LIVE · cybersecurity feed
Live wire
Australia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning RepairCISA’s logging guidance works beyond government
patch

You could've applied all 1,449 Oracle patches and still been hit by this attack

Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert

zeroday.news ·

A recent credential theft incident targeting an Oracle database server would not have been prevented by any of the 1,449 patches Oracle released in late July, according to cybersecurity firm Huntress. The attack highlights a shift in threat actor tactics toward exploiting system functionality rather than solely identifying vulnerabilities.

The incident began with a SQL injection against an unnamed organization's public-facing web application. While SQL injection is a well-known vulnerability, the subsequent actions taken by the threat actor were described as novel.

After gaining initial access, the attackers deployed a post-exploitation toolkit named "khunt." This toolkit was introduced into the Oracle database via a Java Source object, a technique rarely documented in real-world attacks. Oracle databases include an embedded Java Virtual Machine (JVM), allowing users to store Java source code as a database object.

In this specific attack, the threat actors utilized `CREATE JAVA SOURCE` commands. These commands were fed to the Oracle database from a Tomcat server through the existing database connection. The embedded Java source code was then compiled directly within the database as a stored schema object.

This method allowed the malicious toolkit to reside directly within the database engine. The technique, sometimes referred to as "oraexec," has been discussed conceptually in security circles for years, but its practical application in an actual attack has been infrequently observed.

A cybersecurity lead at Spinnaker Support, a third-party Oracle support vendor, confirmed that even a fully patched Oracle system would have been susceptible to this particular attack, emphasizing that the issue was not a missing patch but rather the exploitation of inherent system functionality.

The incident underscores a growing trend where attackers leverage legitimate features and operational mechanisms of software to achieve their objectives, rather than relying solely on traditional vulnerabilities that can be addressed through patching.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Water sector passes, government sector fails attempts to spot and halt simulated CISA attack

Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further. The post Water sector passes, government sector fails attempts to spot and halt simulated CISA attack appeared first on CyberScoop.

ai

When the Algorithm Fires You: Uber Faces €825M Fine

Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator imposed an 825 million euro penalty, roughly $964 million, over […]

ai

Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek.

ddos

Massive DDoS attack disrupts Norway’s government digital services

A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]

breach

Hospital operator Nutex Health says data stolen in cyberattack

Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]

phishing

ZeroTokens Phishing Platform Steers Attacks in Real Time

ZeroTokens gives phishing operators live control of victim sessions targeting 53 financial brands