#oracle


ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

Sep 26, 2026 // 22:17

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat […]

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Sep 26, 2026 // 14:47

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The […]

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Aug 25, 2026 // 11:42

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its […]

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Aug 6, 2026 // 13:42

Attackers broke into an organization’s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an […]

Hackers run khunt post-exploitation toolkit from Oracle database

Aug 5, 2026 // 23:57

Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. The […]

Estée Lauder discloses data breach via Oracle E-Business flaw

Jul 21, 2026 // 02:03

Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human […]

CISA orders feds to patch actively exploited Oracle flaw by Saturday

Jul 16, 2026 // 13:56

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability […]

Over 900 Oracle E-Business instances exposed to ongoing attacks

Jul 1, 2026 // 15:36

Over 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw. The vulnerability (tracked as CVE-2026-46817) […]

Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild

Jun 30, 2026 // 08:05

A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 […]

Nissan discloses employee data breach linked to Oracle zero-day attacks

Jun 29, 2026 // 23:56

Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft […]

1 2 Next