incident-report
-
CVE-2026-21962: The Oracle WebLogic Flaw That Was Exploited for Seven Months Before Anyone Noticed
CISA added a maximum-severity Oracle WebLogic and HTTP Server flaw to its Known Exploited Vulnerabilities catalogue on August 24, with a three-day federal remediation deadline -- but Oracle patched the bug back in January, and a China-linked threat actor has reportedly been exploiting it against government infrastructure since then. For CISOs, the real story is not the CVE. It is why a patched, unauthenticated, CVSS 10 vulnerability sat unremediated for seven months.
incident-report -
Medusa Ransomware Passes 500 Critical Infrastructure Victims: What the New Federal Advisory Means for Your Board
CISA, the FBI, and HHS jointly updated their Medusa ransomware advisory on August 18-19, reporting the group has now hit over 500 critical infrastructure organizations since 2021, up from 300 in March 2025. This briefing covers what changed, why healthcare is bearing the brunt, and the governance actions CISOs should take this quarter.
incident-report -
Oracle EBS CVE-2026-46817: When the Finance System Itself Becomes the Attack Vector
CISA added CVE-2026-46817 to the Known Exploited Vulnerabilities catalogue on July 15 with a 72-hour federal deadline -- the tightest ever imposed on an Oracle ERP vulnerability. For CISOs with Oracle E-Business Suite deployments, this is a board-level risk requiring immediate escalation.
incident-report -
Oracle PeopleSoft Zero-Day: What the ShinyHunters Breach Means for Enterprise ERP Risk
ShinyHunters exploited a critical Oracle PeopleSoft vulnerability for 14 days before Oracle published any patch — breaching 100+ organisations including major universities. This briefing covers what happened, the systemic ERP risk it reveals, and the governance questions boards should be asking.
incident-report -
Nightmare-Eclipse: What the Windows Zero-Day Campaign Means for Your Board
Six actively exploited Windows vulnerabilities, three confirmed in live attacks, and a credible remote-code-execution threat arriving in June. A plain-English board briefing for security leaders.
incident-report