Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Oracle

16 articles

Tenable Blog vendor Oracle Jul 21

Oracle July 2026 Critical Patch Update Addresses 1235 CVEs

Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Up...

Tenable Blog → Details

CISA Advisories advisories Oracle Jul 15

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-4346 KNX Asso...

2 IOCs

CISA Advisories → Details

Infosecurity Magazine general Oracle Jun 30

Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day

Nissan says employees' data was stolen via the Oracle PeopleSoft zero-day campaign

Infosecurity Magazine → Details

Infosecurity Magazine general Oracle Jun 29

US Federal Insurance Regulator Confirms Data Breach Via Oracle Flaw

An attacker has exploited a zero day in Oracle Peoplesoft to gain access to the IT systems of the NAIC, the standard-setting association for the US federal i...

Infosecurity Magazine → Details

Zero Day Initiative advisories Oracle Jun 24

ZDI-26-389: Oracle PeopleSoft ExecuteProcessActivityCommand External Control of File Path Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle PeopleSoft. Although authentication is required to e...

T1190 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Oracle Jun 24

ZDI-26-388: Oracle PeopleSoft HubMBeanPersistance Deserialization of Untrusted Data Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle PeopleSoft. Although authentication is required to e...

T1190 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Oracle Jun 24

ZDI-26-387: Oracle PeopleSoft HttpListeningConnector Server-Side Request Forgery Vulnerability

This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Oracle PeopleSoft. Authentication is not r...

1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Oracle Jun 24

ZDI-26-362: Oracle VirtualBox VMSVGA Stack-based Buffer Overflow Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to...

T1548 T1068 1 IOC

Zero Day Initiative → Details

Information Security Buzz general Oracle Jun 19

ShinyHunters targets Oracle PeopleSoft customers through critical zero-day

Oracle has issued a security alert to customers about a critical vulnerability affecting PeopleSoft environments after the notorious threat actor ShinyHunter...

1 IOC

Information Security Buzz → Details

Infosecurity Magazine general Oracle May 27

PureLogs Variant Steals Data via Purchase Order Lures

FortiGuard Labs detailed a PureLogs campaign using JavaScript, PowerShell and process hollowing

Infosecurity Magazine → Details

Fortinet Blog vendor Oracle May 26

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data

FortiGuard Labs analyzed a new phishing campaign that uses obfuscated JavaScript, PowerShell, process hollowing, and PureLogs to steal sensitive data

T1566

Fortinet Blog → Details

Zero Day Initiative advisories Oracle Apr 28

ZDI-26-306: Oracle VirtualBox SoundBlaster 16 Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to...

T1548 T1068 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Oracle Apr 28

ZDI-26-305: (0Day) OpenAI Codex Sandbox Escape Vulnerability

This vulnerability allows remote attackers to bypass the sandbox on affected installations of OpenAI Codex. User interaction is required to exploit this vuln...

Zero Day Initiative → Details

PortSwigger Research research Oracle Aug 7

Listen to the whispers: web timing attacks that actually work

Websites are riddled with timing oracles eager to divulge their innermost secrets. It's time we started listening to them.

PortSwigger Research → Details

PortSwigger Research research Oracle Jan 23

Hiding payloads in Java source code strings

In this post we'll show you how Java handles unicode escapes in source code strings in a way you might find surprising - and how you can abuse them to concea...

PortSwigger Research → Details

Threatpost general Oracle Aug 30

Watering Hole Attacks Push ScanBox Keylogger

Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.

T1203 T1189 T1592

Threatpost → Details

«Previous page 1 2 3
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA