Oracle — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
121
occurrences
First Seen
October 23, 2025
Last Seen
August 27, 2026

Related Threat Clusters

Recent Intelligence Reports

  • Carhartt data breach exposes information of 12.9 million accounts — Bleepingcomputer · August 27, 2026
  • 89 — cwe.mitre.org · August 25, 2026
  • Attacks on Oracle Weblogic and HTTP Server observed — Heise.De · August 25, 2026
  • 004 — attack.mitre.org · August 20, 2026
  • 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency — Theregister · August 12, 2026
  • KHunt Toolkit Turns Oracle SQL Injection Into SYSTEM — Gbhackers · August 6, 2026
  • Oracle Linux 9 Thunderbird Important Security Advisory ELSA-2026 — Linuxsecurity · August 5, 2026
  • CVE-2026-69240 AKAOMA CVE VULNERABILITIES / 1h Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a string and starts with TO_TIMESTAMP or TO_DATE, escape returns val directly instead of replacing single quotes. An attacker can inject arbitrary SQL expressions through an app — cve.akaoma.com · August 4, 2026

CVSS v3.1 Breakdown