Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
13 / 20 results
criticalbug_reportVulnerabilityOracle critical vulnerability under active exploitation, patching urgent
Multiple Oracle products affected. Specific product names, versions, and CVE identifiers not disclosed in available advisory. CERT.BE warning indicates at least one critical-severity vulnerability among multiple flaws.
criticalbug_reportVulnerabilityOracle WebLogic & HTTP Server CVE-2026-21962 actively exploited (CVSS 10.0)
Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (all versions prior to January 2026 patch). Affects unauthenticated attackers with network access via HTTP.
highbug_reportVulnerabilityCERT.BE warns of critical Oracle vulnerabilities requiring urgent patching
Multiple Oracle products affected. Specific product names, versions, and CVE identifiers not provided in advisory. Scope appears broad across Oracle product portfolio based on CERT.BE warning classification.
highbug_reportVulnerabilityOracle SQL injection exploited to deploy khunt toolkit inside database
Oracle databases with Java Virtual Machine enabled, particularly those connected to public-facing Java applications (Apache Tomcat observed). Specific Oracle versions not disclosed.
criticalbug_reportVulnerability900+ Oracle E-Business Suite instances exposed, under active attack
Oracle E-Business Suite instances exposed to the internet (900+ confirmed). Specific vulnerable versions not disclosed; critical severity vulnerability being exploited.
highperson_alertThreat ActorShinyHunters Exploits Oracle PeopleSoft Zero-Day in Nissan Breach
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has established a pattern of exploiting vulnerabilities in enterprise applications to exfiltrate sensitive data, which is th…
highperson_alertThreat ActorShinyHunters Exploits Oracle PeopleSoft Zero-Day at NAIC
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has historically targeted organizations to exfiltrate sensitive data, which is then leveraged for extortion or sold on under…
criticalbug_reportVulnerabilityOracle E-Business Suite under active exploit via CVE-2026-46817
Oracle E-Business Suite (EBS) financial application. Specific affected versions not disclosed in available intelligence.
criticalbug_reportVulnerabilityOracle PeopleSoft RCE actively exploited, immediate patching required
Oracle PeopleSoft (specific versions not disclosed in alert). Remote code execution vulnerability affecting internet-facing PeopleSoft instances.
criticalbug_reportVulnerabilityOracle PeopleSoft zero-day CVE-2026-35273 exploited by ShinyHunters
Oracle PeopleSoft (all versions prior to June 10 patch). Confirmed exploitation targeting enterprise systems and universities. Vulnerability was unpatched during active exploitation window (May 27 - June 9).
criticalbug_reportVulnerabilityOracle PeopleSoft zero-day CVE-2026-35273 exploited for RCE by ShinyHunter
Oracle PeopleSoft Suite, all versions (specific affected versions not disclosed). Unauthenticated remote code execution vulnerability affecting internet-facing PeopleSoft instances.
highperson_alertThreat ActorShinyHunters Targets Oracle PeopleSoft Servers in Mass Data Theft
ShinyHunters is a financially motivated cybercrime group known for large-scale data theft and extortion operations. The group has gained notoriety for breaching numerous organizations and exfiltrating sensitive data, which is then used for extortion…
highbug_reportVulnerabilityOracle releases critical security patches for multiple products
Multiple Oracle products affected by high-severity vulnerabilities. Specific product names, versions, and CVE identifiers not provided in CERT.BE advisory. Likely part of Oracle's quarterly Critical Patch Update (CPU).