Estée Lauder Data Breach: Oracle E-Business Suite Flaw Exploited
Estée Lauder discloses a data breach affecting HR systems due to an unpatched flaw in Oracle E-Business Suite. Customers notified of potential data exposure.
Oracle EBS: Over 900 Instances Exposed to Ongoing Attacks
Over 900 Oracle E-Business Suite (EBS) instances are exposed online, facing ongoing attacks targeting a critical flaw. Learn the risks and mitigation steps.
ShinyHunters Breach NAIC via PeopleSoft Zero-Day: Public Data Stolen
ShinyHunters exploited an Oracle PeopleSoft zero-day to breach NAIC, exfiltrating public data, logs, and configuration files. Review PeopleSoft security.
Nissan Breach: Oracle PeopleSoft Zero-Day Exploited by ShinyHunters
Nissan discloses a data breach impacting current and former employees, attributed to an exploited Oracle PeopleSoft zero-day vulnerability linked to the ShinyHunters…
Oracle PeopleSoft CVE-2026-35273 Exploit: CISA KEV Mitigation Guide
CISA adds CVE-2026-35273 in Oracle PeopleSoft to its KEV catalog. Learn how to mitigate this missing authentication vulnerability and protect enterprise systems.
ShinyHunters Exploits Oracle ERP Zero-Day to Breach Higher Ed
ShinyHunters is exploiting an unpatched zero-day vulnerability in Oracle ERP software, targeting US higher education institutions for data theft.
CVE-2026-35273: Oracle PeopleSoft RCE Exploited as Zero-Day by ShinyHunters
Mandiant and GTIG identified ShinyHunters (UNC6240) exploiting CVE-2026-35273, a critical RCE in Oracle PeopleSoft, targeting higher education.
Oracle PeopleSoft RCE via CVE-2026-35273 — Mitigation Guide
ShinyHunters (UNC6240) exploited an Oracle PeopleSoft zero-day (CVE-2026-35273) to breach university networks and exfiltrate data for extortion purposes.
CVE-2024-21319: PeopleSoft Auth Bypass Exploited by ShinyHunters
Oracle PeopleSoft zero-day CVE-2024-21319, an authentication bypass, is being actively exploited by ShinyHunters. Patch PeopleSoft 8.59, 8.60, 8.61 now.
CVE-2022-21371: CISA Warns of Oracle WebLogic Exploitation
CISA adds CVE-2022-21371 to its KEV catalog, warning of active exploitation of an information disclosure flaw in Oracle WebLogic Server. Patch immediately.
Oracle January 2025 CSPU: Addressing 77 Security Vulnerabilities
Oracle transitions to monthly Critical Security Patch Updates, resolving 77 flaws including critical RCE vulnerabilities in Communications and Hospitality suites.
CVE-2024-21182: Oracle WebLogic Server Under Active Exploitation
CISA added CVE-2024-21182, an unspecified vulnerability in Oracle WebLogic Server, to its KEV Catalog due to active exploitation. Immediate patching required.
Security Analysis of Prediction Market Oracle Manipulation on Polymarket
An investigation into the vulnerabilities of decentralized oracles, including physical sensor tampering and insider trading risks within Polymarket.
Oracle Red Bull Racing: Securing F1 IP via Identity Automation
Discover how Oracle Red Bull Racing leverages identity governance automation to protect intellectual property and streamline security in high-stakes F1 environments.
Oracle April 2026 CPU: 481 Patches for Unauthenticated Flaws
Oracle's April 2026 Critical Patch Update addresses 481 vulnerabilities across 28 product families, including 300+ unauthenticated remote exploits.
CVE-2021-35587: Critical RCE in Oracle Identity Manager Patched
Oracle issues emergency patches for CVE-2021-35587, a critical RCE flaw in Identity Manager with a 9.8 CVSS score. Immediate mitigation is required.
Oracle Fusion Middleware RCE Flaw: Immediate Patch Required
A critical unauthenticated remote code execution (RCE) flaw in Oracle Fusion Middleware's Identity and Web Services Managers demands immediate patching.
Oracle Identity Manager RCE via CVE-2026-21992 — Patch Now
Oracle issued an emergency patch for CVE-2026-21992, a critical unauthenticated RCE flaw in Identity Manager and Web Services Manager. Immediate patching is required.
Native Launches Multicloud Security Control Plane for Policy Enforcement
Native introduces a security control plane that translates and enforces consistent policies across AWS, Azure, GCP, and Oracle using provider-native APIs.
Oracle EBS Exploitation: Risks to Enterprise Financial Integrity
Analysis of the Oracle EBS hack affecting major corporations and the technical risks associated with unpatched ERP systems and financial data theft.