Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Toolkit Hidden Inside Oracle Database Evades Endpoint Tools

Attackers used SQL injection to compile a post-exploitation toolkit inside an Oracle database

Oracle
·Infosecurity Magazine
Read →
Vulnerabilities & Patches
Emerging1 src

Security updates for Thursday

Security updates have been issued by Debian (7zip, kernel, libde265, and p7zip), Mageia (tomcat), Oracle (fence-agents, frr10, kernel, ldns, libgcrypt, mingw-glib2, nodejs24, osbuild-composer, p11-kit, php8.4, sg3_utils, and thunderbird), Red Hat (libXfont2), and SUSE (containerd, evince, libXfont2, nginx, openssl-3, pcp, php7, php8, python-Django, python-httplib2, python-nltk, rrdtool, vifm, and wireshark).

Oracle
·LWN.net
Read →
Threat Actors & Campaigns
Emerging1 src

Attackers hid malware inside Oracle Database after SQL injection breach

Huntress has documented a case where the Oracle database itself became the malware host. The security firm disclosed a campaign in which threat actors exploited a SQL injection vulnerability to store a custom post-exploitation toolkit, dubbed Khunt, inside an Oracle database using the platform’s built-in Java capabilities. Huntress became aware of the intrusion after investigating a credential theft activity on a server running Oracle Database. The researchers learned that rather than simply executing commands through SQL injection, the attackers had leveraged Oracle’s embedded Java Virtual Machine (OJVM) to upload, compile, and execute malicious Java code directly from within the database. The approach reportedly allowed the attackers to blend into legitimate database functionality while maintaining a persistent foothold on the compromised server.

Oracle
·CSO Online
Read →
Vulnerabilities & Patches
Emerging1 src

Patch faster isn’t the answer. Patch smarter is.

The 30-day patch cycle is dead. Most security teams already know this. What they haven’t fully reckoned with is why it died, and what has to replace it. SC Media recently gathered a range of security leaders on exactly this shift, and the picture they described is stark. AI didn’t just add more vulnerabilities to the pile. It collapsed the time between disclosure and exploitation from weeks to hours. Microsoft’s July release patched more than 600 bugs in a single Patch Tuesday, on the heels of a record 206 flaws the month before. In the same week, CISA pushed emergency patch orders for Oracle E-Business and Microsoft SharePoint, and researchers documented a full ransomware operation executed start to finish in under 24 hours. Recent Cloud Security Alliance research puts a number on the danger. Only 9% of organizations remediate critical vulnerabilities within 24 hours.

MicrosoftAwsOracle
·Mend.io Blog
Read →
Breaches & Ransomware
Emerging1 src

JCPenney - 368,418 breached accounts

In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated they primarily related to internal HR systems and impacted current and former employees. The data included 368k corporate and personal email addresses, names, dates of birth, Social Security numbers, phone numbers and

Oracle
·Have I Been Pwned
Read →
Vulnerabilities & Patches
Emerging1 src

15th June – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 15th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES • The University of Nottingham, a UK research university, has  suffered a data breach after ShinyHunters accessed its student records system. The incident affected about 454,600 current and former students and exposed contact details, passport numbers, enrollment information, and fee payment records later appeared online. According to analysts, this breach is part of a larger wave of attacks targeting more than 100 organizations by ShinyHunters, exploiting CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft that allows remote code execution.

CVE-2026-35273AwsOracle
·Check Point Research
Read →
Vulnerabilities & Patches
Emerging1 src

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273 , a critical remote code execution vulnerability (CVSS 9. 8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity predates Oracle's June 10, 2026 advisory, the vulnerability was exploited as a zero-day. Upon becoming aware of active scanning and exploitation, we initiated notifications to over 100 global organizations whose IP addresses correlated with potentially vulnerable endpoints.

CVE-2026-35273GoogleOracle
·Mandiant / Google TI
Read →
Vulnerabilities & Patches
Emerging1 src

Issue 285: API hack at Avelo Airlines, 3.5 billion leak at WhatsApp, F5 API security survey, AI-generated code risks

This week, we share news of API vulnerabilities affecting Avelo Airlines, WhatsApp, and Oracle, and an incident notification from OpenAI to API developers about potential information exposure. We also highlight a new survey from F5 on the role of API security in agentic AI systems. And to wrap up, we have an article examining the risks from AI-generated software and what API teams need to know. Vulnerability: Massive API Data Exposure at Avelo Airlines Security researcher Alex Schapiro reveals API flaws he found in Avelo Airlines’ reservation system that exposed millions of passenger records, including PII and payment-related data. The main API vulnerability in this case was a broken authentication check. The API accepted a 6-character reservation code without also requiring the passenger’s last name.

AwsOracle
·API Security News
Read →