KDDI Corporation, one of Japan’s largest telecom companies, disclosed a data breach that exposed up to 14.2 million email accounts across six Japanese internet service providers.
The company detected the intrusion on June 17, quickly blocked the attackers, and launched an investigation. According to KDDI, the breach was caused by a vulnerability in third-party software used by its email system. The company is continuing its investigation while assessing the full impact of the incident.
“On June 17, 2026, we confirmed that some information from email services provided by various ISP operators (hereinafter referred to as “the email service”) may have been leaked to an external party in the email system (hereinafter referred to as “the System”) that we provide to Internet Service Providers (hereinafter referred to as “ISP operators”).” reads the data breach notice.
“On the same day, we modified the System to prevent further damage. We have identified the suspected location of the Unauthorized Access and implemented technical defense measures.”
Brian Higgins, Security Specialist at Comparitech had this to say:
“It looks like KDDI Corp are responding to this breach as best they can but the nature and volume of the compromised information is of considerable concern. Email is ubiquitous in modern communications so the available data points offer all manner of opportunities for malicious actors.
Unfortunately third party and supply chain attacks are far more likely to succeed as most organisations are fairly used to protecting core networks these days, but the interconnectivity required to operate means that access devolves to those less aware of the dangers or less able to resource the necessary security protocols.”
Paul Bischoff, Consumer Privacy Advocate at Comparitech follows with the:
“A big breach of email accounts and passwords like this is much more serious than most data breaches. Email accounts are often what we use to log into other accounts. We use email to verify new accounts, log in, change passwords, receive one-time codes, and recover other accounts. So a breach of an email account can lead to several more accounts being hijacked. Furthermore, cybercriminals can use hacked email accounts to spread scams, phishing, and spam. And of course, all of the information stored in your emails is at risk.”
We’ll have to see how this plays out. But I expect the usual pattern of phishing, spearfishing and other targeted attacks. Because I truly expect nothing less.
Attackers exploit critical Oracle E-Business vulnerabilitie
Posted in Commentary with tags Oracle on June 29, 2026 by itnerdThreat intel company Defused has reported that attackers are exploiting a critical vulnerability which is named CVE-2026-46817 in the Oracle E-Business Suite (EBS) financial application.
The vulnerability in the File Transmission component of EBS’s Oracle Payments product lets unauthenticated malicious actors with HTTP network access to take over vulnerable systems through low-complexity attacks.
Oracle released security updates to address the vulnerability in the May 2026 Critical Security Patch Update and urged that customers patch immediately. The vulnerability has no known previous exploitation or POC, according to Defused.
Sunil Gottumukkala, CEO of Averlon had this comment:
“This is an unauthenticated, low-complexity takeover of Oracle E-Business Suite, which runs many companies’ financials and payments, so the value to an attacker is obvious. EBS is already a known extortion target.
“Oracle shipped the patch in May, there is still no public proof-of-concept, yet attackers are already exploiting it, most likely by reverse-engineering the patch itself. A released fix can become the attacker’s roadmap, which is why the exposure window, the gap between when a patch ships and when it’s actually deployed, is where the real risk lives. Every day a critical vulnerability sits unpatched is another day inside that window.
“Organizations running EBS Payments on affected versions have no time to spare. Patch now, take the File Transmission component off the open internet, and hunt for compromise.”
Denis Calderone, CTO, Suzu Labs had this to say:
“The Cl0p campaign that exploited CVE-2025-61882 across more than a hundred Oracle EBS environments proved two things. First, that Oracle EBS is a target-rich environment full of financial, HR, and procurement data worth serious extortion money. And second, that a lot of organizations are running internet-exposed EBS instances and not patching fast enough. CVE-2026-46817 looks like what follows when that kind of spotlight gets put on a platform. Different actors, different component, but the same exposed attack surface. And this time, the target is Oracle Payments’ File Transmission module, the component that formats and transmits payment instructions, ACH batches, wire transfers, and EFT files directly to financial institutions.
“Some months back we all witnessed Cl0p’s Oracle EBS campaign hit over a hundred organizations using a sophisticated five-step exploit chain through BI Publisher that required SSRF, CRLF injection, path traversal, and malicious XSLT template processing just to get to code execution. That was a fairly sophisticated chained attack. CVE-2026-46817 looks far less complex, more like the front door was just left wide open. There is no authentication on the HTTP endpoint, and no complex exploit chain required. A crafted HTTP request gets you from zero access to full control of the system that formats and transmits ACH batches, wire transfers, and EFT files to financial institutions. Oracle EBS has a definite spotlight on its back. Now we have different actors picking different components, and we’d argue this is potentially much worse.
“The way the File Transmission component handles file operations can be exploited to execute arbitrary code on the server, and the attacker lands with enough privilege to take over Oracle Payments entirely. Oracle scored it a 9.8. File Transmission is the component that opens connections with banks and payment systems to send formatted payment instruction files. Full takeover of that system means potential access to read, modify, or redirect financial transactions.
“What’s got our attention is the exploitation timeline. There is no public proof-of-concept code for this vulnerability. Defused observed active exploitation on their Oracle EBS honeypots over the weekend. This probably means that someone reverse-engineered Oracle’s May patch, built a working exploit, and deployed it operationally in under six weeks. That tells you something about the caliber of actor going after this and how much value they see in owning a payment processing system.
“Oracle EBS is self-hosted, so the attack surface is entirely in your hands. If your Oracle Payments File Transmission endpoints are reachable over HTTP from untrusted network segments, restrict that access immediately to trusted internal sources only. Apply the May 2026 Critical Patch Update. The affected version range is 12.2.3 through 12.2.15, nearly identical to the Cl0p campaign’s target set. And given the six-week window between patch availability and confirmed exploitation, assume compromise and hunt for indicators of unauthorized access to your payment processing infrastructure going back to late May. If you’re running these versions, treat this as an emergency, not a quarterly maintenance item.”
Since organizations are in control, it is up to organizations to patch all the things. And I recommend that organizations do so before there is an attack that comes of this.
Leave a comment »