Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Oracle

20 articles

Security Affairs CVE Oracle NEW 4h ago

U.S. CISA adds Oracle PeopleSoft Enterprise PeopleTools flaw to its Known Exploited Vulnerabilities catalog

U.S.

1 IOC

Security Affairs →

Cyberscoop Vulnerability Disclosure Oracle 21h ago

ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw

Oracle still hasn't patched the vulnerability the group has been using in its attacks since late May. The post ShinyHunters is actively extorting universitie...

Cyberscoop →

Rapid7 Blog Zero-Day Oracle 23h ago

Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)

Overview On June 10, 2026, Oracle published a security alert for CVE-2026-35273, a critical vulnerability in the Updates Environment Management component of ...

T1190 1 IOC

Rapid7 Blog →

CISA Advisories CVE Oracle 1d ago

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-35273 Oracle Pe...

1 IOC

CISA Advisories →

BleepingComputer Zero-Day Oracle 1d ago

Oracle mitigates PeopleSoft zero-day exploited in data theft attacks

Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with ...

T1190 T1041 1 IOC

BleepingComputer →

SecurityWeek Zero-Day Oracle 1d ago

Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks

Oracle has released a patch for CVE-2026-35273, but it has not said whether it’s a zero-day exploited in ShinyHunters attacks. The post Oracle Addresses Peop...

1 IOC

SecurityWeek →

SC Media Zero-Day Oracle 2d ago

ShinyHunters gang targets Oracle PeopleSoft servers in data theft attacks

The ShinyHunters gang is exploiting a combination of old and zero-day vulnerabilities, referred to as a "gadget chain," to target both cloud and on-premises ...

T1041

SC Media →

BleepingComputer General Oracle 2d ago

Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks

Oracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100...

T1041

BleepingComputer →

SC Media General Oracle 2d ago

Mini Shai-Hulud ‘Hades’ variant affects 23 PyPI package versions

The JavaScript stealer payload includes an anti-analysis LLM prompt injection.

SC Media →

The Hacker News Vulnerability Disclosure Oracle 3d ago

Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

Cybersecurity researchers have flagged half a dozen vulnerabilities in protobuf.js, a JavaScript and TypeScript implementation of Protocol Buffers (Protobuf)...

T1190

The Hacker News →

The Hacker News General Oracle 4d ago

New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing

A malicious website can work out which sites you visit and which apps you open, using nothing but JavaScript and the timing of your SSD. The attack, called F...

The Hacker News →

GBHackers Malware Oracle 5d ago

Lucid Stealer Hits 18 Browsers, Crypto Wallets, and Discord Tokens

A new, fully featured Lucid Stealer build that combines large-scale credential theft with hidden remote access. The sample, distributed through Telegram-link...

T1078

GBHackers →

GBHackers Malware Oracle Jun 3

Fake Purchase Orders Spread JS.MonoGlyphRAT in U.S. Enterprise Attacks

Hackers are using highly convincing fake purchase orders and sales documents to sneak a new JavaScript backdoor, JS.MonoGlyphRAT, into US enterprises, where ...

GBHackers →

CSO Online CVE Oracle Jun 2

Two-year old Oracle WebLogic Server vulnerability is being exploited

US federal government departments have been given until Thursday to patch a two-year old high severity vulnerability in Oracle WebLogic Server that could all...

2 IOCs

CSO Online →

SC Media CVE Oracle Jun 2

CISA orders agencies to patch critical Oracle WebLogic Server vulnerability

The vulnerability, CVE-2024-21182, affects Oracle WebLogic Server versions 12.2.

3 IOCs

SC Media →

The Hacker News CVE Oracle Jun 2

Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation

The U.S.

1 IOC

The Hacker News →

BleepingComputer Vulnerability Disclosure Oracle Jun 2

CISA flags two-year-old Oracle flaw as actively exploited in attacks

CISA has ordered government agencies to secure their systems against a high-severity Oracle WebLogic Server vulnerability that was patched two years ago and ...

BleepingComputer →

SecurityWeek CVE Oracle Jun 2

Oracle WebLogic Vulnerability Exploited in the Wild

The vulnerability is CVE-2024-21182 and it can be exploited without authentication to hack affected WebLogic servers. The post Oracle WebLogic Vulnerability ...

1 IOC

SecurityWeek →

GBHackers CVE Oracle Jun 2

CISA Issues Alert on Oracle WebLogic Server Flaw Under Active Exploitation

The U.S.

1 IOC

GBHackers →

SecurityWeek Advisory Oracle Jun 2

Oracle’s First Monthly Patches Resolve 77 Vulnerabilities

Oracle’s monthly Critical Security Patch Update (CSPU) rollouts are meant to deliver critical fixes faster. The post Oracle’s First Monthly Patches Resolve 7...

SecurityWeek →

1 2 3 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA