Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Oracle

20 articles

BleepingComputer general Oracle Aug 5

Hackers run khunt post-exploitation toolkit from Oracle database

Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate...

BleepingComputer → Details

Help Net Security general Oracle Aug 5

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenti...

Help Net Security → Details

GBHackers general Oracle Aug 4

Fake Xeno Roblox Cheats Deliver Java RAT That Steals Discord and Gaming Accounts

Fake Roblox cheat tools are once again being weaponized, with a newly observed campaign distributing a sophisticated Java-based remote access trojan (RAT) di...

GBHackers → Details

GBHackers general Oracle GitHub Aug 4

Shai-Hulud Supply Chain Attack Compromises Keyv and Hundreds of npm Packages

Attackers have compromised the GitHub account of a Keyv maintainer, a widely used JavaScript key-value storage library, to distribute credential-stealing mal...

T1195

GBHackers → Details

SC Media general Oracle Aug 3

Adform supply-chain attack replaced crypto wallet addresses

The attack exploited Adform's JavaScript tracking script, "trackpoint-async.js," which is embedded in numerous websites.

SC Media → Details

Cloudflare Blog vendor Oracle Aug 3

Workers RPC now works across Python and JavaScript

One coding agent can write a Python Worker and another can write a JavaScript Worker. At runtime, those Workers can exchange references to live objects and c...

Cloudflare Blog → Details

Help Net Security general Oracle Aug 3

Qodana 2026.2 adds post-quantum crypto checks for JVM code

Qodana 2026.2 shipped with new security inspections, published benchmark results, post-quantum cryptography checks, and coverage reporting that no longer has...

T1059

Help Net Security → Details

The Hacker News general Oracle Aug 1

Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites

Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet...

The Hacker News → Details

GBHackers general Oracle Jul 30

Hackers Can Compromise Tor Browser Users by Exploiting Firefox JIT Flaw

Tor Browser users on unpatched versions may be at risk of compromise simply by visiting a malicious webpage, following the disclosure of CVE-2026-10702, a se...

T1598 1 IOC

GBHackers → Details

The Hacker News general Oracle Jul 29

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POP...

1 IOC

The Hacker News → Details

SC Media general Oracle Jul 28

Hackers exploit FastJson vulnerability for remote code execution

Bleeping Computer disclosed that hackers are actively exploiting a critical vulnerability in the FastJson open-source Java library, enabling remote code exec...

T1190

SC Media → Details

BleepingComputer general Oracle Jul 27

Hackers target US firms in FastJson RCE zero-day attacks

Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated...

T1190

BleepingComputer → Details

SC Media general Oracle Jul 27

Malvertising campaign assembles malware in browser

A large-scale malvertising campaign is using fake websites for Solana, Luno, and TradingView, employing malicious JavaScript to assemble malware directly in ...

T1189

SC Media → Details

SANS ISC advisories Oracle Jul 27

Java Spring Boot "heapdump" scans, (Mon, Jul 27th)

Spring Boot exposes the endpoint "/actuator/heapdump" to collect debug information. By default, the endpoint will return a file heapdump.

SANS ISC → Details

BleepingComputer general Oracle Jul 25

Malicious sites use JavaScript to build malware in browser memory

A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware di...

T1189

BleepingComputer → Details

The Hacker News general Oracle Jul 25

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot appli...

1 IOC

The Hacker News → Details

GBHackers general Oracle Jul 25

Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials

A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.

T1566

GBHackers → Details

Unit 42 research Oracle Jul 23

Russian Global Webmail Espionage

Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global W...

Unit 42 → Details

CSO Online enterprise Oracle Jul 22

Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware

Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Busi...

CSO Online → Details

Qualys Blog vendor Oracle Jul 22

Oracle Critical Patch Update, July 2026 Security Update Review

Oracle released its third quarterly edition of this year’s Critical Patch Update. The update received patches for 1449 security vulnerabilities.

Qualys Blog → Details

«Previous page 1 2 3 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA