View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Hackers post Oracle PeopleSoft breach data from US insurance body

🚨 ACTIVE EXPLOITS & INCIDENTS

  • Insurance Body Confirms Hackers Posted Oracle PeopleSoft Breach Data β€” Cybersecurity Dive The National Association of Insurance Commissioners (NAIC) confirmed data from an Oracle PeopleSoft breach was posted by threat actors. Some ratings agencies have suspended data feeds as a precaution, indicating active exploitation and potential downstream impact on insurance sector data integrity.
  • Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks β€” The Hacker News China-aligned Mustang Panda APT is actively targeting Indian government and hydropower sectors, leveraging Zoho WorkDrive as a covert C2 channel. New malware variants and compromised high-level administrative machines highlight a sophisticated supply chain abuse and espionage campaign.
  • Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input β€” The Hacker News / Microsoft Security Blog A malicious Chromium extension impersonating the AI search engine Perplexity silently logged all user search queries and address bar inputs, routing them through attacker-controlled servers before redirecting to legitimate results. Google removed the extension after Microsoft’s responsible disclosure, but affected users should audit browser extensions immediately.

πŸ”“ VULNERABILITIES & CVEs

πŸ“‹ VENDOR BULLETINS & ADVISORIES

  • Microsoft Extends Windows Server 2022 Hotpatching Until October 2027 β€” BleepingComputer Microsoft has extended hotpatching support for Windows Server 2022 by one year beyond mainstream support, until October 2027. Organizations relying on hotpatching for critical uptime should adjust maintenance plans accordingly to leverage this extended security update window.

πŸ•΅οΈ THREAT RESEARCH & DEEP DIVES

πŸ’Ό INDUSTRY NEWS, M&A & DEALS

  • Straiker Raises $64 Million for AI Security Platform β€” SecurityWeek Straiker secured $64M in funding to advance its AI security platform that identifies AI agents and monitors their access, behavior, and risk profiles. This investment signals growing market demand for AI governance and defense tools amid rising AI-driven attack surfaces.

πŸš€ PRODUCT LAUNCHES & UPDATES

  • WhatsApp Rolling Out Username Feature to Bolster Phone Number Privacy β€” SecurityWeek / BleepingComputer / The Hacker News WhatsApp has begun global rollout of an optional username system allowing users to mask phone numbers behind usernames for messaging. This privacy enhancement aims to reduce phone number exposure and associated risks such as SIM swapping and targeted phishing.

πŸ“° LESSER-KNOWN / UNDER-REPORTED

  • U.S. Offers $10 Million for Hackers Targeting WhatsApp, Signal Users β€” BleepingComputer The U.S. Department of State announced rewards up to $10M for information on UNC5792 and UNC4221 hacker groups linked to Russian intelligence, who target encrypted messaging users. This highlights ongoing geopolitical cyber espionage efforts against secure communication platforms.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check