Skip to content

Topic

Enterprise application security

Security of large business software suites such as ERP and commerce systems that hold core corporate data and processes.

Current clusters

security5 publishers

ShinyHunters slips past PeopleSoft firewall rules by encoding one character

ShinyHunters is again mass-exploiting Oracle PeopleSoft flaw CVE-2026-35273, defeating firewall rules by URL-encoding a single character. Anyone who filtered the endpoint instead of applying Oracle's June 10 patch should assume exposure.

Perspective Coverage

5 publishers
Builder
Builder 31%
Operator
Operator 57%
Investor
Investor 12%

Reality

Evidence78
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence75
security5 publishers

Three days from patch to probe: SAP Commerce Cloud RCE is already being hunted

CVE-2026-58231 is an unauthenticated, CVSS 10.0 code execution bug in Commerce Cloud's Data Hub Adapter. Defused says attempts hit its honeypots three days after patch day.

Perspective Coverage

5 publishers
Builder
Builder 26%
Operator
Operator 65%
Investor
Investor 9%

Reality

Evidence70
Adoption55
Hype gap+25
Incentives40
Confidence68