Oracle EBS Exploitation and DriveSurge Campaign Active in the Wild

Oracle EBS Exploitation and DriveSurge Campaign Active in the Wild

•

Episode description

Oracle EBS Exploitation and DriveSurge Campaign Active in the Wild

Oracle E-Business Suite vulnerability CVE-2026-46817 is under active exploitation, with confirmed activity from threat intelligence firm Defused. Nissan’s recent breach of its Oracle PeopleSoft instance underscores the broader risk to Oracle’s enterprise portfolio. UK small businesses face exposure through supply chain relationships with payroll bureaus, accountancy firms, and manufacturers running Oracle systems. Meanwhile, newly documented threat actor DriveSurge operates a pay-per-install initial access broker model, compromising legitimate websites to deliver malware through fake browser updates and ClickFix social engineering. The campaign bypasses email security controls entirely, infecting users through normal web browsing. Additional concerns include active exploitation of Langflow (CVE-2026-55255) and the Miasma Mini Shai-Hulud supply chain campaign now targeting Backstage npm packages. Today’s briefing provides specific, actionable steps: verify Oracle patch status with suppliers, implement web filtering against zTDS infrastructure, brief staff on fake browser update prompts, and audit dependencies in development pipelines. These are email-and-call actions, not budget-heavy projects.

Chapters

  • Introduction Mauven opens with two active threat stories: exploitation of Oracle E-Business Suite and a drive-by attack campaign bypassing email controls through compromised websites. Both pose immediate risks to UK small businesses through supply chain and web browsing vectors.
  • Oracle EBS Active Exploitation CVE-2026-46817 in Oracle E-Business Suite is under confirmed exploitation. Nissan’s PeopleSoft breach demonstrates sustained threat actor attention to Oracle’s enterprise platforms. UK small businesses face exposure through payroll bureaus, accountancy firms, and manufacturers. Practical steps include verifying patch status directly with suppliers and documenting responses in writing.
  • Mid-Roll Call to Action Brief listener prompt to follow the show and share the briefing with relevant contacts.
  • DriveSurge Drive-By Campaign DriveSurge, a newly documented initial access broker, compromises legitimate websites to deliver malware via fake browser updates and ClickFix prompts. The campaign uses zTDS traffic distribution and bypasses standard email security. Recommended defences include web filtering against zTDS infrastructure and staff briefing on fake update prompts.
  • Langflow and Miasma Mini Shai-Hulud Updates CVE-2026-55255 in Langflow is under active exploitation, with lower-scored CVE-2026-33017 seeing wider use due to easier exploitation. The Miasma Mini Shai-Hulud campaign now targets Backstage npm packages. Organisations using AI frameworks or modern CI/CD pipelines should audit patch status and dependencies.
  • Closing Summary Mauven summarises practical actions in order of urgency: verify Oracle patch status with suppliers, brief staff on fake browser updates, confirm web filtering covers zTDS, and audit development dependencies. All actions require communication and follow-up, not significant budget.

Links

No chapters are available for this episode.