Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Oracle

20 articles

GBHackers general Oracle 1d ago

Hackers Can Compromise Tor Browser Users by Exploiting Firefox JIT Flaw

Tor Browser users on unpatched versions may be at risk of compromise simply by visiting a malicious webpage, following the disclosure of CVE-2026-10702, a se...

T1598 1 IOC

GBHackers → Details

The Hacker News general Oracle 2d ago

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POP...

1 IOC

The Hacker News → Details

SC Media general Oracle 3d ago

Hackers exploit FastJson vulnerability for remote code execution

Bleeping Computer disclosed that hackers are actively exploiting a critical vulnerability in the FastJson open-source Java library, enabling remote code exec...

T1190

SC Media → Details

BleepingComputer general Oracle 3d ago

Hackers target US firms in FastJson RCE zero-day attacks

Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated...

T1190

BleepingComputer → Details

SC Media general Oracle 4d ago

Malvertising campaign assembles malware in browser

A large-scale malvertising campaign is using fake websites for Solana, Luno, and TradingView, employing malicious JavaScript to assemble malware directly in ...

T1189

SC Media → Details

SANS ISC advisories Oracle 4d ago

Java Spring Boot "heapdump" scans, (Mon, Jul 27th)

Spring Boot exposes the endpoint "/actuator/heapdump" to collect debug information. By default, the endpoint will return a file heapdump.

SANS ISC → Details

BleepingComputer general Oracle 6d ago

Malicious sites use JavaScript to build malware in browser memory

A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware di...

T1189

BleepingComputer → Details

The Hacker News general Oracle 6d ago

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot appli...

1 IOC

The Hacker News → Details

GBHackers general Oracle 6d ago

Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials

A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.

T1566

GBHackers → Details

Unit 42 research Oracle Jul 23

Russian Global Webmail Espionage

Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global W...

Unit 42 → Details

CSO Online enterprise Oracle Jul 22

Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware

Oracle’s July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Busi...

CSO Online → Details

Qualys Blog vendor Oracle Jul 22

Oracle Critical Patch Update, July 2026 Security Update Review

Oracle released its third quarterly edition of this year’s Critical Patch Update. The update received patches for 1449 security vulnerabilities.

Qualys Blog → Details

Tenable Blog vendor Oracle Jul 21

Oracle July 2026 Critical Patch Update Addresses 1235 CVEs

Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates. Key Takeaways The third Critical Patch Up...

Tenable Blog → Details

CISA Advisories advisories Oracle Jul 15

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-4346 KNX Asso...

2 IOCs

CISA Advisories → Details

Infosecurity Magazine general Oracle Jun 30

Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day

Nissan says employees' data was stolen via the Oracle PeopleSoft zero-day campaign

Infosecurity Magazine → Details

Infosecurity Magazine general Oracle Jun 29

US Federal Insurance Regulator Confirms Data Breach Via Oracle Flaw

An attacker has exploited a zero day in Oracle Peoplesoft to gain access to the IT systems of the NAIC, the standard-setting association for the US federal i...

Infosecurity Magazine → Details

Zero Day Initiative advisories Oracle Jun 24

ZDI-26-389: Oracle PeopleSoft ExecuteProcessActivityCommand External Control of File Path Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle PeopleSoft. Although authentication is required to e...

T1190 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Oracle Jun 24

ZDI-26-388: Oracle PeopleSoft HubMBeanPersistance Deserialization of Untrusted Data Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle PeopleSoft. Although authentication is required to e...

T1190 1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Oracle Jun 24

ZDI-26-387: Oracle PeopleSoft HttpListeningConnector Server-Side Request Forgery Vulnerability

This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Oracle PeopleSoft. Authentication is not r...

1 IOC

Zero Day Initiative → Details

Zero Day Initiative advisories Oracle Jun 24

ZDI-26-362: Oracle VirtualBox VMSVGA Stack-based Buffer Overflow Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to...

T1548 T1068 1 IOC

Zero Day Initiative → Details

1 2 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA