Hackers now exploit critical Oracle E-Business flaw in attacks

Oracle E-Business Flaw Exploited by Hackers, Urgent Patching Recommended A critical vulnerability in Oracle’s E-Business Suite (EBS) financial application has been discovered to be actively exploited by hackers. According to threat intelligence company Defused, attackers are now using the flaw, tracked as CVE-2026-46817, to take over vulnerable systems with ease. For those unfamiliar, the Oracle … Read more

Critical SimpleHelp flaw exploited to deploy new stealer malware

Critical Vulnerability in SimpleHelp Platform Exploited to Deploy New Stealer Malware A critical vulnerability in the SimpleHelp platform has been exploited by hackers to deploy a new cross-platform information stealer known as Djinn Stealer. The vulnerability, identified as CVE-2026-48558, allows attackers to create highly privileged technician accounts without authentication, giving them full access to systems … Read more

NAIC says public data stolen in ShinyHunters’ PeopleSoft breach

A High-Profile Breach Exposes Public Data, Raises Questions About Hacker Claims The National Association of Insurance Commissioners (NAIC) has confirmed that its systems were breached by the notorious hacking group ShinyHunters. The attackers claimed to have stolen sensitive data from NAIC’s Oracle PeopleSoft server, but an investigation revealed that they only accessed publicly available information … Read more

Nissan discloses employee data breach linked to Oracle zero-day attacks

Nissan Discloses Employee Data Breach Linked to Widespread Oracle Exploits Automotive giant Nissan has revealed that it suffered a significant data breach affecting current and former employees, following a wave of attacks targeting Oracle PeopleSoft software. The breach is linked to exploits of a zero-day vulnerability in Oracle’s PeopleTools, which was used by threat actors … Read more

Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

A malicious Chrome extension, dubbed “Perplexity,” has been discovered intercepting search queries and address bar inputs from millions of users worldwide. The extension, which was available for download on the official Chrome Web Store, posed as a productivity tool that offered personalized recommendations and insights to users. But beneath its innocuous façade, Perplexity was secretly … Read more

Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

Indian government agencies and institutions are under attack from a notorious threat actor known as Mustang Panda, who is leveraging Zoho WorkDrive – a cloud-based file sharing and collaboration platform – as a command channel for its malicious activities. Mustang Panda has been a persistent threat in the region, with a history of targeting high-profile … Read more

WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private

A Major Breakthrough for WhatsApp Users: Introducing Usernames to Protect Phone Numbers from Hackers and Spammers For years, WhatsApp users have been vulnerable to identity theft and harassment due to the platform’s reliance on phone numbers as unique identifiers. However, a recent update has finally brought much-needed relief to millions of users worldwide. The messaging … Read more

Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input

A malicious Chrome extension, dubbed “Perplexity,” has been caught intercepting sensitive user input and search queries on popular browsers, including Google Chrome, Mozilla Firefox, and Microsoft Edge. The extension, which boasts over 200,000 users worldwide, was created to provide features such as website optimization and analytics insights but secretly siphoned off valuable information from unsuspecting … Read more