Weekly Cybersecurity Report | Week 27, 2026

As your dedicated cybersecurity services provider, CyberOne equips you with timely and in-depth information about current cyber attacks. Discover a weekly cybersecurity report of the latest exploits and breaches shaping the ever-evolving cybersecurity landscape.

Weekly Cybersecurity Report | Week 27, 2026

Information security updates and events from the past week

1.Active Exploitation of Oracle E-Business Suite (CVE-2026-46817)

The most critical vulnerability discovery this week involves the Oracle E-Business Suite (EBS).

  • The Flaw: Threat actors have been actively exploiting CVE-2026-46817, a critical vulnerability (CVSS score of 9.8) in the Oracle Payments “File Transmission” component.
  • Impact: The flaw allows an unauthenticated attacker with network access to achieve complete compromise of the Oracle Payments system, leading to full unauthorized access to sensitive financial data.
  • Remediation: The vulnerability affects versions 12.2.3 through 12.2.15. Organizations are urged to check their patch levels immediately. Live exploitation was detected by honeypot infrastructure as early as the weekend of June 27–28.

2. Fallout: PeopleSoft Data Exposure

Following a recent breach involving Oracle PeopleSoft, further details emerged this week regarding the scope of the impact.

  • Incident Status: As of June 29, the National Association of Insurance Commissioners (NAIC) confirmed that hackers have posted data stolen from PeopleSoft environments.
  • Consequences: Several ratings agencies have suspended data feeds from affected systems as a precautionary measure, highlighting the cascading impact when high-trust financial systems are breached.

3. Ongoing Supply Chain Monitoring (Klue/Salesforce)

While the initial Klue supply chain breach occurred earlier in June, the situation remained a top-tier security concern throughout this week.

  • The Danger: The breach involved the theft of OAuth tokens, which allowed attackers to impersonate authorized service accounts. Security teams are currently performing “Integration Audits” to identify if any malicious tokens remain active within their Salesforce or other CRM environments. This serves as a reminder to limit third-party integration permissions to the “least privilege” necessary.

4. Continued Surge in Regional Cyber Activity

Following reports earlier in the week of a sharp increase in cyberattacks against Israel (with 4,800 incidents recorded in June), security officials confirmed that the trend has persisted into early July.

  • Tactics: The activity includes not only traditional DDoS and data exfiltration but also sophisticated “digital propaganda” campaigns utilizing AI-generated content (such as deepfake videos) designed to cause psychological and social disruption.

5. Emerging Threat Class: AI-Driven EDR Evasion

Industry reports from the turn of the month have highlighted a new generation of “AI-built” ransomware toolkits.

  • Capabilities: These tools are being used to automate the evasion of Endpoint Detection and Response (EDR) systems and accelerate Active Directory discovery. This evolution marks a shift where AI is used not just to find vulnerabilities, but to autonomously navigate corporate networks once a foothold is established.

 

The cybersecurity attacks highlighted in this report aren’t just incidents, they’re blueprints of the adversary’s arsenal. To protect your business you need the right partner. CyberOne is here to help! Check out our services.