Largest-ever Oracle Critical Patch Update with 1,235 CVEs in 1,449 security updates. E-Business Suite received 410 patches (28.3% of total) with 261 critical severity. 663 vulnerabilities are remotely exploitable without credentials.
Apply July 2026 CPU immediately, prioritizing Oracle E-Business Suite versions impacted by 410 new fixes. Focus on internet-facing Oracle Fusion Middleware and Communications systems first. Test in staging before production deployment.
Source: MSRC • Published: 2026-07-21
Over 40 CVEs disclosed against MCP implementations between January-April 2026. Command injection affects 43% of tested servers, path traversal affects 82% of 2,614 implementations, SSRF affects 36.7% of 7,000+ servers. CVE-2025-6514 (mcp-remote) has CVSS 9.6 OS command injection with 437,000+ downloads.
Implement policy validation of MCP tool metadata before ingestion. Review workspace trust model configurations for Amazon Q and IDE extensions. Disable automatic MCP server loading from untrusted repositories. Audit all MCP server configurations for command injection vulnerabilities.
Source: Web • Published: 2026-04-30
North Korean APT Sapphire Sleet (BlueNoroff/APT38) compromised stolen developer account and republished 140+ packages in @mastra scope within 19 minutes. First confirmed nation-state mass npm supply chain attack targeting AI agent frameworks.
Implement package signature verification immediately. Use dependency pinning for all AI framework dependencies. Monitor for unexpected package updates. Apply AI coding assistant output validation. Review and remove compromised @mastra packages. Rotate npm credentials.
Source: Web • Published: 2026-06-17
Chinese APT Salt Typhoon compromised 200+ organizations across 80 countries including 8+ U.S. telecom providers (FBI, Verizon, AT&T, Lumen). FBI confirmed threats remain active and ongoing as of February 2026. Over 1 million people's metadata compromised. Pre-positioned access for potential infrastructure disruption.
Implement zero-trust architecture immediately. Segment OT/IT networks. Deploy EDR with behavioral analytics. Monitor for living-off-the-land techniques. Review authentication logs for unusual patterns. Conduct comprehensive network forensics. Harden telecom infrastructure per CISA guidance.
Source: CISA • Published: 2026-02-15
Chinese APT Volt Typhoon maintained persistent access inside U.S. critical infrastructure for at least five years. Intelligence community assesses targeting is preparation to disrupt U.S. infrastructure rather than espionage. Confirmed dormant presence in power grids, water systems, and telecommunications.
Deploy comprehensive network monitoring for critical infrastructure. Implement air-gapped OT environments where possible. Review all authentication systems for unauthorized access. Deploy behavioral analytics for anomaly detection. Segment critical systems. Follow CISA AA24-038A mitigation guidance.
Source: CISA • Published: 2024-02-07
Iranian-affiliated APT targeting U.S. critical infrastructure PLCs, escalating in response to U.S.-Israel-Iran hostilities. Attackers download malicious project files to PLCs using configuration software, adding logic that overrides safety parameters while retaining normal downstream function. Updated advisory July 22, 2026 adds detection guidance for malicious reusable code modules.
Segment ICS/SCADA networks immediately. Implement application whitelisting on engineering workstations. Monitor for unauthorized PLC configuration changes. Deploy integrity monitoring for ladder logic. Review all PLC project files for malicious modifications. Implement change control for PLC programming.
Source: CISA • Published: 2026-07-22
Oracle-CPU-July-2026: Largest-ever Oracle Critical Patch Update with 1,235 CVEs in 1,449 security updates. E-Business Suite received 410 patches (28.3% of total) with 261 critical severity. 663 vulnerabilities are remotely exploitable without credentials.