Tag: oracle
38 articles

CISA Mandates Swift Patching for Oracle Flaw
Don't wait - patch now! A critical Oracle flaw, scored 10.0, requires immediate attention to prevent low-complexity attacks that could give hackers complete access to your critical data.

TikTok Reversal Sparks Mobile Security Concerns
TikTok's recent U.S. entity shift has done little to alleviate mobile security concerns, as its privacy policy still raises red flags about invasive data collection and usage. Expert Matt Stern warns that the app's practices remain a threat to user data.

Oracle Exploited: Attackers Turn SQL Injection into Windows SYSTEM Access
Attackers have successfully exploited a SQL injection vulnerability to gain unprecedented access to Oracle databases, converting it into a Windows SYSTEM-level access with alarming ease. This rare and sophisticated technique has allowed hackers to deploy a custom toolkit, dubbed khunt, that turns database-stored Java into a powerful post-exploitation tool.

Pentagon Consolidates Oracle Software Buys in $7 Billion Deal
The Department of Defense has secured a $7 billion deal with Oracle to centralize software purchases, a move that's expected to save taxpayers at least $441 million while better supporting military personnel. This unified agreement streamlines Oracle buying across the DoD, bringing transparency to enterprise usage and spending.

Oracle Releases 1,449 Security Patches Amid AI-Driven Vulnerability Surge
Oracle's recent release of 1,449 security patches may seem alarming, but experts say it's largely a reflection of the company's massive software ecosystem and its cutting-edge use of AI to supercharge vulnerability detection. This huge number is also a testament to Oracle's proactive approach to staying on top of security threats.

ShinyHunters Breach Exposes NAIC's Public Data
The National Association of Insurance Commissioners (NAIC) revealed that a breach exposed its public data after an unauthorized third party exploited a PeopleSoft vulnerability, identified as CVE-2026-35273, tied to the notorious ShinyHunters extortion group. This security issue allowed attackers to gain access to a portion of NAIC's IT systems, compromising sensitive information.

Oracle Discloses Zero-Day Flaw in PeopleSoft Exploited in Data Theft Attacks
A critical zero-day flaw in Oracle PeopleSoft, known as CVE-2026-35273, has been exploited by hackers to steal sensitive data from over 100 organizations, with a staggering 300 instances affected. Oracle has issued emergency mitigations and is working on a patch to address this highly vulnerable issue.

Known Exploited Vulnerabilities: Stunning High-Risk Alert
CISA just added five actively exploited vulnerabilities — including Oracle E‑Business Suite CVE‑2025‑61884 — meaning organizations must act fast or risk business disruption. Check whether your Oracle and Microsoft systems are affected, apply patches or mitigations ASAP, and ramp up monitoring to spot any signs of compromise.

Oracle E-Business Suite Risky: Must-Have Breach Guide
Google’s Threat Analysis Group says the Clop ransomware gang accessed a large volume of data from Oracle E-Business Suite — a wake-up call for any org that hasn’t checked who holds the keys to its crown jewels. Now’s the time to hunt for shadow EBS instances, tighten access, and patch or segment vulnerable systems before attackers turn stolen data into extortion.

Oracle E-Business Suite: Stunning Critical Breach Risk
A zero-day in Oracle E-Business Suite, actively exploited by CL0P since Aug. 9, 2025, likely hit dozens of organizations and put payroll, financial and HR data at risk. Security teams and leaders are racing to contain the damage, patch systems and lock down access before attackers strike again.

Oracle EBS Must-Have Urgent Patch: Critical Risk
Britain’s NCSC is urging organisations to patch Oracle E-Business Suite immediately after the Clop ransomware gang was seen actively exploiting a critical flaw that could expose payroll, procurement and finance systems. If you run EBS, inventory your instances and apply the patch—or fast compensating controls—now to avoid disruption, data theft and costly ransom demands.

Oracle zero-day: Must-Have Urgent Fix for Best Defense
This week’s cyber roundup proves attackers still love the path of least resistance: a critical Oracle zero-day, BitLocker deployment gaps that erode encryption guarantees, and a fast‑spreading WhatsApp “worm” that rode on trust. The takeaway? Patch, audit key management, and treat people and processes as the front lines of defense.

E-Business Suite Critical Patch: Must-Have Fix
Oracle rushed an out-of-cycle emergency patch for a 9.8 CVSS flaw in E-Business Suite after a wave of Cl0p-linked data theft, and customers are racing to patch, isolate systems, and hunt for signs of exfiltration. If your E-Business Suite is reachable over HTTP, treat it as potentially compromised—inventory, patch, and lock down access now.

Oracle E-Business Suite Exclusive Patch: Risky Threat
Oracle just pushed an emergency patch for a 9.8-rated zero‑day in E‑Business Suite that Clop has already exploited to steal data and extort victims — if you run EBS, patch now and hunt for signs of compromise. This high‑severity, out‑of‑cycle fix shows how one flaw in widely used enterprise software can force organizations into urgent, risky choices between patching and business continuity.

Oracle E-Business Suite Critical Patch: Must-Have Fix
Oracle’s July patch closes the immediate Clop-linked weakness in E-Business Suite portals — but with thousands of internet-facing, heavily customized EBS installs still at risk, organizations need to patch, isolate access, and harden defenses now to avoid extortion.

Oracle E-Business Suite: Urgent Must-Have Patch
Oracle warned and patched critical E-Business Suite flaws in July 2025 — yet attackers are actively scanning and exploiting systems that haven’t applied the fixes, turning patch delays into real-world breaches. If your ERP runs on EBS, now’s the time to prioritize updates, isolate vulnerable modules, and tighten access controls before the next compromise hits payroll, procurement, or customer trust.

Clop ransomware: Exclusive Risky Extortion Alert
Extortion emails claiming stolen Oracle E‑Business Suite data are rattling execs — but Google and Mandiant say they’ve found no proof, leaving companies stuck between precaution and panic. The result: tough choices about trust, disclosure and whether to pay up for silence when the evidence is murky.

US TikTok user data Exclusive Risky Fix
Oracle will host U.S. TikTok data on American servers — a move pitched as a security-first fix to ease fears about Chinese access, but skeptics worry it could be more paper shield than real protection. The deal’s success will hinge on strong cryptographic controls, independent audits and transparent oversight, not just where the servers sit.

TikTok’s US operations: Exclusive Risky Power Grab
President Trump says Michael Dell is part of a consortium — reportedly including Larry Ellison and the Murdochs — aiming to buy TikTok’s U.S. operations, reigniting a high-stakes debate over data security and who controls a platform used by tens of millions every day.

Pwn2Own Unveils Critical Zero-Day Attacks on VMware ESXi and Microsoft SharePoint Vulnerabilities
Pwn2Own uncovers critical zero-day vulnerabilities in VMware ESXi and Microsoft SharePoint, challenging current cybersecurity defenses and alerting IT professionals.

Indiana Health System Notifies 263,000 of Oracle Hack
Indiana Health System notifies 263,000 patients after an Oracle hack compromised personal data. Discover breach details and protective measures.

Cryptohack Roundup: KiloEX Offers Compensation
Explore Cryptohack Roundup: KiloEX offers compensation to security researchers. Discover its impact on crypto rewards and industry trends.

Oracle’s Cloud Data Theft Concerns Resurface as CISA Revives Discussion
Oracle faces renewed scrutiny over cloud data theft concerns as CISA reignites discussions on cybersecurity vulnerabilities and data protection measures.

CISA Issues Warning on Credential Risks Following Oracle Cloud Leak
CISA warns of credential risks after Oracle Cloud leak, urging organizations to enhance security measures to protect sensitive data.