vulnerability Multiples vulnérabilités dans Oracle Weblogic (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle WebLogic, allowing an attacker to compromise data confidentiality and integrity. These vulnerabilities affect various WebLogic Server Proxy Plug-ins and the WebLogi… CERT-FR · Jul 23, 2026 High CVE-2025-68161CVE-2026-34477CVE-2026-34478oracleweblogicvulnerability
vulnerability Multiples vulnérabilités dans Oracle Java SE (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle Java SE, potentially allowing an attacker to cause a denial of service, compromise data confidentiality, and damage data integrity. These vulnerabilities affect var… CERT-FR · Jul 23, 2026 High CVE-2026-41254CVE-2026-46917CVE-2026-46968javavulnerabilitysecurity
threat-intel Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Oracle released a massive quarterly security update addressing over 1,400 vulnerabilities, primarily identified through the use of AI. The update includes fixes for a wide range of products and services, highlighting the… SecurityWeek · Jul 22, 2026 High patchvulnerabilityai
threat-intel Ransomware Is Accelerating, But It's Not Because of AI Ransomware activity is surging, with a 25% increase in incidents between April 2025 and March 2026, driven by a fragmented ecosystem and the emergence of numerous new groups. Black Kite researchers found that many victim… Dark Reading · Jul 21, 2026 High USEUransomwarevulnerabilitysupply-chain
data-breach Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Estée Lauder has been hit by a zero-day vulnerability in Oracle EBS, allowing the Cl0p cybercrime group to steal a massive amount of sensitive data, including personal information and payroll details. The breach, discove… SecurityWeek · Jul 21, 2026 High CVE-2025-61882zero-daydata breachremote code execution
threat-intel ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories This week’s security news is a mixed bag, encompassing a range of threats from sophisticated ransomware attacks to deceptive software distribution and widespread surveillance techniques. A new ransomware family, Spirals,… The Hacker News · Jul 16, 2026 High CVE-2026-46817CVE-2023-4346CVE-2026-35273NESPPOransomwareinfostealerbrandjacking
threat-intel 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers have discovered 11 outdated, Microsoft-signed UEFI shim bootloaders that could be exploited to bypass Secure Boot on systems relying on these shims. These bootloaders, primarily from versions 0.7 and earlier,… The Hacker News · Jul 14, 2026 High CVE-2026-8863CVE-2026-10797FIuefisecure bootvulnerability
threat-intel AI Data Centers and the Concentration of Wealth This article argues that focusing solely on opposition to AI data centers in the US is a misguided approach, as it obscures the larger issue of corporate AI dominance and the concentration of wealth within the industry.… Schneier on Security · Jul 13, 2026 High CHUNaidata centerscorporate power
threat-intel AI Surveillance and Social Progress This article explores the growing threat of AI-powered surveillance systems, particularly in China, and their potential to significantly erode personal freedoms and democratic progress. The author argues that these syste… Schneier on Security · Jul 10, 2026 High CHUSGEsurveillanceaifacial recognition
data-breach County Government Reportedly Paid $1 Million to Cyber Extortion Group A small county government in Ohio reportedly paid $1 million to the Kairos cyber extortion group to prevent the release of stolen data following a brute-force attack in May 2025. The attackers, Kairos, demanded $3 millio… SecurityWeek · Jul 7, 2026 High USdata breachransomwaregovernment
vulnerability New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure A newly discovered CitrixBleed-like vulnerability (CVE-2026-8451) in NetScaler ADC and Gateways was exploited within 24 hours of its public disclosure. The flaw, stemming from an out-of-bounds read issue in the XML parse… SecurityWeek · Jul 2, 2026 Critical CVE-2026-8451DEHKcitrixbleedsamlmemory disclosure
threat-intel Massive Password Spray Campaign Targeting Azure CLI A massive password spray campaign targeting Microsoft 365 environments, specifically the Azure CLI, was observed by Huntress. The attacks, originating from AS32167 and linked to LSHIY LLC, resulted in the compromise of o… SecurityWeek · Jul 1, 2026 High CHHOUScredential spraymfaoauth ropc
ransomware Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk Recent breaches targeting educational institutions, including ransomware attacks on Oracle E-Business Suite and Instructure's Canvas platform, highlight the vulnerability of the sector due to legacy technology, understaf… Dark Reading · Jun 27, 2026 High USthird-party riskransomwareeducation
threat-intel EdTech Attackers Shift From Schools to Their Software Suppliers This article reports a concerning shift in cyberattacks targeting the education sector, with attackers now focusing on edtech software suppliers like Instructure and Oracle rather than individual schools. The Shiny Hunte… Dark Reading · Jun 25, 2026 High edtechsupply chainransomware
data-breach FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. A significant data leak, dubbed "FortiBleed," has exposed approximately 73,932 Fortinet VPN credentials for firewall URLs across numerous organizations worldwide. The leak, discovered by Bob Diachenko, reveals a multi-op… BleepingComputer · Jun 17, 2026 High USGBJPvpncredentialsbreach
threat-intel ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More This week’s cybersecurity recap highlights several active exploits and attacks, including a Chrome 0-day being actively leveraged, a ShinyHunters gang exploiting a PeopleSoft zero-day for lateral movement and data exfilt… The Hacker News · Jun 15, 2026 High CVE-2026-11645CVE-2026-2441CVE-2026-3909UNCHzero-dayphishingsupply-chain
ransomware ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed A ShinyHunters ransomware group exploited a zero-day vulnerability in Oracle's PeopleSoft software suite to compromise over 300 instances across more than 100 organizations, primarily targeting higher education instituti… Dark Reading · Jun 12, 2026 High CVE-2026-35273USUKzero-daypeoplesoftransomware
vulnerability Ivanti Sentry Exploitation Attempts Hitting Honeypots A recently patched vulnerability in Ivanti Sentry, CVE-2026-10520, has been observed attempting exploitation on honeypots, according to Ivanti and CISA. The flaw allows for remote code execution with root privileges via… SecurityWeek · Jun 12, 2026 High CVE-2026-10520USvulnerabilitycommand injectionroot privilege
vulnerability ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities The ShinyHunters extortion group exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft to gain unauthorized access to university systems, resulting in data theft and a demand for payment. Mandiant iden… The Hacker News · Jun 11, 2026 High CVE-2026-35273GBUSzero-dayexploitationuniversity
vulnerability Oracle mitigates PeopleSoft zero-day exploited in data theft attacks A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools has been exploited by the ShinyHunters ransomware gang to steal data from numerous organizations. Oracle has released mitigations, but t… BleepingComputer · Jun 11, 2026 Critical CVE-2026-35273zero-daydata theftpeoplesoft