Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Oracle

20 articles

The Hacker News general Oracle Sep 7

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against ap...

T1190 1 IOC

The Hacker News → Details

GBHackers general Oracle Sep 1

JSCeal Crypto Stealer Uses V8 Bytecode to Steal Browser Credentials and Intercept HTTPS

A sophisticated cryptocurrency-focused information stealer that hides its malicious logic inside compiled V8 JavaScript bytecode. JSCeal, also tracked by som...

GBHackers → Details

Kaspersky Securelist research Oracle Sep 1

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Kaspersky Securelist → Details

Security Affairs general Oracle Aug 30

Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft

Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchest...

T1041

Security Affairs → Details

GBHackers general Oracle Aug 28

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page for virtually every request, undermin...

T1566

GBHackers → Details

Security Affairs general Oracle Aug 26

U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog

U.S.

1 IOC

Security Affairs → Details

SC Media general Oracle Aug 25

CISA adds Oracle WebLogic bug to its list of exploited vulnerabilities

Experts say exploiting WebLogic middleware gives attackers access to an enterprise's core business apps.

SC Media → Details

PortSwigger Research research Oracle Aug 25

What's in a tag name? JavaScript, apparently

I was on my laptop, as I often am when there's rubbish on telly, and found myself wondering what characters are allowed in a tag. I knew they had to begin wi...

PortSwigger Research → Details

Security Affairs general Oracle Aug 25

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

U.S.

1 IOC

Security Affairs → Details

SecurityWeek general Oracle Aug 25

CISA Warns of Exploited Oracle WebLogic Vulnerability

The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers. The post CISA Warns of Exploited O...

1 IOC

SecurityWeek → Details

The Hacker News general Oracle Aug 25

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S.

1 IOC

The Hacker News → Details

GBHackers general Oracle Aug 25

Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive Data

The U.S.

1 IOC

GBHackers → Details

CISA Advisories advisories Oracle Aug 24

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-21962 Oracle HT...

1 IOC

CISA Advisories → Details

GBHackers general Oracle Aug 24

Critical isolated-vm Flaw Lets Attackers Escape Sandbox and Hijack Host Control Flow

A critical vulnerability has been discovered in the widely used Node.js sandboxing library, isolated-vm.

GBHackers → Details

CSO Online enterprise Oracle Aug 20

Critical flaw patched in popular JavaScript sandbox used in AI projects

A critical sandbox escape vulnerability was discovered and patched in isolated-vm, a library for running JavaScript code inside an isolated process. If explo...

T1190

CSO Online → Details

SC Media general Oracle WordPress Aug 20

New malware campaign combines social engineering with defense evasion

The campaign, observed in late July 2026, begins with compromised WordPress websites injected with obfuscated ErrTraffic JavaScript.

T1204

SC Media → Details

The Hacker News general Oracle GitHub Aug 20

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on G...

The Hacker News → Details

Qualys Blog vendor Oracle Aug 19

Oracle Critical Patch Update, August 2026 Security Update Review

Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities.

Qualys Blog → Details

SecurityWeek general Oracle Aug 19

943 Patches Rolled Out With Oracle’s August 2026 Security Update

The fixes resolve over 1,000 vulnerabilities across two dozen products, including over 460 remotely exploitable bugs. The post 943 Patches Rolled Out With Or...

SecurityWeek → Details

The Hacker News general Oracle Aug 19

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically desig...

T1190

The Hacker News → Details

«Previous page 1 2 3 4 5 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA