BreachFeed
company

Oracle

Tracked by 1 person

Track Oracle

Incident history

CSO Online·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu4acuev85yfhpu2f1pgek1h

Oracle’s September patches put Fusion Middleware back in the hot seat

Oracle’s September 2026 Critical Security Patch Update has arrived with 673 new security patches spanning 17 Oracle product families, with Oracle E-Business Suite accounting for the largest share at 159 patches, followed by Fusion Middleware with 153. Of these, 19 E-Business Suite vulnerabilities and 78 Fusion Middleware vulnerabilities can be remotely exploited without authentication. Other product categories with 50 or more issues fixed in the rollout include Oracle Database Server, Oracle…

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmty9is1t1gdnhpu2q7g0hyvt

Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks

A critical zero-day vulnerability in Oracle PeopleSoft exposed the Council of Europe and scores of other organizations to data theft and extortion in May and early June 2026. The ShinyHunters hacking group exploited the flaw across about 100 organizations and 300 instances worldwide, according to reports cited by The Register. The attackers targeted the management and configuration layers of enterprise resource-planning systems, stealing sensitive records. […] The post Beyond the Perimeter:…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq0028hnu2mtwm9vbb

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzpe004hhku2x9g2o6qe

Feds ban Fable, Maine portal disabled, ShinyHunters exploits Oracle

Feds require Anthropic to ban 'foreign national' access to Fable, Mythos Maine disables data breach notification portal after fake disclosures ShinyHunters extorts universities through exploiting an unpatched Oracle flaw Get the show notes here: Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And…

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzpe004rhku2afadgrvj

Russia claims officials' surveillance, Project Glasswing expands, CISA flags two-year-old Oracle flaw

Russia claims officials' surveillance Project Glasswing access expands CISA flags two-year-old Oracle flaw Get the show notes here: https://cisoseries.com/cybersecurity-news-russia-claims-officials-surveillance-project-glasswing-expands-cisa-flags-two-year-old-oracle-flaw/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta [rhymes with Santa] Agent works like a GRC engineer in the…