Aggregator
CVE-2022-37308 | OX Software OX App Suite up to 7.10.6 cross site scripting (EUVD-2022-39944)
CVE-2022-37309 | OX Software OX App Suite up to 7.10.6 cross site scripting (EUVD-2022-39945)
Apple Modifies Hide My Email Feature to Use Dedicated Domain
Apple intends to substantively diminish the efficacy of one of its most advantageous privacy mechanisms designed for premium iCloud subscribers. The technology giant will systematically transition masked email aliases to a distinct, dedicated domain....
The post Apple Modifies Hide My Email Feature to Use Dedicated Domain appeared first on Information Security News.
布局数字战场:美国网络司令部为JCWA构建云原生基座与数据动脉
供应商泄露上千万用户数据,甲方赔偿超2.3亿元
CVE-2026-6039 | LibreOffice up to 25.8.6/26.2.2 out-of-bounds write (Nessus ID 321128 / WID-SEC-2026-1929)
CVE-2026-10741 | Sonatype Nexus Repository Manager up to 3.92.x Configuration authorization (EUVD-2026-37783 / WID-SEC-2026-1987)
CVE-2026-20178 | Cisco Webex App redirect (cisco-sa-webex-app-redirect-KOyxhffH / WID-SEC-2026-1988)
Monero P2Pool Critical Vulnerability: Urgent V4.16 Update
Monero miners have received an urgent warning: a critical vulnerability discovered within P2Pool is currently being exploited in live attacks. Project developer sech1 reported this active exploitation on Reddit. He implored all network participants...
The post Monero P2Pool Critical Vulnerability: Urgent V4.16 Update appeared first on Information Security News.
从低权限 Key 到 AI Gateway 接管:LiteLLM 漏洞链完整剖析
Сверхновая взорвалась почти 70 лет назад. Её остаток должен был погаснуть. Он не погас — и теперь разгорается заново
Yakit 新功能:Edit Binary 让上传包里的不可见字符可控了
Silver Fox Trojan: China Cracks Down on Cybercrime Cells Across Five Provinces
Chinese police have dismantled several cybercrime cells tied to a new variant of the Silver Fox Trojan. The Ministry of Public Security’s cybersecurity bureau announced the crackdown this week, describing a malware operation that...
The post Silver Fox Trojan: China Cracks Down on Cybercrime Cells Across Five Provinces appeared first on Information Security News.
Oracle June 2026 Critical Security Patch Update Addresses 243 CVEs (CVE-2026-35273)
Oracle addresses 243 CVEs in its June 2026 Critical Security Patch Update with 245 patches, including 122 critical updates.
Key Takeaways- The June 2026 Critical Security Patch Update (CSPU) contains fixes for 243 unique CVEs in 245 security updates
- 122 issues (49.8% of all patches) were assigned a critical severity rating
- Oracle Fusion Middleware received the highest number of patches at 106, accounting for 43.3% of all patches
On June 16, Oracle released its Critical Security Patch Update (CSPU) for June 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 243 unique CVEs in 245 security updates across 11 Oracle product families. Out of the 245 security updates published, 49.8% of patches were assigned a critical severity. Critical severity patches accounted for the bulk of security patches at 49.8%, followed by high severity patches at 42.4%.
This month's update includes 122 critical patches across 122 CVEs.
SeverityIssues PatchedCVEsCritical122122High104102Medium1515Low44Total245243AnalysisThis month's update saw the Oracle Fusion Middleware product family contain the highest number of patches at 106, accounting for 43.3% of the total patches, followed by Oracle E-Business Suite at 55 patches, which accounted for 22.4% of the total patches.
A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.
Oracle Product FamilyNumber of PatchesRemote Exploit without AuthOracle Fusion Middleware10653Oracle E-Business Suite556Oracle JD Edwards2012Oracle Enterprise Manager166Oracle Siebel CRM127Oracle PeopleSoft117Oracle Virtualization100Oracle MySQL84Oracle Communications33Oracle Systems31Oracle Supply Chain11Oracle PeopleSoft zero-day exploitedOn June 10, Oracle published an out-of-band Security Alert Advisory for CVE-2026-35273, a remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools. On June 11, researchers at Google Threat Intelligence Group (GTIG) and Mandiant published a blog post confirming that CVE-2026-35273 was exploited in the wild as a zero-day by the extortion group ShinyHunters (UNC6240). The campaign, which affected over 100 global organizations, primarily impacted organizations within the United States, 68% of which were in the higher education sector. Organizations are advised to apply the available patches as soon as possible.
SolutionCustomers are advised to apply all relevant patches in this CSPU. Please refer to the June 2026 advisory for full details.
Identifying affected systemsA list of Tenable plugins to identify these vulnerabilities will appear here as they're released. This link uses a search filter to ensure that all matching plugin coverage will appear as it is released.
Get more information- Oracle Critical Security Patch Update Advisory - June 2026
- Oracle June 2026 Critical Security Patch Update Risk Matrices
- Oracle Advisory to CVE Map
Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.
Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
Steam Workshop Flaw Exploited to Distribute Malware via Wallpaper Engine
Even conventional digital distribution ecosystems can morph into potent vectors for infection when user-generated content is capable of executing arbitrary code. Malicious actors have recently exploited the Steam Workshop to proliferate malware disguised as...
The post Steam Workshop Flaw Exploited to Distribute Malware via Wallpaper Engine appeared first on Information Security News.
Microsoft Confirms RoguePlanet Zero-Day in Defender, Patch Under Development
SearchLeak: Microsoft 365 Copilot Flaw Let One Click Leak Enterprise Data
A single link to a trusted Microsoft domain could quietly turn Copilot into a data exfiltration tool. Varonis Threat Labs disclosed this flaw, naming it SearchLeak. The chain let an attacker steal emails, MFA...
The post SearchLeak: Microsoft 365 Copilot Flaw Let One Click Leak Enterprise Data appeared first on Information Security News.