Advertisement
Top

Tag: Oracle


Threats & Malware, Vulnerabilities

Alert: Active Exploitation of TP-Link, Apache, and Oracle Vulnerabilities Detected

May 2, 2023

Via: The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three flaws to the Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The security vulnerabilities are as follows – CVE-2023-1389 (CVSS score: 8.8) – TP-Link Archer AX-21 […]


Threats & Malware, Vulnerabilities

Oracle’s October 2021 CPU Includes 419 Security Patches

October 20, 2021

Via: Security Week

Just over half of the patches address vulnerabilities that could be exploited remotely without authentication, Oracle announced. Of the 419 new security patches in the October 2021 CPU, 36 deal with critical vulnerabilities, with one of them featuring a CVSS […]


Threats & Malware, Vulnerabilities

Oracle Warns of Critical Remotely Exploitable Weblogic Server Flaws

July 22, 2021

Via: The Hacker News

Oracle on Tuesday released its quarterly Critical Patch Update for July 2021 with 342 fixes spanning across multiple products, some of which could be exploited by a remote attacker to take control of an affected system. Chief among them is […]


Threats & Malware, Vulnerabilities

Oracle Delivers 390 Security Fixes With April 2021 CPU

April 21, 2021

Via: Security Week

The quarterly set of security patches addresses a total of 41 vulnerabilities considered critical severity, including 5 that feature a CVSS score of 10. The most severe of these vulnerabilities could be exploited to execute code remotely within the context […]


Cyber-crime, Malware

New Cryptojacking Malware Targeting Apache, Oracle, Redis Servers

February 1, 2021

Via: The Hacker News

A financially-motivated threat actor notorious for its cryptojacking attacks has leveraged a revised version of their malware to target cloud infrastructures using vulnerabilities in web server technologies, according to new research. Deployed by the China-based cybercrime group Rocke, the Pro-Ocean […]


Threats & Malware, Virus & Malware

New ModPipe Point of Sale (POS) Malware Targeting Restaurants, Hotels

November 12, 2020

Via: The Hacker News

Cybersecurity researchers today disclosed a new kind of modular backdoor that targets point-of-sale (POS) restaurant management software from Oracle in an attempt to pilfer sensitive payment information stored in the devices. The backdoor — dubbed “ModPipe” — impacts Oracle MICROS […]


Cyber warfare, Cyber-crime, Threats & Malware, Vulnerabilities

25 vulnerabilities exploited by Chinese state-sponsored hackers

October 21, 2020

Via: Help Net Security

The US Cybersecurity and Infrastructure Security Agency (CISA) has released a list of 25 vulnerabilities Chinese state-sponsored hackers have been recently scanning for or have exploited in attacks. “Most of the vulnerabilities […] can be exploited to gain initial access […]


Threats & Malware, Vulnerabilities

Oracle’s July 2020 CPU Includes 443 New Patches

July 15, 2020

Via: Security Week

This is a record-breaking CPU not only in terms of number of patches (the first to include over 400 fixes), but also in regard to the amount of critical flaws addressed: approximately 100 of the patches deal with vulnerabilities with […]


Cloud security, Security

What differentiates Oracle from other cloud providers when it comes to security?

January 16, 2020

Via: TechRadar

Cybersecurity is an important aspect and it becomes more precarious when organisations are flocking to the cloud to deploy mission-critical apps. Data is the new oil of the 21st century. The opportunity that the cloud presents also brings in challenges […]


Application security, Network security, Security

64% of IT decision makers have reported a breach in their ERP systems in the past 24 months

October 7, 2019

Via: Help Net Security

ERP applications are ‘critical’ to business operations, according to the IDC survey of 430 IT decision makers. ERP-related breach Sixty-four percent of the 191 decision makers surveyed whose organizations rely on SAP or Oracle E-Business Suite confirmed that their deployments […]


Cloud security, Security

Oracle Launches New Services to Secure the Cloud

September 17, 2019

Via: Security Week

The new services, Oracle Data Safe, Oracle Cloud Guard and Oracle Cloud Maximum Security Zones, deliver centralized security configuration and posture management capabilities, while also automating the enforcement of security practices. The new products operate in the background to gather […]


Vulnerabilities

Oracle Patches Another Remote Code Execution Flaw in WebLogic

June 19, 2019

Via: Security Week

The security hole, tracked as CVE-2019-2729 with a CVSS score of 9.8, impacts WebLogic versions 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. The flaw was independently reported to Oracle by nearly a dozen researchers. According to Oracle, the vulnerability exists due to a […]


Cyber-crime, Malware

New Echobot Botnet targets Oracle, VMware Apps and includes 26 Exploits

June 17, 2019

Via: Security Affairs

Recently a new botnet, tracked Echobot, appeared in the threat landscape its operators are adding new exploits to infect a broad range of systems, including IoT devices, enterprise apps Oracle WebLogic and VMware SD-Wan. The Echobot botnet was first detected […]


Vulnerabilities

Oracle Squashes 53 Critical Bugs in April Security Update

April 17, 2019

Via: Threat Post

Oracle is urging customers to patch critical vulnerabilities in its products as part of its massive April update, which fixes a whopping 297 flaws. Of those flaws, 53 vulnerabilities in Oracle products had a CVSS score of 9.0 or higher, […]


Vulnerabilities

Apple, Oracle, VMware Software Hacked at Pwn2Own 2019

March 21, 2019

Via: Security Week

Apple’s Safari web browser and the Oracle VirtualBox and VMware Workstation virtualization products were hacked on the first day of the Pwn2Own 2019 hacking competition, earning researchers a total of $240,000 in cash. Pwn2Own 2019, which takes place these days […]


Network security

Oracle Java SE 12 brings improvements to developer productivity

March 19, 2019

Via: Help Net Security

Oracle announced the general availability of Java SE 12 (JDK 12), continuing the six-month release cadence that provides enterprises and developers faster access to completed enhancements to the popular programming language. The release brings continued improvements to developer productivity, including […]


Cloud security

As Businesses Move Critical Data to Cloud, Security Risks Abound

February 21, 2019

Via: Dark Reading

Companies think their data is safer in the public cloud than in on-prem data centers, but the transition is driving security issues. More business-critical data is finding a new home in the public cloud, which 72% of organizations believe is […]


Vulnerabilities

Oracle: Apply Out-of-Band Patch for Database Flaw ASAP

August 15, 2018

Via: Dark Reading

Flaw in the Java VM component of Oracle’s Database Server is easily exploitable, security experts warn. Oracle this week urged organizations to immediately patch a critical vulnerability in multiple versions of Oracle database that gives attackers a way to completely […]


Vulnerabilities

Oracle Patches New Spectre, Meltdown Vulnerabilities

June 25, 2018

Via: Security Week

Oracle announced on Friday that it has started releasing software and microcode updates for products affected by the recently disclosed variants of the Spectre and Meltdown vulnerabilities. Intel, AMD, ARM, IBM, Microsoft and other major tech companies last month coordinated […]


Network security

Oracle Buys Zenedge for Cloud Security

February 15, 2018

Via: Dark Reading

Oracle announces its acquisition of Zenedge, which focuses on cloud-based network and infrastructure security. Oracle has agreed to buy Zenedge to ramp up security for its subscription-based cloud infrastructure services, the company announced today. Terms of the deal were not […]