Tag: oracle
-
Hackers Smuggle Post-Exploitation Toolkit Into Oracle Database Via Classic SQL Injection Flaw
A SQL injection vulnerability that many organisations might consider a decades-old, well-understood threat has been used as the entry point for a far more sophisticated attack, after threat actors were caught planting a custom-built, database-resident toolkit inside an Oracle database. Security firm Huntress said it was alerted to suspicious activity on an endpoint hosting an…
-
Cyberangriff auf Ungarn: Hacker stürzt Finanzverwaltung ins IT-Chaos
Ein Angreifer hat IT-Systeme der Finanzverwaltung Ungarns infiltriert. Den Zugriff erhielt er wohl über eine seit 2017 bekannte Lücke in Oracle Weblogic. First seen on golem.de Jump to article: www.golem.de/news/cyberangriff-auf-ungarn-hacker-stuerzt-finanzverwaltung-ins-it-chaos-2608-211627.html
-
Innerhalb der E”‘Business Suite – Zahlungskomponente in Oracle ist aktiven Angriffen ausgesetzt
Tags: oracleFirst seen on security-insider.de Jump to article: www.security-insider.de/oracle-payments-cve-2026-46817-systemuebernahme-ohne-authentifizierung-a-b007b1e321b85456bca9f85cf0917f7d/
-
Oracle July 2026 Patch Fixes 1,434 CVEs Across 334 Products
Oracle has released its July 2026 Critical Patch Update, delivering one of its largest quarterly security releases to date. The latest Oracle security patch addresses more than 1,400 vulnerabilities across hundreds of products, with the company indicating that artificial intelligence likely played a significant role in identifying most of the flaws. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/july-2026-critical-patch-update-oracle/
-
Estée Lauder customer data compromised in Oracle E-Business Suite breach
First seen on scworld.com Jump to article: www.scworld.com/brief/estee-lauder-customer-data-compromised-in-oracle-e-business-suite-breach
-
Estée Lauder Confirms Cyberattack Affecting Personal Information
The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/estee-lauder-data-breach-oracle-ebs/
-
Estée Lauder Confirms Cyberattack Affecting Personal Information
The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/estee-lauder-data-breach-oracle-ebs/
-
Estée Lauder discloses data breach tied to Oracle EBS vulnerability
Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/estee-lauder-data-breach-oracle-ebs/
-
Estée Lauder meldet Datenabfluss durch Oracle-Schwachstelle
Estée Lauder meldet einen Datenabfluss. Angreifer nutzten eine Sicherheitslücke in Oracle E-Business Suite zur Entwendung von Personal- und Kundendaten. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/estee-lauder-datenabfluss
-
Estée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
-
Cosmetics giant Estée Lauder victim of mass Oracle breach
Employee data at US-based cosmetics firm Estée Lauder was compromised through a vulnerability in Oracle’s software, likely orchestrated by the Cl0p ransomware gang. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645849/Cosmetics-giant-Estee-Lauder-victim-of-mass-Oracle-breach
-
U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, oracle, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities (KEV) catalog. The flaws added to the catalog are: The vulnerability CVE-2023-4346 (CVSS…
-
CISA orders feds to patch actively exploited Oracle flaw by Saturday
CISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-flaw-by-saturday/
-
CISA Warns of Actively Exploited Oracle E-Business Suite Flaw
Tags: business, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting CVE-2026-46817, an improper privilege management vulnerability in Oracle E-Business Suite that can lead to a takeover of Oracle Payments. The agency added the issue to its Known Exploited Vulnerabilities Catalog on July 15, 2026, and directed affected federal civilian executive…
-
Investors Accuse Oracle of Hiding OpenAI Financial Risks
Suit Claims Oracle’s AI Backlog Relied Heavily on One Financially Strained Customer. An investor class action lawsuit alleges Oracle failed to disclose internal concerns about OpenAI’s revenue, user growth and ability to meet cloud-computing commitments, leaving investors unaware of risks tied to Oracle’s multibillion-dollar AI infrastructure expansion and February debt offering. First seen on govinfosecurity.com…
-
Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attack
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Companies keep bolting AI onto their products, and the security bill is … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/05/week-in-review-simplehelp-vulnerability-exploited-oracle-ebs-payments-flaw-under-attack/
-
Breach Roundup: DeepSeek Sparks Browser Ransomware
Tags: ai, attack, breach, cisa, data, data-breach, fraud, india, iphone, oracle, penetration-testing, ransomwareAlso, False Negatives Causes Trust in AI Pentest to Drop. This week: a DeepSeek browser-only ransomware path, AI pen testing trust dropped, Mustang Panda targeted India, Tata breach exposed iPhone 18 data, CISA flagged BlueHammer in ransomware attacks, 950 Oracle EBS systems exposed, Amazon to pay U.S. Federal Trade Commission penalty over fraud records. First…
-
950 Oracle E-Business Suite Instances Exposed as CVE-2026-46817 Attacks Observed in the Wild
Around 950 internet-facing Oracle E-Business Suite (EBS) instances have been identified as exposed following enhanced scanning efforts. At the same time, active exploitation attempts tied to CVE-2026-46817 have already been observed in the wild. The findings were disclosed by The Shadowserver Foundation, which recently expanded its fingerprinting capabilities through domain-based scanning in collaboration with Validin.…
-
Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed
Oracle E-Business Suite flaw CVE-2026-46817 is under active attack, with about 950 vulnerable internet-facing instances still exposed. This week, Defused Cyber researchers warned that a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, is being actively exploited. The flaw affects Oracle Payments versions 12.2.3 through 12.2.15 and allows unauthenticated attackers to take over vulnerable…
-
Researchers spot exploitation of another critical Oracle defect
The defect impacts a popular collection of business applications that attackers have hit before in widespread attack sprees. First seen on cyberscoop.com Jump to article: cyberscoop.com/oracle-ebs-critical-vulnerability-exploited/
-
Critical flaw in Oracle E-Business Suite is under immediate threat
Researchers warn that successful exploitation of the vulnerability could allow an attacker to compromise Oracle Payments. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/critical-flaw-oracle-e-business-suite-threat/824230/
-
Over 900 Oracle E-Business instances exposed to ongoing attacks
Over 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks/
-
Critical Oracle E-Business Suite bug actively exploited
First seen on scworld.com Jump to article: www.scworld.com/news/critical-oracle-e-business-suite-bug-actively-exploited
-
Nissan confirms employee data exposed in Oracle PeopleSoft cyberattack
First seen on scworld.com Jump to article: www.scworld.com/brief/nissan-confirms-employee-data-exposed-in-oracle-peoplesoft-cyberattack
-
Nissan Traces Data Breach to PeopleSoft Zero-Day Exploit
Extortionists Add National Association of Insurance Commissioners to Breach List. Japanese automotive giant Nissan and the U.S. National Association of Insurance Commissioners are the latest organizations to confirm they fell victim to cyber extortionists who recently wielded a zero-day exploit against Oracle PeopleSoft, leading to the theft of data. First seen on govinfosecurity.com Jump to…
-
Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day
Nissan says employees’ data was stolen via the Oracle PeopleSoft zero-day campaign First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/nissan-oracle-peoplesoft-zero-day/
-
Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)
Exploitation attempts targeting a critical vulnerability (CVE-2026-46817) in Oracle Payments, the payment-processing module within Oracle’s E-Business Suite (EBS), have … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/30/oracle-payments-cve-2026-46817-exploitation/
-
Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817
Attackers are exploiting a critical flaw in Oracle E-Business Suite, CVE-2026-46817, that allows remote, unauthenticated attackers to take over Oracle Payments. A critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, is being actively exploited in the wild, according to cybersecurity firm Defused Cyber. >>CVE-2026-46817 (CVSS 9.8 unauth HTTP takeover in Oracle E-Business) is being…
-
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber.The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Payments that could be abused to take over susceptible instances.”Easily exploitable vulnerability allows First seen on thehackernews.com…
-
Nissan discloses employee data breach linked to Oracle zero-day attacks
Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/

