🔍 On day one of Zero Day Initiative’s Pwn2Own Ireland 2026, ethical hacking teams discovered 32 zero-day vulnerabilities across smartphones, smart home devices, printers and AI tools, earning over $368,000 in prizes. Notable successes included exploits against Sonos Era 300, LiteLLM, Philips Hue Bridge Pro, Lexmark CX532adwe, Oracle Autonomous AI Database, OpenAI Codex and Garmin Index BPM. Findings will be responsibly disclosed to vendors with a 90-day patch window as the contest continues.
🔒 The FBI removed an Accenture contractor after a data breach exposed personal details of employees tied to an unpatched third-party platform. FBI Cyber Division Assistant Director Brett Leatherman said the incident resulted from a security failure when a contractor did not apply a required patch. Reuters sources identified the platform as Oracle PeopleSoft, and said the contractor worked for Accenture on the system.
FBI Removes Contractor Over ShinyHunters Job Portal Breach
🔒 The FBI removed an Accenture contractor after an alleged role in a ShinyHunters breach that exposed thousands of bureau employees' personal data. Reuters sources say the incident stemmed from a third-party platform security failure where a contractor failed to apply an explicit patch. The FBI cited mitigation steps and removal of the contractor, while Accenture affirmed continued support for the FBI mission. Reports indicate the exploited platform was Oracle PeopleSoft and the attack leveraged a CVE-2026-35273 bypass.
Enterprises face uncertainty after PeopleSoft breach claims
🛡️ The theft of FBI employee data tied to ShinyHunters and the shutdown of the FBI’s PeopleSoft jobs portal has raised alarm among enterprise users of PeopleSoft. Law enforcement has made arrests, but neither the FBI nor Oracle has clarified whether a new PeopleSoft zero-day caused the breach. Analysts urge immediate mitigations—patches, removing exposed management interfaces, and hunting for web shells—while warning that vendor silence and unconfirmed claims leave many organizations exposed.
🛡️ The FBI thanked Dutch police for arresting a 24-year-old suspected of playing a leadership role in the ShinyHunters gang, and warned remaining members to come forward while they still can. The arrest followed revelations that ShinyHunters breached the FBI job application portal, exposing Social Security numbers and sensitive medical records of about 5,000 staff. The group claims to have exploited a patched Oracle PeopleSoft flaw and has since escalated activity, including extortion attempts against other cybercrime groups.
Attackers Bypass WAFs to Exploit Oracle PeopleSoft
🛡️ Google warns of renewed mass exploitation of a critical Oracle PeopleSoft flaw (CVE-2026-35273, CVSS 9.8) by activity linked to ShinyHunters/UNC6240. The campaign weaponizes a modified exploit that URL-encodes the character "P" to bypass WAF rules, targeting multiple sectors globally and deploying web shells, trojanized installers, and backdoors. Affected organizations are urged to apply patches, disable or remove the PSEMHUB component, inspect logs and web directories, rotate credentials, and hunt for signs of data exfiltration and persistence.
🔍 Mandiant and Google Threat Intelligence Group (GTIG) report that UNC6240 (ShinyHunters) resumed mass exploitation of CVE-2026-35273 against Oracle PeopleSoft by URL-encoding the vulnerable /PSEMHUB/ path to bypass WAF rules. The actor deployed web shells and a trojanized binary (Ple64.exe) loading the SIDEEYE backdoor, expanding targeting across education, technology, healthcare, government and more. Immediate patching, WAF normalization, and mitigation guidance are recommended.
Oracle September patches put Fusion Middleware at risk
🛡️ Oracle’s September 2026 Critical Security Patch Update delivers 673 fixes across 17 product families, led by Oracle E-Business Suite (159 patches) and Fusion Middleware (153). Several vulnerabilities in these products are remotely exploitable without authentication, including five Fusion Middleware flaws rated CVSS 10.0 and an additional CVSS 10.0 issue in Hyperion Financial Management. Oracle urges immediate patching and notes that mitigations such as blocking protocols or removing privileges may break functionality and are not substitutes for updates.
Amazon RDS for Oracle Adds July 2026 Supplemental Patch
🔔 Amazon RDS for Oracle now supports the Supplemental Patch Bundle (SPB) for the July 2026 Release Update (RU) for Oracle Database 19c and 26ai. Starting April 2026, Oracle renamed the Oracle Spatial Patch Bundle to Supplemental Patch Bundle, which includes targeted fixes for features like Oracle Spatial, Data Pump, and GoldenGate. You can apply the SPB to new or existing instances by selecting the "Supplemental Patch Bundle Engine Versions" checkbox in the AWS Console, and use AWS Organizations rollout policy to stagger automatic minor upgrades across environments.
🔒 CISA has added a maximum-severity vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (CVE-2026-21962, CVSS 10.0) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaw allows unauthenticated HTTP access to create, modify, or delete critical data and potentially gain full access to affected instances. Oracle released patches in January, but reports from GreyNoise and CloudSEK indicate ongoing exploitation activity. Federal agencies must remediate under BOD 26-04 by August 27, 2026.
🔔 Amazon RDS for Oracle now supports Oracle Application Express (APEX) 26.1, a low-code platform for building secure, scalable enterprise applications. This managed database service simplifies setup, operation, and scaling of Oracle Database deployments in the cloud. APEX 26.1 is available in all AWS regions where RDS for Oracle is offered; consult the RDS documentation for details on enabling or modifying APEX options.
Oracle launches Database Security Central free trial
🔒 Oracle has introduced Database Security Central, a tool that provides a centralized view of security risk across database environments and will be free through February 2027. It arrives as attackers increasingly target Oracle database flaws and following Oracle’s move to monthly patch releases. The tool assesses posture, detects configuration drift, highlights privileged access risks, monitors sensitive data access, and centralizes policy management and audit evidence collection.
Post‑exploitation toolkit embedded inside Oracle DB
🛡️ Huntress discovered a post‑exploitation toolkit compiled and stored as schema objects inside an Oracle database, enabling command execution on the underlying Windows host. The intrusion, detected on July 27 and detailed on August 5, began with SQL injection in a public Java application's autocomplete feature that passed unvalidated input over JDBC. Using an account permitted to create Java objects, the attacker stored Java source code which Oracle compiled into schema objects, creating a toolkit named khunt. Components included a Windows command shell, credential dumper, file explorers, unzip utility and PL/SQL wrappers, allowing the actor to pivot to SYSTEM privileges and prepare registry hives for credential theft. Huntress highlighted detection gaps because endpoint tools typically do not inspect Java classes and PL/SQL objects inside databases, turning the DB into an operational foothold; they recommended input sanitization, parameterized queries and least‑privilege for query‑capable accounts.
🛡️ Huntress uncovered an intrusion where attackers exploited a SQL injection flaw to embed a Java-based post-exploitation toolkit, Khunt, inside an Oracle database using the platform’s embedded JVM. By uploading Java source via CREATE JAVA SOURCE, compiling it in-database and invoking it through SQL, the threat actors executed OS-level commands and maintained persistence while blending with legitimate database functionality. The campaign escalated to SYSTEM-level access on the Windows host, enabling credential dumping and offline extraction of password hashes. Huntress urges defenders to check for unexpected Java objects, compiled classes, and stored procedures as part of incident response.
🛡️ Oracle’s July 2026 Critical Patch Update is its largest ever, delivering 1,449 fixes across 32 product families, including Database, Fusion Middleware, Java SE, and GoldenGate. Fusion Middleware saw 355 vulnerabilities, 219 exploitable remotely without authentication, and ten scored a CVSS 10.0. Database Server received critical fixes including CVE-2026-61211 (CVSS 9.9) in DBMS_CLOUD and an Oracle Net Services flaw, with additional OpenSSL-related patches. Experts urge rapid triage based on exposure and business impact as the sheer volume outpaces typical patching workflows.
Estée Lauder discloses Oracle E‑Business Suite breach
🛡️ Estée Lauder is notifying individuals after discovering that an unauthorized actor accessed its Oracle E-Business Suite HR system on or around August 9, 2025, exposing personal information. The company's investigation concluded on June 19, 2026, and the exposed data may include names, contact details, SSNs, passport numbers, bank account and health information. The breach correlates with mass exploitation tied to CVE-2025-61882 and activity by the Clop group; affected individuals are being offered 24 months of identity monitoring through Kroll.
CISA orders federal patching for exploited Oracle EBS flaw
🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch systems by Saturday to mitigate active exploitation of a critical Oracle E-Business Suite vulnerability, tracked as CVE-2026-46817. The flaw in the Oracle Payments File Transmission component allows unauthenticated HTTP access leading to system takeover in low-complexity attacks. Oracle issued fixes in its May 2026 Critical Security Patch Update and urged immediate patching, while security firms and CISA have observed active exploitation. Shadowserver reports over 1,000 Internet-exposed Oracle EBS instances, many in the U.S., prompting CISA to add the flaw to its list of known exploited vulnerabilities and mandate remediation under BOD 26-04.
🚀 Amazon RDS for Oracle now supports Oracle Database 26ai, Oracle's Long Term Support release, with integration to Amazon Bedrock providing access to foundation models such as Anthropic Claude, Amazon Nova, and Meta Llama. Oracle Database 26ai enables Select AI for generating and running SQL from natural language prompts and supports in-database RAG via Oracle AI Vector Search, avoiding the need for a separate vector store. The release also offers JSON Relational Duality Views and SQL Property Graphs and is available in Enterprise Edition across commercial and GovCloud regions.
Over 900 Oracle E-Business instances exposed online
🔒 Over 900 Oracle E-Business Suite (EBS) instances were found exposed online amid active attacks exploiting a critical File Transmission flaw in Oracle Payments (CVE-2026-46817). The vulnerability permits unauthenticated HTTP takeover, and Oracle released patches in its May 2026 Critical Security Patch Update, urging immediate remediation. Threat intelligence firm Defused reported active exploitation observed on honeypots, while Shadowserver noted roughly 950 exposed instances and the extent of patching remains unclear.
Critical Oracle E‑Business Suite Flaw Actively Exploited
🔒 A critical authentication and privilege-management vulnerability, tracked as CVE-2026-46817 (CVSS 9.8), affects Oracle Payments in E‑Business Suite versions 12.2.3 through 12.2.15 and has been observed under active exploitation. Patches were released in Oracle's last Critical Security Patch Update, but Defused Cyber reported exploitation against their honeypots and noted no prior public PoC. Details about the attack method, attribution, and campaign scope remain unknown, while experts urge rapid incident response and patching.