< ciso
brief />
Tag Banner

All news with #oracle tag

92 articles

Amazon RDS for Oracle Adds APEX 26.1 Support

🔔 Amazon RDS for Oracle now supports Oracle Application Express (APEX) 26.1, a low-code platform for building secure, scalable enterprise applications. This managed database service simplifies setup, operation, and scaling of Oracle Database deployments in the cloud. APEX 26.1 is available in all AWS regions where RDS for Oracle is offered; consult the RDS documentation for details on enabling or modifying APEX options.
read more →

Oracle launches Database Security Central free trial

🔒 Oracle has introduced Database Security Central, a tool that provides a centralized view of security risk across database environments and will be free through February 2027. It arrives as attackers increasingly target Oracle database flaws and following Oracle’s move to monthly patch releases. The tool assesses posture, detects configuration drift, highlights privileged access risks, monitors sensitive data access, and centralizes policy management and audit evidence collection.
read more →

Post‑exploitation toolkit embedded inside Oracle DB

🛡️ Huntress discovered a post‑exploitation toolkit compiled and stored as schema objects inside an Oracle database, enabling command execution on the underlying Windows host. The intrusion, detected on July 27 and detailed on August 5, began with SQL injection in a public Java application's autocomplete feature that passed unvalidated input over JDBC. Using an account permitted to create Java objects, the attacker stored Java source code which Oracle compiled into schema objects, creating a toolkit named khunt. Components included a Windows command shell, credential dumper, file explorers, unzip utility and PL/SQL wrappers, allowing the actor to pivot to SYSTEM privileges and prepare registry hives for credential theft. Huntress highlighted detection gaps because endpoint tools typically do not inspect Java classes and PL/SQL objects inside databases, turning the DB into an operational foothold; they recommended input sanitization, parameterized queries and least‑privilege for query‑capable accounts.
read more →

Attackers hide Java malware inside Oracle databases

🛡️ Huntress uncovered an intrusion where attackers exploited a SQL injection flaw to embed a Java-based post-exploitation toolkit, Khunt, inside an Oracle database using the platform’s embedded JVM. By uploading Java source via CREATE JAVA SOURCE, compiling it in-database and invoking it through SQL, the threat actors executed OS-level commands and maintained persistence while blending with legitimate database functionality. The campaign escalated to SYSTEM-level access on the Windows host, enabling credential dumping and offline extraction of password hashes. Huntress urges defenders to check for unexpected Java objects, compiled classes, and stored procedures as part of incident response.
read more →

Oracle July 2026 Critical Patch Update Overview

🛡️ Oracle’s July 2026 Critical Patch Update is its largest ever, delivering 1,449 fixes across 32 product families, including Database, Fusion Middleware, Java SE, and GoldenGate. Fusion Middleware saw 355 vulnerabilities, 219 exploitable remotely without authentication, and ten scored a CVSS 10.0. Database Server received critical fixes including CVE-2026-61211 (CVSS 9.9) in DBMS_CLOUD and an Oracle Net Services flaw, with additional OpenSSL-related patches. Experts urge rapid triage based on exposure and business impact as the sheer volume outpaces typical patching workflows.
read more →

Estée Lauder discloses Oracle E‑Business Suite breach

🛡️ Estée Lauder is notifying individuals after discovering that an unauthorized actor accessed its Oracle E-Business Suite HR system on or around August 9, 2025, exposing personal information. The company's investigation concluded on June 19, 2026, and the exposed data may include names, contact details, SSNs, passport numbers, bank account and health information. The breach correlates with mass exploitation tied to CVE-2025-61882 and activity by the Clop group; affected individuals are being offered 24 months of identity monitoring through Kroll.
read more →

CISA orders federal patching for exploited Oracle EBS flaw

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch systems by Saturday to mitigate active exploitation of a critical Oracle E-Business Suite vulnerability, tracked as CVE-2026-46817. The flaw in the Oracle Payments File Transmission component allows unauthenticated HTTP access leading to system takeover in low-complexity attacks. Oracle issued fixes in its May 2026 Critical Security Patch Update and urged immediate patching, while security firms and CISA have observed active exploitation. Shadowserver reports over 1,000 Internet-exposed Oracle EBS instances, many in the U.S., prompting CISA to add the flaw to its list of known exploited vulnerabilities and mandate remediation under BOD 26-04.
read more →

Amazon RDS adds support for Oracle Database 26ai

🚀 Amazon RDS for Oracle now supports Oracle Database 26ai, Oracle's Long Term Support release, with integration to Amazon Bedrock providing access to foundation models such as Anthropic Claude, Amazon Nova, and Meta Llama. Oracle Database 26ai enables Select AI for generating and running SQL from natural language prompts and supports in-database RAG via Oracle AI Vector Search, avoiding the need for a separate vector store. The release also offers JSON Relational Duality Views and SQL Property Graphs and is available in Enterprise Edition across commercial and GovCloud regions.
read more →

Over 900 Oracle E-Business instances exposed online

🔒 Over 900 Oracle E-Business Suite (EBS) instances were found exposed online amid active attacks exploiting a critical File Transmission flaw in Oracle Payments (CVE-2026-46817). The vulnerability permits unauthenticated HTTP takeover, and Oracle released patches in its May 2026 Critical Security Patch Update, urging immediate remediation. Threat intelligence firm Defused reported active exploitation observed on honeypots, while Shadowserver noted roughly 950 exposed instances and the extent of patching remains unclear.
read more →

Critical Oracle E‑Business Suite Flaw Actively Exploited

🔒 A critical authentication and privilege-management vulnerability, tracked as CVE-2026-46817 (CVSS 9.8), affects Oracle Payments in E‑Business Suite versions 12.2.3 through 12.2.15 and has been observed under active exploitation. Patches were released in Oracle's last Critical Security Patch Update, but Defused Cyber reported exploitation against their honeypots and noted no prior public PoC. Details about the attack method, attribution, and campaign scope remain unknown, while experts urge rapid incident response and patching.
read more →

Nissan reports employee data breach after PeopleSoft zero-day

🔒 Nissan has disclosed a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability tied to a wider campaign. The automaker says the incident may have exposed contact, financial, tax, and identification details and impacts employees in the US, Canada, Mexico, and Brazil. Nissan has engaged external cybersecurity experts, restricted certain payroll functions, and will offer monitoring services to affected individuals while working with Oracle on remediation.
read more →

NAIC Confirms PeopleSoft Breach Exposes Credit Data

🔒 The US National Association of Insurance Commissioners (NAIC) disclosed a security breach detected on June 11 and revealed on June 17 that an unauthorized actor exploited a zero-day in Oracle PeopleSoft to access parts of its environment. The attacker obtained and published some statutory financial reporting and credit rating agency data, and possibly routine technical files. NAIC says personal, payment, and several regulatory system records were not compromised and operations are largely restored.
read more →

AWS launches EC2 U7in-24TB in Seoul region

🚀 Amazon EC2 High Memory U7in-24TB instances (u7in-24tb.224xlarge) are now available in the AWS Asia Pacific (Seoul) region. These 7th-generation U7i instances use custom Intel Sapphire Rapids CPUs and provide 24 TiB of DDR5 memory, 896 vCPUs, up to 200 Gbps network, and 100 Gbps EBS bandwidth to accelerate in-memory workloads. U7i offers up to 45% better price performance over prior U-1 instances and is suited for mission-critical databases like SAP HANA, Oracle, and SQL Server.
read more →

Oracle issues 245 high-priority security fixes

🔒 Oracle released a Critical Security Patch update containing 245 fixes for supported on-premises products, including Enterprise Manager, JD Edwards, Fusion Middleware, MySQL and PeopleSoft. The update provides targeted, high-priority fixes outside the quarterly cadence to reduce disruption and speed remediation. Several patches address remote, unauthenticated exploits—most notably in WebLogic Server, Oracle Coherence and PeopleSoft—some of which are already actively exploited or present immediate risk. Vendors and analysts warn that the scale and placement of these flaws, especially in Fusion Middleware components nearing end of support, create significant control-plane and pivot risks.
read more →

Oracle Autonomous AI Database Serverless on AWS

🛠️ Oracle Autonomous AI Database Serverless (ADB-S) is now available on Oracle Database@AWS through AWS Marketplace with Bring Your Own License and License Included options. ADB-S runs on Exadata infrastructure as a fully managed service that automates patching, tuning, scaling, backups, and high availability. It supports four workload types—AI Transaction Processing, AI Lakehouse, AI JSON Database, and Oracle APEX—with independent compute and storage scaling. Integrations include AWS KMS for encryption, Amazon CloudWatch for monitoring, and Amazon EventBridge for events.
read more →

Amazon EC2 U7i-8TB high memory instances in Paris

🔥 Amazon EC2 High Memory U7i-8TB instances (u7i-8tb.112xlarge) are now available in the AWS Europe (Paris) region. These 7th-generation U7i instances are powered by custom 4th-generation Intel Xeon Scalable (Sapphire Rapids) processors and provide 8 TiB of DDR5 memory for scaling transaction processing throughput. They deliver 448 vCPUs, up to 100 Gbps EBS and network bandwidth, ENA Express, and up to 45% better price performance versus U-1 instances. U7i instances are targeted at mission-critical in-memory databases such as SAP HANA, Oracle, and SQL Server.
read more →

ShinyHunters exploited Oracle PeopleSoft zero‑day

🔒 The ShinyHunters extortion group exploited an unpatched Oracle PeopleSoft remote code execution zero‑day (CVE-2026-35273) to compromise enterprise servers, steal data, and extort victims. Mandiant links the activity to UNC6240 and observed attacks from May 27 to June 9, before Oracle published its advisory on June 10. The flaw requires no authentication and exposes PeopleTools 8.61 and 8.62 installations with externally reachable Environment Management Hub endpoints. Universities were heavily targeted; mitigations focus on disabling or blocking PSEMHUB and hunting for post‑exploit indicators.
read more →

Oracle mitigates PeopleSoft zero-day used in data theft

🔔 Oracle warns of a critical PeopleSoft Suite zero-day, CVE-2026-35273, enabling unauthenticated remote code execution and carrying a CVSS 9.8 score. The flaw impacts PeopleSoft PeopleTools versions 8.61 and 8.62; Oracle released emergency mitigations and plans a patch. Threat actor ShinyHunters is linked to active exploitation and large-scale data theft across hundreds of instances. Administrators are urged to review logs and block identified IPs to assess compromise.
read more →

ShinyHunters Target Oracle PeopleSoft Instances

🛡️ ShinyHunters are actively stealing data from Oracle PeopleSoft instances, claiming breaches across 300 instances at over 100 organizations. The actor says they used a mix of old and zero-day vulnerabilities in a "gadget chain," with many victims in the education sector. Exposed tooling, scripts, and IOCs were found in online directories, and impacted organizations are urged to check logs and begin incident response immediately.
read more →

Two-year-old Oracle WebLogic flaw now actively exploited

🔒 US federal agencies were ordered to patch a two-year-old high-severity Oracle WebLogic Server vulnerability, CVE-2024-21182, after its addition to CISA’s Known Exploited Vulnerabilities catalog. The flaw affects supported versions 12.2.1.4.0 and 14.1.1.0.0 and was patched by Oracle in the July 2024 CPU. Security experts note that inclusion in the KEV indicates active weaponization and highlight persistent slow patching across organizations as a key risk.
read more →