Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Oracle

20 articles

PortSwigger Research research Oracle Aug 25

What's in a tag name? JavaScript, apparently

I was on my laptop, as I often am when there's rubbish on telly, and found myself wondering what characters are allowed in a tag. I knew they had to begin wi...

PortSwigger Research → Details

Security Affairs general Oracle Aug 25

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

U.S.

1 IOC

Security Affairs → Details

SecurityWeek general Oracle Aug 25

CISA Warns of Exploited Oracle WebLogic Vulnerability

The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited O...

1 IOC

SecurityWeek → Details

The Hacker News general Oracle Aug 25

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S.

1 IOC

The Hacker News → Details

GBHackers general Oracle Aug 25

Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive Data

The U.S.

1 IOC

GBHackers → Details

CISA Advisories advisories Oracle Aug 24

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-21962 Oracle HT...

1 IOC

CISA Advisories → Details

GBHackers general Oracle Aug 24

Critical isolated-vm Flaw Lets Attackers Escape Sandbox and Hijack Host Control Flow

A critical vulnerability has been discovered in the widely used Node.js sandboxing library, isolated-vm.

GBHackers → Details

CSO Online enterprise Oracle Aug 20

Critical flaw patched in popular JavaScript sandbox used in AI projects

A critical sandbox escape vulnerability was discovered and patched in isolated-vm, a library for running JavaScript code inside an isolated process. If explo...

T1190

CSO Online → Details

SC Media general Oracle WordPress Aug 20

New malware campaign combines social engineering with defense evasion

The campaign, observed in late July 2026, begins with compromised WordPress websites injected with obfuscated ErrTraffic JavaScript.

T1204

SC Media → Details

The Hacker News general Oracle GitHub Aug 20

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on G...

The Hacker News → Details

Qualys Blog vendor Oracle Aug 19

Oracle Critical Patch Update, August 2026 Security Update Review

Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities.

Qualys Blog → Details

SecurityWeek general Oracle Aug 19

943 Patches Rolled Out With Oracle’s August 2026 Security Update

The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs. The post 943 Patches Rolled Out With Or...

SecurityWeek → Details

The Hacker News general Oracle Aug 19

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically desig...

T1190

The Hacker News → Details

GBHackers general Oracle Aug 19

Cl0p Hackers Exploit PTC Windchill Vulnerability to Deploy Custom Web Shell and Steal Data

The Cl0p ransomware and extortion operation is likely exploiting a critical PTC Windchill vulnerability to deploy a purpose-built Java web shell that can har...

T1190 T1041 1 IOC

GBHackers → Details

Tenable Blog vendor Oracle Aug 19

Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs

Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates. Key Takeaways The August 2026 C...

Tenable Blog → Details

BleepingComputer general Oracle Aug 18

Clop created custom web shell for Windchill data theft attacks

A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to ...

T1190 T1041

BleepingComputer → Details

GBHackers general Oracle Aug 18

Projextor Abuses Cross-Platform Electron Framework to Conceal Malware Activity

Threat actors behind the Projextor campaign are abusing Electron-based productivity applications to conceal malware-like capabilities behind fully functionin...

T1059

GBHackers → Details

CSO Online enterprise Oracle Salesforce ServiceNow Aug 14

Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks

Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco. The attack appears similar to...

CSO Online → Details

Security Affairs general Oracle Aug 9

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Fake...

Security Affairs → Details

GBHackers general Oracle Apache Aug 7

Enterprise Java Vulnerabilities Enable Pre-Auth RCE in Bonita BPM and Apache OFBiz

Security research presented at Black Hat 2026 has identified 12 vulnerabilities across four enterprise Java platforms, including two critical pre-authenticat...

T1190

GBHackers → Details

«Previous page 1 2 3 4 5 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA