CuraSec

tag: Oracle-Ebs · 2 items

2026-07-21 · BleepingComputer · source ↗ #oracle-ebs#data-breach#erp
  • Engineer — Plan: If your org runs Oracle E-Business Suite (especially for HR), review Oracle’s recent security advisories for EBS patches and audit privileged access to HR data — no specific CVE or PoC is published yet, so active exploitation pressure is unclear.
  • SOC/IR — Learn: High-profile ERP-targeting breach with no published IOCs, TTPs, or attacker attribution to act on; file for context that Oracle EBS HR modules are being targeted, but there’s no detection work to do today.
  • Leader — Act: If your organization uses Oracle E-Business Suite, direct your team this week to confirm patch status and assess whether employee or customer PII is exposed via the same flaw; this breach will prompt customer and board questions if you operate in consumer goods or retail.
2026-07-16 · BleepingComputer · source ↗ #oracle-ebs#cisa-kev#active-exploitation
  • Engineer — Act: CISA KEV listing with confirmed active exploitation and an imminent Saturday deadline; audit your environment for Oracle E-Business Suite deployments and apply Oracle’s patch immediately.
  • SOC/IR — Act: Active exploitation is underway against Oracle EBS financial systems; initiate a hunt for anomalous EBS access patterns and monitor threat intel feeds for IOCs to sweep across relevant log sources.
  • Leader — Act: A CISA-mandated Saturday deadline on actively exploited financial software warrants same-week confirmation from your engineering team that Oracle E-Business Suite is either patched or absent from your environment.