Oracle Security A.I CyberSecurity Scoring
Oracle Security
Company Information
Website:https://www.oracle.com/security/
Employees number:None
Number of followers:11,377
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:oracle.com
Oracle Security Risk Score (AI oriented)
Between 0 and 549
Oracle SecurityIT Services and IT Consulting
Updated:
10/07/2026
10/07/2026
517/1000
Critical
C
Oracle Security Global Score (TPRM)
xxxx
Oracle SecurityIT Services and IT Consulting
Score locked

Oracle SecurityCritical
Current Score
517C (CRITICAL)
01000
4 incidents
-67.33 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
522
JULY 2026
517
JUNE 2026
518
Vulnerability
16 Jun 2026 • Oracle Security
Mozilla and Oracle: Assume You Will Be Hacked
AI-Powered Cyberattacks Surge as Hackers Outpace Defenses
513
CRITICAL-5
ORAMOZ1781656969
AI-Powered Cyberattacks Surge as Hackers Outpace Defenses
In 2025, cyberattacks have escalated at an unprecedented rate, fueled by AI’s ability to automate and refine malicious software. Cybersecurity firm Palo Alto Networks reported a fourfold increase in daily attacks among its clients compared to 2024, with hackers leveraging AI to develop adaptive malware, accelerate data theft, and bypass traditional defenses. Former Yahoo and Facebook security chief Alex Stamos warned of a "crazy amount of offensive activity," noting that organizations including banks, hospitals, and government agencies are being breached daily.
The shift stems from AI’s dual role in both offense and defense. Advanced models like Anthropic’s Claude Mythos Preview and OpenAI’s GPT-5.5-Cyber have demonstrated near-human hacking capabilities, prompting their restricted release to select government and corporate partners. These tools have already uncovered thousands of long-standing vulnerabilities in open-source software, with Mozilla using Mythos to patch 400+ bugs in Firefox in April alone 20 times its typical monthly rate. Yet, despite these efforts, the window to respond to threats has collapsed: Moody’s Ratings found that attackers now exploit known vulnerabilities in just 44 days, down from over 700 days in 2020.
The threat landscape is further complicated by open-source AI hacking tools, which lower the barrier for less skilled criminals. The hacking group ShinyHunters, linked to AI-assisted attacks, recently disrupted Canvas (impacting thousands of schools) and breached Oracle’s HR system, potentially exposing data from over 100 organizations. Meanwhile, the U.S. government has restricted public access to Mythos, limiting its defensive applications.
Legacy systems and under-resourced sectors such as hospitals, utilities, and municipal agencies are particularly vulnerable. Many rely on outdated code written by retired or deceased developers, lacking the funds or expertise to modernize. Hospitals, already targeted by ransomware, face heightened risks as AI amplifies attacks. Experts warn of potential blackouts, banking disruptions, or large-scale data breaches in the coming years, with Anthropic estimating that a single attack on one of its partners could affect 100 million people.
While AI-driven security tools offer some defense, the pace of innovation has outstripped preparedness. Mozilla’s CTO, Raffi Krikorian, compared the urgency to Y2K-scale upgrades, but with months not years to act. As AI continues to evolve, the cycle of discovery and exploitation may persist, leaving organizations and individuals scrambling to adapt.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
524
Vulnerability
11 Jun 2026 • Oracle Security
ThemeREX, Joomla, Simple File List, WP File Manager, Oracle and DigitalOcean: Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
WP-SHELLSTORM Cybercrime Group's Exposed Server Reveals Mass Webshell Operation Targeting 1.4 Million Sites
517
CRITICAL-7
ORAJOOMANWPMDIGTHE1783693992
Cybercrime Crew’s Exposed Server Reveals Mass Webshell Operation Targeting 1.4 Million Sites
A cybercrime group, tracked as WP-SHELLSTORM, inadvertently exposed its operations for three weeks after leaving an unsecured server online. The incident, discovered by researchers at SOCRadar and Ctrl-Alt-Intel, provided an unprecedented look into a webshell access brokerage a scheme where attackers compromise websites en masse, install backdoors, and sell access to other criminals.
### The Exposure
On June 11, 2026, SOCRadar identified an unprotected server (IP: 137.175.93[.]126) hosting 800MB of data, including:
- Hacking tools (exploit scripts, webshells)
- Activity logs (command histories, scan results)
- Target lists naming 1.4 million websites (WordPress, Joomla, and others)
- Command-and-control (C2) configurations
The server, rented in the U.S., was left open due to a Python web server left running for 22 days a simple but costly oversight. Ctrl-Alt-Intel independently analyzed the same directory, publishing findings on June 22, before SOCRadar’s July 9 report.
### The Attack Method
The group exploited 27 known vulnerabilities, primarily in WordPress plugins, to deploy webshells small scripts granting remote control over compromised servers. Key flaws included:
- Breeze caching plugin (CVE-2026-3844) – Exploited against 45,000+ sites, successfully backdooring 17,000+ (only effective with a non-default setting enabled).
- Joomla JCE editor (CVE-2026-48907) – Targeted 560,000+ sites but only breached 77.
- Other WordPress plugins (e.g., ThemeREX Addons, Simple File List, WP File Manager).
The attackers used FOFA, a Chinese search engine for internet-connected systems, to build target lists. Their toolkit included:
- down.php – A heavily obfuscated webshell derived from BestShell (open-source Chinese malware).
- VShell – A stealthy backdoor disguised as a kernel process ([kworker/0:2]) to evade detection.
### Compromise Scale
While the 1.4 million figure represents targets, not breaches, researchers confirmed:
- Ctrl-Alt-Intel: 25,195 sites with evidence of compromise.
- SOCRadar: 5,700+ active webshells.
### Earlier Corporate Espionage Campaign
Before the WordPress spree, the same group ran a quieter operation in May 2026, targeting Java-based corporate systems via a Nacos configuration server flaw (CVE-2021-29441). They extracted:
- 613 configuration files from 11 systems across nine companies (fintech, e-commerce, logistics, gaming, electronics).
- Cloud credentials (AWS, Alibaba, Oracle, Tencent, DigitalOcean).
- Database passwords and Alipay RSA private keys.
SOCRadar suggests this was a "funding round" before scaling up the higher-volume webshell operation.
### Attribution & Sloppy Tradecraft
Researchers assess with medium-to-high confidence that the group is Chinese or Chinese-speaking, citing:
- Simplified Chinese in code and command logs.
- Use of FOFA (requiring a Chinese phone number for registration).
- Tools like Godzilla and VShell, common in Chinese-speaking cybercrime forums.
Despite a sophisticated toolchain, the group made basic errors:
- Left the server unprotected for weeks.
- Exposed a FOFA config file, traceable via law enforcement.
- Failed to sanitize command histories, revealing the full operation.
When alerted, the group deleted log entries between July 2–4, but the damage was already done.
### Broader Implications
WP-SHELLSTORM stands out not for its technical sophistication, but for its scale and opportunism. Using publicly known vulnerabilities and automated scanning, the group compromised thousands of sites without needing zero-days.
The incident mirrors a March 2026 exposure of Russia’s APT28 (Fancy Bear), where an open directory revealed phishing tools and logs. In both cases, human error not advanced hacking led to the unraveling of major cybercrime operations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
587
APRIL 2026
587
MARCH 2026
584
FEBRUARY 2026
580
JANUARY 2026
577
DECEMBER 2025
573
NOVEMBER 2025
570
OCTOBER 2025
755
Breach
19 Oct 2025 • Oracle Security
F5
Oracle E-Business Suite Remotely Exploitable Vulnerability (CVE-2025-61884)Microsoft Zero-Day Exploits (CVE-2025-24990, CVE-2025-59230, CVE-2025-47827)F5 Data Breach: Nation-State Attackers Stole BIG-IP Source CodeAdobe Experience Manager 'Perfect' Vulnerability (CVE-2025-54253)Microsoft Revokes 200 Certificates Used for Malicious Teams Installers (Vanilla Tempest Ransomware)Cisco Zero-Day Rootkit Deployment on Network Switches (CVE-2025-20352)U.S. Seizes $15B in Bitcoin Linked to Forced-Labor Crypto ScamUnitree G1 Humanoid Robot Bluetooth Vulnerability (Espionage Risk)Healthcare Cybersecurity Breakdown: 93% of U.S. Organizations Attacked (Patient Care Disruptions)
565
CRITICAL-190
F50032500101925
US tech company F5 confirmed a data breach in which nation-state attackers stole the source code and vulnerability information related to its BIG-IP family of networking and security products. BIG-IP is a critical infrastructure component used by enterprises for traffic management, load balancing, and security, making this breach particularly severe. The stolen data could enable adversaries to identify and exploit undiscovered flaws in BIG-IP systems, potentially leading to supply-chain attacks, unauthorized network access, or large-scale disruptions in organizations relying on F5’s solutions. The breach underscores the escalating risks of state-sponsored cyber espionage targeting foundational IT infrastructure, with implications for global cybersecurity resilience. F5 has not disclosed whether customer data was compromised, but the theft of proprietary code and vulnerability details poses a long-term threat to its product ecosystem and the broader digital supply chain.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
755
MAY 2025
755
Breach
01 May 2025 • Oracle Security
Fortinet, Samsung, Foxconn, Oracle and DHL: 74,000 Fortinet firewall credentials exposed in FortiBleed data leak
Russian Cybercriminal Group Exposes 74,000 Fortinet Firewall Credentials in Massive Leak
672
CRITICAL-83
SAMFOXORAFORDHL1781785487
Russian Cybercriminal Group Exposes 74,000 Fortinet Firewall Credentials in Massive Leak
A Russian-speaking cybercriminal group inadvertently exposed credentials from nearly 74,000 Fortinet firewalls and VPN gateways worldwide after leaving the data unsecured on a server. The breach, discovered by security researcher Volodymyr “Bob” Diachenko over the past weekend, was confirmed by other researchers, including Kevin Beaumont, who verified the authenticity of the leaked login details.
The compromised data, dubbed FortiBleed, includes configuration files containing sensitive information visible only from the devices themselves. The group obtained the credentials through automated large-scale harvesting, intercepting SSL VPN authentication hashes, cracking them using a 45-GPU cluster via Hashtopolis, and leveraging the passwords to infiltrate Active Directory environments. Researchers at Hudson Rock identified 73,932 unique firewall URLs across 194 countries, with many devices exposing their FortiGate Management Interface to the internet.
While Fortinet previously addressed password storage vulnerabilities in early 2025 by adopting PBKDF2 with randomized salt, many devices still use the older, weaker SHA-256 with salt method, making them susceptible to brute-force attacks. The leaked data appears to include both recently harvested credentials and older collections from prior breaches.
The breach impacts high-profile organizations, including Samsung, Siemens, Foxconn, Oracle, Accenture, DHL, Infosys, and Fortinet, as well as government agencies and critical infrastructure sectors. Notably, four organizations spanning Japan, Taiwan/Vietnam, Iraq, and Turkey were fully compromised, with a Turkish NATO defense contractor suffering exfiltration of classified defense documents.
Fortinet attributes the leak to exploited vulnerabilities and brute-force attacks, though the exact timeline of data collection remains unclear. Organizations using Fortinet devices are advised to assume compromise if their domains or IPs appear in the exposed dataset, requiring credential rotation, MFA enforcement, and system upgrades to mitigate further risks.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Oracle Security ??
What was Oracle Security's A.I Rankiteo Cyber Score in July 2026 ??
What was Oracle Security's A.I Rankiteo Cyber Score in June 2026 ??
What was Oracle Security's A.I Rankiteo Cyber Score in May 2026 ??
What was Oracle Security's A.I Rankiteo Cyber Score in April 2026 ??
What was Oracle Security's A.I Rankiteo Cyber Score in March 2026 ??
What was Oracle Security's A.I Rankiteo Cyber Score in February 2026 ??
What was Oracle Security's A.I Rankiteo Cyber Score in January 2026 ??
What was Oracle Security's A.I Rankiteo Cyber Score in December 2025 ??
What was Oracle Security's A.I Rankiteo Cyber Score in November 2025 ??
What was Oracle Security's A.I Rankiteo Cyber Score in October 2025 ??
What was Oracle Security's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Oracle Security's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Oracle Security ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Oracle Security's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?