from Absolute Security, discusses "Cyber Resilience: The Emerging Category." AI music hits a sour note down under. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode?

·The CyberWire
Read →
Vulnerabilities & Patches
Emerging1 src

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-21962 (CVSS score of 10,0), to its Known Exploited Vulnerabilities (KEV) catalog . CVE-2026-21962 is a critical, unauthenticated vulnerability affecting the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS. An attacker does not need an account or valid credentials. With network access, they can exploit the flaw remotely through HTTP and potentially compromise the affected server. Successful exploitation could allow the attacker to access, modify or delete critical data, potentially gaining broad access to information available through the affected components.

·Security Affairs
Read →