August 26, 2026
- Oracle’s 1,449-patch bundle did not protect against CVE-2026-21962. The actively exploited flaw is an unauthenticated, low-complexity HTTP issue caused by improper access control. CISA confirms exploitation, and The Register explains the patch gap. (discussion)
· Vulnerabilities & Exploits
in Oracle WebLogic Is Under Active Attack
August 9, 2026
- Oracle has banned AI-generated code from OpenJDK, even as academia splits between journals that forbid AI in peer review and those now mandating it (Dealroom) (discussion).
· Industry & Policy
in AI Agents' Black Hat Reckoning Goes Public
August 7, 2026
- Attackers turned an Oracle SQL injection into Windows SYSTEM access using khunt, a database-resident post-exploitation toolkit. They fed Java source into Oracle, let the DB compile it into stored schema objects, and ran commands from inside the engine — dumping SAM/SECURITY/SYSTEM hives while most activity stayed buried in Apache logs rather than endpoint telemetry. The Hacker News, Huntress
· Offensive Techniques
in Meta Becomes the Fourth Lab to Admit Its AI Hacked a Stranger
August 3, 2026
- A public PoC is out for CVE-2026-60206, a CVSS 9.9 SAML authentication bypass in Oracle WebLogic. Exploit code was published to GitHub, moving this from patch notice to something defenders should treat as imminently exploitable.
· Vulnerabilities & Exploits
in God-Mode Access in N-able N-central Tops a Day of Fresh Exploits
July 21, 2026
in Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live
July 18, 2026
- Oracle E-Business Suite CVE-2026-46817 under active exploitation — CISA confirmed exploitation of the unauthenticated flaw in the Oracle Payments File Transmission component, with 1,000+ internet-exposed EBS instances tracked and a July 18 federal deadline (Daily Dark Web).
· Vulnerabilities & Exploits
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
July 17, 2026
in Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands
July 3, 2026
in Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire
June 30, 2026
- Oracle E-Business Suite CVE-2026-46817 (CVSS 9.8), an improper-privilege/auth flaw in Oracle Payments, is now being exploited in the wild per Defused, allowing instance takeover. The Hacker News, BleepingComputer
· Vulnerabilities & Exploits
- NAIC confirmed a breach by ShinyHunters via an Oracle PeopleSoft zero-day (group claims 3.1 TB stolen); Nissan disclosed an employee-data breach tied to the same PeopleSoft exploitation campaign. NAIC, Nissan
· Threat Activity
in Edge Appliances Bleed: watchTowr Drops Kemp LoadMaster Pre-Auth RCE as Oracle EBS Joins the Exploited List
June 28, 2026
- NAIC confirmed a cyberattack exploiting an Oracle PeopleSoft zero-day; ShinyHunters claims 3.1TB of data theft, though the organization disputes the scope. SC Media
· Breaches & Data Exposure
in A WHQL-Signed Kernel Backdoor Hides in a WFP Callout as a "Clean" GitHub Repo Pwns AI Coding Agents
June 18, 2026
- Oracle PeopleSoft CVE-2026-35273 unauthenticated RCE is under active exploitation by ShinyHunters (aka Bling Libra), with the education sector hit hardest since at least late May. Horizon3 confirmed exploitation predating disclosure, and Unit 42 corroborates the campaign against universities. watchTowr warns that "vibecoded" PoCs circulating are only the first-stage SSRF, not the full chain — treat public exploits skeptically (watchTowr).
· Vulnerabilities & Exploits
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel