Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Oracle

20 articles

GBHackers general Oracle 13h ago

Critical isolated-vm Flaw Lets Attackers Escape Sandbox and Hijack Host Control Flow

A critical vulnerability has been discovered in the widely used Node.js sandboxing library, isolated-vm.

GBHackers → Details

CSO Online enterprise Oracle 3d ago

Critical flaw patched in popular JavaScript sandbox used in AI projects

A critical sandbox escape vulnerability was discovered and patched in isolated-vm, a library for running JavaScript code inside an isolated process. If explo...

T1190

CSO Online → Details

SC Media general Oracle WordPress 4d ago

New malware campaign combines social engineering with defense evasion

The campaign, observed in late July 2026, begins with compromised WordPress websites injected with obfuscated ErrTraffic JavaScript.

T1204

SC Media → Details

The Hacker News general Oracle GitHub 4d ago

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on G...

The Hacker News → Details

Qualys Blog vendor Oracle 5d ago

Oracle Critical Patch Update, August 2026 Security Update Review

Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities.

Qualys Blog → Details

SecurityWeek general Oracle 5d ago

943 Patches Rolled Out With Oracle’s August 2026 Security Update

The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs. The post 943 Patches Rolled Out With Or...

SecurityWeek → Details

The Hacker News general Oracle 5d ago

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically desig...

T1190

The Hacker News → Details

GBHackers general Oracle 5d ago

Cl0p Hackers Exploit PTC Windchill Vulnerability to Deploy Custom Web Shell and Steal Data

The Cl0p ransomware and extortion operation is likely exploiting a critical PTC Windchill vulnerability to deploy a purpose-built Java web shell that can har...

T1190 T1041 1 IOC

GBHackers → Details

Tenable Blog vendor Oracle 5d ago

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs

Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates. Key Takeaways The August 2026 C...

Tenable Blog → Details

BleepingComputer general Oracle 6d ago

Clop created custom web shell for Windchill data theft attacks

A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to ...

T1190 T1041

BleepingComputer → Details

GBHackers general Oracle 6d ago

Projextor Abuses Cross-Platform Electron Framework to Conceal Malware Activity

Threat actors behind the Projextor campaign are abusing Electron-based productivity applications to conceal malware-like capabilities behind fully functionin...

T1059

GBHackers → Details

CSO Online enterprise Oracle Salesforce ServiceNow Aug 14

Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks

Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco. The attack appears similar to...

CSO Online → Details

Security Affairs general Oracle Aug 9

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Fake...

Security Affairs → Details

GBHackers general Oracle Apache Aug 7

Enterprise Java Vulnerabilities Enable Pre-Auth RCE in Bonita BPM and Apache OFBiz

Security research presented at Black Hat 2026 has identified 12 vulnerabilities across four enterprise Java platforms, including two critical pre-authenticat...

T1190

GBHackers → Details

Infosecurity Magazine general Oracle Aug 6

Toolkit Hidden Inside Oracle Database Evades Endpoint Tools

Attackers used SQL injection to compile a post-exploitation toolkit inside an Oracle database

Infosecurity Magazine → Details

CSO Online enterprise Oracle Aug 6

Attackers hid malware inside Oracle Database after SQL injection breach

Huntress has documented a case where the Oracle database itself became the malware host. The security firm disclosed a campaign in which threat actors exploi...

T1078 T1598

CSO Online → Details

The Hacker News general Oracle Aug 6

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

Coinspect has identified CryptoJS.lib.

The Hacker News → Details

GBHackers general Oracle Aug 6

KHunt Toolkit Turns Oracle SQL Injection Into SYSTEM-Level RCE and Credential Theft

KHunt shows how a “routine” SQL injection against an Oracle‑backed web app can be weaponized into SYSTEM‑level remote code execution and credential theft by ...

T1190 T1078 T1598

GBHackers → Details

GBHackers general Oracle Aug 6

Critical Jenkins Deserialization Flaw Allows Attackers to Execute Code on Controllers

A critical vulnerability in Jenkins, tracked as CVE-2026-70426, may allow attackers to execute arbitrary code on Jenkins controllers by bypassing deserializa...

1 IOC

GBHackers → Details

BleepingComputer general Oracle Aug 5

Hackers run khunt post-exploitation toolkit from Oracle database

Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate...

BleepingComputer → Details

1 2 3 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA