✔️ #Metaprotec recomienda comprobar si tu infraestructura utiliza versiones afectadas del plugin LiteSpeed para cPanel, aplicar el parche correspondiente y monitorizar cualquier actividad con privilegios elevados en tus servidores.
#cPanel#Vulnerabilidad#PatchManagement
This week’s biggest cyber stories are about trusted business systems becoming fast-moving points of exposure. The roll-up connects university data theft, patch pressure, remote access attacks, AI tooling, backup risk, supply chain pressure, and major data exposure into one practical read.
🎓 Universities face data theft after Oracle PeopleSoft systems are hit
🛠️ Microsoft’s record-sized update puts summer patching under pressure
🌐 Check Point VPN attacks push remote access into emergency mode
⚡ Federal patching timelines are moving toward days instead of weeks
🤖 AI development tools and enterprise platforms are now part of the attack surface
💾 Backup systems, developer secrets, and SaaS tables remain high-value targets
💸 Data breaches and ransomware finance continue to drive legal and business risk
#Cybersecurity#InfoSec#CyberRisk#CISO#ThreatIntelligence#PatchManagement#Ransomware#CloudSecurity#AIsecurity#BareMetalCyber
Oracle has issued an out of band security alert for CVE-2026-35273, a zero day vulnerability affecting Oracle PeopleSoft PeopleTools that is reportedly being exploited in the wild.
The flaw is remotely exploitable without authentication and may allow remote code execution, creating significant risk for organizations running exposed PeopleSoft infrastructure. Reported activity has targeted PeopleSoft application components, including Environment Management Hub endpoints, with threat actors allegedly using old and zero day vulnerabilities to access systems, extract credentials, map connected nodes, and steal data.
Organizations using PeopleSoft should immediately review affected versions, validate exposure of PSEMHUB and PSIGW endpoints, apply available Oracle guidance, disable or remove Environment Management Hub where possible, block external access to vulnerable paths, and review logs for indicators of compromise.
PeopleSoft environments often support sensitive HR, student, financial, and business records, which makes rapid response critical.
#Cybersecurity#Oracle#PeopleSoft#CVE202635273#ZeroDay#VulnerabilityManagement#ThreatIntelligence#RemoteCodeExecution#PatchManagement#DataSecurity
CISA BOD 26-04 publiée mardi : 3 jours pour patcher les KEV critiques. Or seul 26 % des KEV ont été corrigées en 2025, délai médian 43 jours (DBIR 2026). Votre SLA actuel ?
#Cybersécurité#PME#PatchManagement#NIS2