<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Oracle Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Oracle.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available</title><link>https://thehackernews.com/2026/07/fastjson-1x-rce-vulnerability-targeted.html</link><guid isPermaLink="false">cst-3211</guid><description>Attackers are actively exploiting CVE-2026-16723, a critical remote code execution vulnerability in Alibaba's Fastjson JSON library for Java. The flaw allows unauthenticated code execution in affected Spring Boot applications with a CVSS score of 9.0. No patched version is currently available.</description><pubDate>Sat, 25 Jul 2026 12:52:43 GMT</pubDate></item><item><title>Rondo Meets Geoserver</title><link>https://isc.sans.edu/diary/rss/33176</link><guid isPermaLink="false">cst-3040</guid><description>Geoserver instances are being targeted with CVE-2024-36401, an X-Path expression evaluation flaw, to deploy the Rondo botnet. The exploit chain attempts to download and execute a shell script from a remote server, though evidence suggests the malware may have been subsequently removed from affected hosts. This represents a continuation of Rondo's documented interest in Geoserver as an attack vector.</description><pubDate>Wed, 22 Jul 2026 17:35:33 GMT</pubDate></item><item><title>Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates</title><link>https://securityweek.com/oracle-patches-over-1400-vulnerabilities-with-quarterly-security-updates</link><guid isPermaLink="false">cst-2986</guid><description>Oracle released its July 2026 Critical Patch Update addressing over 1,400 vulnerabilities. The update includes fixes for flaws that were likely identified through artificial intelligence (AI) discovery methods.</description><pubDate>Wed, 22 Jul 2026 09:33:12 GMT</pubDate></item><item><title>Oracle July 2026 Critical Patch Update Addresses 1235 CVEs</title><link>https://tenable.com/blog/oracle-july-2026-critical-patch-update-addresses-1235-cves</link><guid isPermaLink="false">cst-2966</guid><description>Oracle released its July 2026 Critical Patch Update on July 21, addressing 1235 unique CVEs across 1449 patches spanning 32 product families. The release included 261 critical patches (18% of all patches), with Oracle E-Business Suite and Fusion Middleware receiving the largest share of fixes. The update covers vulnerabilities across multiple severity levels, with 219 patches in Fusion Middleware exploitable remotely without authentication.</description><pubDate>Tue, 21 Jul 2026 21:07:46 GMT</pubDate></item><item><title>Estée Lauder discloses data breach via Oracle E-Business flaw</title><link>https://bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw</link><guid isPermaLink="false">cst-2875</guid><description>Estée Lauder disclosed a data breach resulting from attackers exploiting a vulnerability in Oracle E-Business Suite, which the company deployed for HR operations. The breach affected customer data stored within systems accessible through the compromised application.</description><pubDate>Mon, 20 Jul 2026 22:39:30 GMT</pubDate></item><item><title>CISA orders feds to patch actively exploited Oracle flaw by Saturday</title><link>https://bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-flaw-by-saturday</link><guid isPermaLink="false">cst-2669</guid><description>The Cybersecurity and Infrastructure Security Agency (CISA) has issued a mandatory directive requiring federal agencies to patch a critical vulnerability in Oracle E-Business Suite that is currently being exploited in active attacks. The deadline for remediation is Saturday.</description><pubDate>Thu, 16 Jul 2026 10:56:03 GMT</pubDate></item><item><title>CISA Adds Two Known Exploited Vulnerabilities to Catalog</title><link>https://cisa.gov/news-events/alerts/2026/07/15/cisa-adds-two-known-exploited-vulnerabilities-catalog</link><guid isPermaLink="false">cst-2622</guid><description>CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2023-4346 affecting KNX Protocol and CVE-2026-46817 in Oracle E-Business Suite. The agency emphasized that federal agencies must prioritize patching these vulnerabilities under Binding Operational Directive 26-04, and encouraged all organizations to adopt risk-based vulnerability management.</description><pubDate>Wed, 15 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Microsoft releases Windows 10 KB5099539 extended security update</title><link>https://bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5099539-extended-security-update</link><guid isPermaLink="false">cst-2513</guid><description>Microsoft released Windows 10 KB5099539, an extended security update containing July 2026 Patch Tuesday fixes for 570 vulnerabilities and additional security patches. This update addresses a substantial volume of identified flaws across the Windows 10 platform.</description><pubDate>Tue, 14 Jul 2026 18:49:28 GMT</pubDate></item><item><title>AI Data Centers and the Concentration of Wealth</title><link>https://schneier.com/blog/archives/2026/07/ai-data-centers-and-the-concentration-of-wealth.html</link><guid isPermaLink="false">cst-2409</guid><description>An essay argues that while local opposition to AI data center construction raises legitimate concerns about resource allocation, environmental impact, and job creation, this focus may distract from AI companies' larger goal of capturing value across major industries like software development, healthcare, and law. The authors contend that despite some successful campaigns against early-stage projects, well-capitalized proposals continue to advance through litigation and political support, while the real strategic prize for AI companies lies in displacing professionals across multiple sectors.</description><pubDate>Mon, 13 Jul 2026 11:01:57 GMT</pubDate></item><item><title>AI Surveillance and Social Progress</title><link>https://schneier.com/blog/archives/2026/07/ai-surveillance-and-social-progress.html</link><guid isPermaLink="false">cst-2316</guid><description>AI-powered surveillance systems combining facial recognition, real-time tracking, and automated enforcement are being deployed globally to monitor public behavior and issue immediate sanctions for rule violations. China operates over 600 million surveillance cameras integrated with social credit systems that publicly shame and restrict citizens deemed untrustworthy, while similar systems are being tested in North America, Europe, and other regions. The technology's primary impact may be widespread self-censorship and behavioral conformity rather than objective public safety.</description><pubDate>Fri, 10 Jul 2026 11:02:04 GMT</pubDate></item><item><title>UAT-7810 continues building ORB networks using new malware</title><link>https://blog.talosintelligence.com/uat-7810</link><guid isPermaLink="false">cst-516</guid><description>Cisco Talos is tracking UAT-7810, a China-nexus APT actor that builds and maintains Operational Relay Box (ORB) networks for use by secondary threat actors. UAT-7810 has developed and deployed new malware variants including LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST, targeting Linux and embedded devices across multiple architectures. The group exploits known vulnerabilities in Ruckus wireless routers and ASUS AiCloud routers from infrastructure in Eastern Europe and Hong Kong.</description><pubDate>Tue, 07 Jul 2026 10:00:05 GMT</pubDate></item><item><title>6th July – Threat Intelligence Report</title><link>https://research.checkpoint.com/2026/6th-july-threat-intelligence-report-2</link><guid isPermaLink="false">cst-594</guid><description>A threat intelligence bulletin reports multiple significant incidents across sectors: ransomware attacks affecting financial, defense, manufacturing, and insurance organizations; artificial intelligence threats including LLM-generated ransomware, unsafe coding agents, and phishing domain hijacking; and critical vulnerabilities in Oracle, Linux, Citrix, and Progress products with active exploitation observed.</description><pubDate>Mon, 06 Jul 2026 12:01:54 GMT</pubDate></item><item><title>New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS</title><link>https://thehackernews.com/2026/07/new-java-based-quimarat-maas-built-to.html</link><guid isPermaLink="false">cst-20</guid><description>Researchers have identified QuimaRAT, a Java-based remote access trojan (RAT) marketed as a malware-as-a-service (MaaS) offering that targets Windows, Linux, and macOS. The malware is sold through subscription tiers ranging from $150 per month to $1,200 for lifetime access.</description><pubDate>Mon, 06 Jul 2026 08:13:33 GMT</pubDate></item><item><title>It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)</title><link>https://labs.watchtowr.com/its-37oc-and-all-we-can-think-about-is-coldfusion-adobe-coldfusion-security-bulletin-apsb26-68-cve-bonanza</link><guid isPermaLink="false">cst-554</guid><description>Adobe released a security advisory on June 30 addressing multiple critical vulnerabilities in ColdFusion 2025 (Update 9 and below) and ColdFusion 2023 (Update 20 and below), including several arbitrary code execution flaws, privilege escalation issues, and file system access vulnerabilities. The analysis highlights that several vulnerabilities involve the Remote Development Services (RDS) feature, which requires being explicitly enabled and having authentication disabled to be exploited, and researchers note difficulty in mapping all disclosed CVEs to specific vulnerability details.</description><pubDate>Thu, 02 Jul 2026 16:38:28 GMT</pubDate></item><item><title>Researchers spot exploitation of another critical Oracle defect</title><link>https://cyberscoop.com/oracle-ebs-critical-vulnerability-exploited</link><guid isPermaLink="false">cst-141</guid><description>Researchers detected six instances of exploitation against a critical Oracle E-Business Suite vulnerability (CVE-2026-46817, CVSS 9.8) within a two-hour window on honeypots, likely representing early reconnaissance and weaponization testing. Shadowserver scans identified approximately 950 potentially vulnerable Oracle E-Business Suite instances, with over half publicly exposed in the United States. Oracle patched the payments processing defect in late May, and the discovery follows a history of similar Oracle products being targeted by ransomware groups and other threat actors in widespread campaigns.</description><pubDate>Wed, 01 Jul 2026 19:23:26 GMT</pubDate></item><item><title>Oracle Critical Patch Update, June 2026 Security Update Review</title><link>https://blog.qualys.com/category/vulnerabilities-threat-research</link><guid isPermaLink="false">cst-391</guid><description>Oracle released its June 2026 Critical Patch Update addressing 245 security vulnerabilities across multiple product families, with Oracle Fusion Middleware receiving the most patches at 106. The update includes patches for critical vulnerabilities in Fusion Middleware, E-Business Suite, JD Edwards, MySQL, and PeopleSoft, many of which can be exploited remotely without credentials and may lead to remote code execution. Qualys has published associated QID coverage for vulnerability scanning and assessment.</description><pubDate>Thu, 18 Jun 2026 14:30:21 GMT</pubDate></item><item><title>Massive breach spills credentials for thousands of sensitive networks</title><link>https://arstechnica.com/security/2026/06/massive-breach-spills-credentials-for-thousands-of-sensitive-networks</link><guid isPermaLink="false">cst-431</guid><description>Researchers discovered a massive breach affecting approximately 74,000 Fortinet firewalls across more than 21,000 organizations in 194 countries, with plaintext credentials exposed online. Russian-speaking attackers gained access to sensitive networks at major organizations including Oracle, Chevron, Lenovo, Federal Express, and NATO defense contractors. In many cases, threat actors leveraged the compromised devices to access centralized authentication systems such as Active Directory and Radius servers.</description><pubDate>Wed, 17 Jun 2026 19:54:31 GMT</pubDate></item><item><title>PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data</title><link>https://arstechnica.com/security/2026/06/peoplesoft-0-day-affecting-hundreds-of-organizations-steals-gigabytes-of-data</link><guid isPermaLink="false">cst-436</guid><description>The ransomware group ShinyHunters exploited a critical server-side request forgery (SSRF) vulnerability in Oracle's PeopleSoft software (CVE-2026-35273, CVSS 9.8) to target approximately 100 customers and conduct extortion attacks. The vulnerability was actively exploited for over two weeks before Oracle disclosed it, and victims have received extortion demands from the threat actors. Oracle has released a temporary mitigation but a full patch has not yet been released.</description><pubDate>Fri, 12 Jun 2026 19:26:47 GMT</pubDate></item><item><title>Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)</title><link>https://rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273</link><guid isPermaLink="false">cst-377</guid><description>Oracle released an emergency patch on June 10, 2026 for CVE-2026-35273, a critical server-side request forgery vulnerability in PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 that allows unauthenticated remote code execution. The vulnerability was actively exploited in the wild by UNC6240 (ShinyHunters) for nearly two weeks before Oracle's advisory, primarily targeting higher education institutions, with stolen data published on the attacker's leak site on June 9, 2026. Post-exploitation activity included deployment of remote management tools masquerading as Azure services and exfiltration of PeopleSoft configuration data.</description><pubDate>Fri, 12 Jun 2026 13:43:04 GMT</pubDate></item><item><title>ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit</title><link>https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit</link><guid isPermaLink="false">cst-308</guid><description>Mandiant and Google Threat Intelligence identified UNC6240 (ShinyHunters) exploiting CVE-2026-35273, a critical remote code execution vulnerability in Oracle PeopleSoft's Environment Management component, between late May and early June 2026. The campaign primarily targeted higher education institutions in the United States, with attackers using custom MeshCentral agents for lateral movement and subsequently publishing stolen data on ShinyHunters' leak site. The exploitation occurred before Oracle's patch advisory, making it a zero-day attack that affected over 100 organizations.</description><pubDate>Thu, 11 Jun 2026 14:00:00 GMT</pubDate></item><item><title>More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)</title><link>https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520</link><guid isPermaLink="false">cst-559</guid><description>Ivanti released an advisory for two critical vulnerabilities in its Sentry product: CVE-2026-10520, a pre-authenticated OS command injection flaw allowing unauthenticated remote code execution with CVSS 10.0, and CVE-2026-10523, an authentication bypass enabling creation of arbitrary administrative accounts. Both vulnerabilities affect Ivanti Sentry versions before R10.5.2, R10.6.2, and R10.7.1.</description><pubDate>Wed, 10 Jun 2026 00:52:20 GMT</pubDate></item><item><title>Pwn2Own Berlin 2026: The Full Schedule</title><link>https://thezdi.com/blog/2026/5/13/pwn2own-berlin-2026-the-full-schedule</link><guid isPermaLink="false">cst-393</guid><description>Pwn2Own Berlin 2026 is a competitive hacking event held at OffensiveCon featuring security researchers attempting to exploit vulnerabilities in enterprise software across multiple categories including AI databases, coding agents, web browsers, and NVIDIA products. The competition schedule spans three days in May 2026, with researchers competing for prize pools ranging from $20,000 to $175,000 and Master of Pwn points based on vulnerability severity and impact.</description><pubDate>Wed, 13 May 2026 16:23:07 GMT</pubDate></item><item><title>Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat</title><link>https://reliaquest.com/blog/threat-spotlight-casting-a-wider-net-clickfix-deno-and-leaknets-scaling-threat</link><guid isPermaLink="false">cst-2119</guid><description>LeakNet ransomware operators are expanding their attack capabilities by adopting ClickFix social engineering lures hosted on compromised websites and deploying a Deno-based in-memory loader for command-and-control delivery. The group maintains a consistent post-exploitation sequence across incidents, including jli.dll side-loading into Java, PsExec lateral movement, and S3 bucket payload staging. This shift toward self-directed campaigns reduces LeakNet's reliance on initial access brokers and accelerates their timeline from initial compromise to encryption.</description><pubDate>Tue, 17 Mar 2026 09:00:00 GMT</pubDate></item><item><title>Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s))</title><link>https://labs.watchtowr.com/buy-a-help-desk-bundle-a-remote-access-solution-solarwinds-web-help-desk-pre-auth-rce-chain-s</link><guid isPermaLink="false">cst-565</guid><description>SolarWinds Web Help Desk has been found to contain multiple pre-authentication remote code execution vulnerabilities via Java deserialization, including CVE-2025-40552, CVE-2025-40553, and CVE-2025-40554. Researchers achieved RCE on a fully patched instance by chaining an authentication bypass with a deserialization flaw, demonstrating that previous patches for similar 2024 vulnerabilities did not fully address the underlying issues. This continues a pattern of recurring deserialization problems in the product.</description><pubDate>Wed, 25 Feb 2026 20:06:32 GMT</pubDate></item><item><title>Apache ActiveMQ Exploit Leads to LockBit Ransomware</title><link>https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware</link><guid isPermaLink="false">cst-577</guid><description>A threat actor exploited CVE-2023-46604 on an exposed Apache ActiveMQ server in mid-February 2024 to achieve remote code execution using a Java Spring class, leading to LockBit ransomware deployment. The intrusion demonstrates how unpatched critical vulnerabilities in internet-facing services remain an effective attack vector for ransomware operators.</description><pubDate>Mon, 23 Feb 2026 14:09:43 GMT</pubDate></item><item><title>Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 &amp; CVE-2026-1340)</title><link>https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340</link><guid isPermaLink="false">cst-566</guid><description>Ivanti released patches for two pre-authentication remote code execution vulnerabilities (CVE-2026-1281 and CVE-2026-1340) in Endpoint Manager Mobile (EPMM), an enterprise mobility management platform used to control corporate mobile devices. The vulnerabilities are actively exploited in the wild and have been added to CISA's Known Exploited Vulnerabilities list. Permanent patches are not available until Q1 2026; customers are currently receiving temporary RPM patches that must be reapplied after system updates to remain effective.</description><pubDate>Fri, 30 Jan 2026 16:15:16 GMT</pubDate></item><item><title>Bringing Oracle Cloud Identity to Wiz</title><link>https://wiz.io/blog/wiz-supports-oracle-cloud-identity</link><guid isPermaLink="false">cst-1371</guid><description>Wiz has integrated Oracle Cloud Infrastructure (OCI) identity management capabilities into its Security Graph platform, providing unified visibility across OCI identities, permissions, and policies. This integration enables security teams to map and visualize identity configurations within Wiz's broader cloud security posture framework.</description><pubDate>Mon, 22 Dec 2025 13:00:00 GMT</pubDate></item><item><title>Wiz becomes the first CNAPP to provide DSPM capabilities for Oracle Cloud Infrastructure</title><link>https://wiz.io/blog/introducing-dspm-for-oracle-cloud-infrastructure</link><guid isPermaLink="false">cst-1616</guid><description>Wiz has added Data Security Posture Management (DSPM) capabilities to its Cloud Native Application Protection Platform (CNAPP) offering, enabling Oracle Cloud Infrastructure customers to better identify and protect sensitive data in their environments. This integration provides CNAPP users with built-in data security visibility without requiring separate tools.</description><pubDate>Thu, 14 Mar 2024 14:39:40 GMT</pubDate></item><item><title>ConnectWise/R1Soft RCE &amp; Supply Chain Risks | Huntress</title><link>https://huntress.com/blog/critical-vulnerability-disclosure-connectwise-r1soft-server-backup-manager-remote-code-execution-supply-chain-risks</link><guid isPermaLink="false">cst-1107</guid><description>Huntress confirmed an authentication bypass and sensitive file disclosure vulnerability in the ZK Java framework used by ConnectWise R1Soft Server Backup Manager SE. The flaw allows unauthorized access and exposure of sensitive data in the backup management software. This represents a supply chain security risk affecting organizations relying on this widely used backup solution.</description><pubDate>Mon, 31 Oct 2022 00:00:00 GMT</pubDate></item><item><title>AttachMe: critical OCI vulnerability allows unauthorized access to customer cloud storage volumes</title><link>https://wiz.io/blog/attachme-oracle-cloud-vulnerability-allows-unauthorized-cross-tenant-volume-access</link><guid isPermaLink="false">cst-1786</guid><description>AttachMe was a critical vulnerability in Oracle Cloud Infrastructure (OCI) that allowed unauthorized access to and modification of other users' storage volumes, violating cloud isolation. Oracle patched the vulnerability within hours of disclosure, and no customer action was required.</description><pubDate>Tue, 20 Sep 2022 12:57:00 GMT</pubDate></item><item><title>Wiz extends CNAPP leadership with protection for Alibaba Cloud</title><link>https://wiz.io/blog/wiz-extends-cnapp-leadership-with-protection-for-alibaba-cloud</link><guid isPermaLink="false">cst-1799</guid><description>Wiz announced support for Alibaba Cloud in its cloud native application protection platform (CNAPP), extending its coverage across multiple cloud providers. This follows the recent launch of Oracle Cloud Infrastructure (OCI) integration, broadening the platform's multi-cloud capabilities.</description><pubDate>Thu, 30 Jun 2022 05:40:59 GMT</pubDate></item><item><title>Wiz now integrates with Oracle Cloud Infrastructure, bringing a graph-based cloud security approach to all major providers</title><link>https://wiz.io/blog/supporting-oracle-cloud-wiz-brings-the-first-graph-based-cloud-security-approach-to-all-major-providers</link><guid isPermaLink="false">cst-1803</guid><description>Wiz, a cloud security company, has announced integration with Oracle Cloud Infrastructure (OCI), extending its graph-based security approach across all major cloud providers. The integration enables enterprises like Avery Dennison to maintain security visibility and governance across their OCI deployments alongside other cloud environments.</description><pubDate>Thu, 02 Jun 2022 05:30:16 GMT</pubDate></item><item><title>Critical RCE Vulnerability Updates (log4j - CVE-2021-44228) | Huntress</title><link>https://huntress.com/blog/rapid-response-critical-rce-vulnerability-is-affecting-java</link><guid isPermaLink="false">cst-1161</guid><description>Huntress released analysis of CVE-2021-44228, a critical remote code execution vulnerability in the Java logging library Log4j that enables unauthenticated attackers to execute arbitrary code on affected systems.</description><pubDate>Fri, 10 Dec 2021 00:00:00 GMT</pubDate></item></channel></rss>