Archive for June 29, 2026

Attackers exploit critical Oracle E-Business vulnerabilitie

Posted in Commentary with tags on June 29, 2026 by itnerd

Threat intel company Defused has reported that attackers are exploiting a critical vulnerability which is named CVE-2026-46817 in the Oracle E-Business Suite (EBS) financial application.

The vulnerability in the File Transmission component of EBS’s Oracle Payments product lets unauthenticated malicious actors with HTTP network access to take over vulnerable systems through low-complexity attacks.

Oracle released security updates to address the vulnerability in the May 2026 Critical Security Patch Update and urged that customers patch immediately. The vulnerability has no known previous exploitation or POC, according to Defused.

Sunil Gottumukkala, CEO of Averlon had this comment:

“This is an unauthenticated, low-complexity takeover of Oracle E-Business Suite, which runs many companies’ financials and payments, so the value to an attacker is obvious. EBS is already a known extortion target.

“Oracle shipped the patch in May, there is still no public proof-of-concept, yet attackers are already exploiting it, most likely by reverse-engineering the patch itself. A released fix can become the attacker’s roadmap, which is why the exposure window, the gap between when a patch ships and when it’s actually deployed, is where the real risk lives. Every day a critical vulnerability sits unpatched is another day inside that window.

“Organizations running EBS Payments on affected versions have no time to spare. Patch now, take the File Transmission component off the open internet, and hunt for compromise.”

Denis Calderone, CTO, Suzu Labs had this to say:

“The Cl0p campaign that exploited CVE-2025-61882 across more than a hundred Oracle EBS environments proved two things. First, that Oracle EBS is a target-rich environment full of financial, HR, and procurement data worth serious extortion money. And second, that a lot of organizations are running internet-exposed EBS instances and not patching fast enough. CVE-2026-46817 looks like what follows when that kind of spotlight gets put on a platform. Different actors, different component, but the same exposed attack surface. And this time, the target is Oracle Payments’ File Transmission module, the component that formats and transmits payment instructions, ACH batches, wire transfers, and EFT files directly to financial institutions.

“Some months back we all witnessed Cl0p’s Oracle EBS campaign hit over a hundred organizations using a sophisticated five-step exploit chain through BI Publisher that required SSRF, CRLF injection, path traversal, and malicious XSLT template processing just to get to code execution. That was a fairly sophisticated chained attack. CVE-2026-46817 looks far less complex, more like the front door was just left wide open. There is no authentication on the HTTP endpoint, and no complex exploit chain required. A crafted HTTP request gets you from zero access to full control of the system that formats and transmits ACH batches, wire transfers, and EFT files to financial institutions. Oracle EBS has a definite spotlight on its back. Now we have different actors picking different components, and we’d argue this is potentially much worse.

“The way the File Transmission component handles file operations can be exploited to execute arbitrary code on the server, and the attacker lands with enough privilege to take over Oracle Payments entirely. Oracle scored it a 9.8. File Transmission is the component that opens connections with banks and payment systems to send formatted payment instruction files. Full takeover of that system means potential access to read, modify, or redirect financial transactions.

“What’s got our attention is the exploitation timeline. There is no public proof-of-concept code for this vulnerability. Defused observed active exploitation on their Oracle EBS honeypots over the weekend. This probably means that someone reverse-engineered Oracle’s May patch, built a working exploit, and deployed it operationally in under six weeks. That tells you something about the caliber of actor going after this and how much value they see in owning a payment processing system.

“Oracle EBS is self-hosted, so the attack surface is entirely in your hands. If your Oracle Payments File Transmission endpoints are reachable over HTTP from untrusted network segments, restrict that access immediately to trusted internal sources only. Apply the May 2026 Critical Patch Update. The affected version range is 12.2.3 through 12.2.15, nearly identical to the Cl0p campaign’s target set. And given the six-week window between patch availability and confirmed exploitation, assume compromise and hunt for indicators of unauthorized access to your payment processing infrastructure going back to late May. If you’re running these versions, treat this as an emergency, not a quarterly maintenance item.”

Since organizations are in control, it is up to organizations to patch all the things. And I recommend that organizations do so before there is an attack that comes of this.

KDDI Email System Breach Exposes Up to 14.2 Million Credentials

Posted in Commentary with tags on June 29, 2026 by itnerd

KDDI Corporation, one of Japan’s largest telecom companies, disclosed a data breach that exposed up to 14.2 million email accounts across six Japanese internet service providers.

The company detected the intrusion on June 17, quickly blocked the attackers, and launched an investigation. According to KDDI, the breach was caused by a vulnerability in third-party software used by its email system. The company is continuing its investigation while assessing the full impact of the incident.

“On June 17, 2026, we confirmed that some information from email services provided by various ISP operators (hereinafter referred to as “the email service”) may have been leaked to an external party in the email system (hereinafter referred to as “the System”) that we provide to Internet Service Providers (hereinafter referred to as “ISP operators”).” reads the data breach notice.

“On the same day, we modified the System to prevent further damage. We have identified the suspected location of the Unauthorized Access and implemented technical defense measures.”

Brian Higgins, Security Specialist at Comparitech had this to say:

“It looks like KDDI Corp are responding to this breach as best they can but the nature and volume of the compromised information is of considerable concern. Email is ubiquitous in modern communications so the available data points offer all manner of opportunities for malicious actors. 

Unfortunately third party and supply chain attacks are far more likely to succeed as most organisations are fairly used to protecting core networks these days, but the interconnectivity required to operate means that access devolves to those less aware of the dangers or less able to resource the necessary security protocols.”

Paul Bischoff, Consumer Privacy Advocate at Comparitech follows with the: 

“A big breach of email accounts and passwords like this is much more serious than most data breaches. Email accounts are often what we use to log into other accounts. We use email to verify new accounts, log in, change passwords, receive one-time codes, and recover other accounts. So a breach of an email account can lead to several more accounts being hijacked. Furthermore, cybercriminals can use hacked email accounts to spread scams, phishing, and spam. And of course, all of the information stored in your emails is at risk.”

We’ll have to see how this plays out. But I expect the usual pattern of phishing, spearfishing and other targeted attacks. Because I truly expect nothing less.

MeetingTV lawsuit highlights growing risks around AI-assisted threat intelligence

Posted in Commentary with tags on June 29, 2026 by itnerd

The MeetingTV lawsuit highlights a difficult reality in cybersecurity: once a domain or service is flagged as malicious, that designation can quickly spread across dozens of security products and become incredibly hard to undo. Whether AI was involved or not, the case shows the need for security vendors to have clear processes for validating findings, correcting mistakes, and ensuring legitimate organizations aren’t caught in the fallout.

You can catch up here: MeetingTV lawsuit

Eljan Mahammadli, Head of AI Provenance, Polygraf AI

“What stands out to me here isn’t the hallucination accusation, because the filings don’t actually prove a model wrote that finding, and that uncertainty is the whole problem. When threat intelligence ships without a record of how each conclusion was reached, nobody can audit it afterward, not the researchers and definitely not the company on the receiving end. A bad attribution takes seconds to publish and spreads across hundreds of blocklists almost immediately, but reversing it takes months, if it happens at all. That asymmetry is what the industry should be worried about, whether or not AI touched the report. If we’re going to let models do attribution work, the output has to carry its own evidence chain, so a finding can be contested on the record instead of in court.”

Gidi Cohen, CEO & Co-founder, Bonfy.AI

“The MeetingTV lawsuit should be a wake-up call: when threat intelligence is generated or enriched by AI, the stakes are no longer just about technical accuracy—they’re about business continuity and reputational harm for real companies caught in the blast radius.

This case highlights three responsibilities that security leaders and researchers can’t ignore:

  • First, AI-assisted analysis does not change the obligation to validate findings with human judgment, especially when those findings can lead to long-term blocking of a legitimate service. “Protected speech” in research doesn’t absolve us from doing the hard work of verification.
  • Second, the industry needs a clearer accountability model for distributed threat intelligence. Once a label is published, it is replicated across hundreds of feeds and controls, yet there is still no standard process—or SLA—for correcting mistakes and propagating those fixes downstream.
  • Third, we have to treat false positives in AI-era threat intel as real incidents, not minor collateral damage. For a SaaS business, being silently tagged as malicious can have the same practical impact as a sustained DDoS or a major outage, and our governance models should reflect that.

Regardless of the legal outcome, the lesson is straightforward: if we use AI in security research, we must pair it with rigorous review, transparent methodology, and fast, industry-wide remediation when we get it wrong. Without that, AI doesn’t just help us find threats—it risks becoming one.”

Consider this a warning for organizations. Review everything that and AI does or end up in court. It truly is that simple when it come to either doing the review, or defending it in court.

Iranian cyberattacks on Israel have surged since war, Israeli cyber chief says

Posted in Commentary with tags , on June 29, 2026 by itnerd

Reuters is reporting that Iranian cyberattacks on Israel have surged since the war started, following a statement from the Israeli cyber chief. Yossi Karadi, Director General of Israel’s National Cyber Directorate, told German newspaper Die Welt that in June 2025, during Israeli military operations against Iran, Israel’s authorities registered around 1,600 hostile cyber incidents.  

Commenting on this news is SOCRadar CISO, Ensar Seker:

“An increase in cyber activity during periods of military conflict is expected, but what’s important isn’t just the number of incidents, it’s the shift in targeting and intent. During geopolitical crises, we typically see a broader mix of disruptive attacks, influence operations, espionage, and opportunistic campaigns occurring simultaneously. Many of these campaigns are designed to overwhelm defenders while creating strategic uncertainty rather than achieving a single technical objective

Organizations should also recognize that nation-state cyber campaigns rarely remain confined to government targets. Critical infrastructure, defense contractors, telecommunications providers, logistics companies, healthcare organizations, and multinational enterprises with regional operations often become indirect targets or collateral victims. Even organizations with no direct involvement in the conflict may experience increased phishing activity, credential theft attempts, DDoS attacks, or attacks against their supply chain.

Another notable trend is the growing integration of cyber operations with kinetic military activity. Cyberattacks increasingly support broader strategic objectives by disrupting communications, spreading disinformation, collecting intelligence, or distracting security teams before or during physical operations. This makes rapid detection, threat intelligence, and cross-sector information sharing more important than ever.

From a defensive perspective, organizations should assume that geopolitical events can rapidly change their threat profile. Security teams should strengthen identity security, closely monitor internet-facing assets, accelerate remediation of known exploited vulnerabilities, verify offline recovery capabilities, and continuously monitor for emerging indicators associated with regional threat actors rather than relying solely on traditional perimeter defenses.”

Previously, SOCRadar researchers have published an in-depth Iran-Israel Coflict Threat Landscape Report which can be read here: https://socradar.io/resources/report/iran-israel-conflict-threat-landscape-report/

Arcova Brings Proven End-to-End Data Center Solutions to Power-Constrained Growth

Posted in Commentary with tags on June 29, 2026 by itnerd

Arcova, today announced an end-to-end data center development offering that brings engineering, cybersecurity, regulatory compliance and grid-planning coordination under one accountable team. The offering is designed to take data center programs from site selection through day-two operations, reducing the average development timeline by 18 months and eliminating $60–200M in transition costs created by fragmented vendor coordination.

Data center demand driven by AI has created a structural gap between what developers need and what the grid can deliver. Grid interconnection adds three to four years to construction timelines, transformer and transmission equipment carry lead times of 66 to 120 months, and interconnection studies can consume up to 18-27 months when conducted manually. Each handoff between separate engineering, cybersecurity, regulatory and operations firms adds cost and delay at every seam.

Arcova addresses these constraints through three integrated capabilities, applied as one program:

  • Speed to power targets the primary bottleneck: energized capacity. Rather than sequencing interconnection permitting, behind-the-meter generation options and long-lead equipment procurement after construction decisions are made, Arcova runs those workstreams in parallel across its partner ecosystem. The result is an earlier, more defensible path to power for hyperscalers, utilities and the growing class of developers sourcing capacity through behind-the-meter supply.
  • Secure-by-design engineering embeds cybersecurity and regulatory compliance into the engineering phase from the start, aligned to ISA/IEC 62443, NERC CIP and applicable federal directives. Network segmentation, identity and access governance, secure remote access and monitoring are designed into reference architecture before construction begins. At commissioning, the asset carries documented evidence of security posture and compliance, making it more attractive to investors and easier to finance, sell and operate.
  • AI-accelerated grid planning compresses the interconnection study cycle — work that can run 18–27 months under manual methods. By modeling interconnection scenarios, transmission constraints, and grid-impact analysis at machine speed, Arcova gives developers higher-confidence answers earlier on where and how capacity can come online. These analytics are decision support for Arcova’s engineers and their clients: they accelerate expert work; they do not replace the certification rigor the engineering process enforces.

Together, these capabilities enable Arcova to orchestrate a single program from site identification through energization and certification. This replaces the serial handoffs among six to eight firms that often cause multi-year delays, while ensuring complete compliance documentation and a finance-ready asset at close. Arcova serves as the single point of accountability, drawing on partners such as Young Management & Consulting for construction management and program delivery.

The offering is available now and delivered on a per-program basis, with engagements scoped to each data center program’s size, stage and power strategy. For more information, visit arcova.com/data-centers/