Oracle Database Targeted by khunt Toolkit
Oracle Database was the target of an attack where attackers used SQL injection to load Java code into the database, achieving code…
Oracle Database was the target of an attack where attackers used SQL injection to load Java code into the database, achieving code…
Attackers breached an organization's Oracle database via a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit named…
khunt is a post-exploitation toolkit that runs inside Oracle databases by compiling Java source code into stored schema objects. It enables command…
Cybersecurity researchers have uncovered an active, multi-wave campaign that uses social engineering lures themed around Adobe and Zoom updates, business document reviews,…
An application server whose internal console was targeted by the attacker's scripts testing default credentials. No deployment was confirmed.
A critical Linux kernel vulnerability, tracked as CVE-2026-64600 and named RefluXFS, has been disclosed by Qualys. The flaw, present in Linux kernels…
Oracle E-Business Suite Improper Privilege Management Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security…
Cybersecurity researchers at ESET have discovered 11 old, Microsoft-signed UEFI shim bootloaders that could be exploited to bypass Secure Boot protections on…
Security researcher Chinmohan Nayak has detailed a WhatsApp-to-host attack chain leveraging three now-patched vulnerabilities in the OpenClaw personal AI assistant. The flaws,…
A critical security flaw in Oracle E-Business Suite, tracked as CVE-2026-46817 (CVSS 9.8), is now actively exploited in the wild. The vulnerability,…