<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Waratek</title><link>https://waratek.com/news/</link><description>Recent content on Waratek</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 21 Jul 2026 09:00:00 +0000</lastBuildDate><atom:link href="https://waratek.com/news/index.xml" rel="self" type="application/rss+xml"/><item><title>Oracle Releases the July 2026 Critical Patch Update</title><link>https://waratek.com/news/oracle-releases-the-july-2026-critical-patch-update/</link><pubDate>Tue, 21 Jul 2026 09:00:00 +0000</pubDate><guid>https://waratek.com/news/oracle-releases-the-july-2026-critical-patch-update/</guid><description><![CDATA[<blockquote class="wt-highlights"><p><strong>Highlights</strong></p>
<ul>
<li>Oracle&rsquo;s July 2026 CPU ships 1,455 new security patches, the largest Critical Patch Update Oracle has issued to date.</li>
<li>The highest score this quarter is a perfect CVSS 10.0, affecting Oracle Access Manager, WebLogic Server and Oracle Coherence within Fusion Middleware.</li>
<li>PeopleSoft is the emergency priority. CVE-2026-35278 and CVE-2026-35273 (both CVSS 9.8) are under active exploitation by the ShinyHunters extortion group, which claims to have compromised more than 300 PeopleSoft servers across 100+ organizations since late May 2026.</li>
<li>Fusion Middleware receives 359 patches (224 remotely exploitable without authentication), the largest single-family total in this CPU. WebLogic, Identity Manager and WebCenter Capture each carry CVSS 9.9 unauthenticated RCE flaws.</li>
<li>E-Business Suite receives 416 patches (63 remotely exploitable), reflecting sustained attacker interest after the 2025 Cl0p campaign and a separately exploited flaw patched last month.</li>
<li>Java SE ships 20 patches (18 remotely exploitable) with a comparatively modest maximum CVSS of 7.8, mostly affecting availability rather than confidentiality or integrity.</li>
<li><strong>Action:</strong> patch internet-facing PeopleSoft, Fusion Middleware (WebLogic, Identity Manager, Access Manager) and E-Business Suite this week. Treat the Database Server 9.9 flaw as high priority even though it is not yet reported under active exploitation.</li>
</ul>
</blockquote>
<h2 id="commentary">Commentary</h2>
<p>The Oracle Critical Patch Update (CPU) for July 2026 contains 1,455 new security patches spanning more than two dozen product families, making it the largest quarterly release Oracle has published. The update is cumulative, meaning it folds in the May 28 and June 16, 2026 monthly Critical Security Patch Updates (CSPU) as well as the out-of-band Security Alert issued June 10, 2026 for the PeopleSoft PeopleTools vulnerability now tracked as CVE-2026-35273.</p>]]></description></item><item><title>Oracle Releases Significant June Security Update</title><link>https://waratek.com/news/oracle-releases-significant-june-security-update/</link><pubDate>Wed, 17 Jun 2026 11:30:29 +0000</pubDate><guid>https://waratek.com/news/oracle-releases-significant-june-security-update/</guid><description><![CDATA[<h2 id="key-findings---oracle-cspu-june-2026">Key findings - Oracle CSPU June 2026</h2>
<p><strong>Advisory scope:</strong> 257 CVE-product matrix entries across 66 products in 11 product families (251 unique CVEs; same CVE can appear in multiple matrices).</p>
<table>
	<thead>
			<tr>
					<th>Severity</th>
					<th>Count</th>
					<th>No Auth Required</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><strong>Critical</strong> (CVSS ≥ 9.0)</td>
					<td><strong>134</strong></td>
					<td><strong>104</strong></td>
			</tr>
			<tr>
					<td><strong>High</strong> (7.0–8.9)</td>
					<td><strong>104</strong></td>
					<td>-</td>
			</tr>
			<tr>
					<td><strong>Medium</strong> (4.0–6.9)</td>
					<td><strong>15</strong></td>
					<td>-</td>
			</tr>
			<tr>
					<td>Low (&lt; 4.0)</td>
					<td>4</td>
					<td>-</td>
			</tr>
	</tbody>
</table>
<h2 id="top-risk-products-critical-cves">Top risk products (Critical CVEs)</h2>
<table>
	<thead>
			<tr>
					<th>Product</th>
					<th>Family</th>
					<th>Critical</th>
					<th>High</th>
					<th>Med</th>
					<th>No Auth Req</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td>Oracle WebCenter Content</td>
					<td>Fusion Middleware</td>
					<td><strong>16</strong></td>
					<td>13</td>
					<td>1</td>
					<td>14</td>
			</tr>
			<tr>
					<td>Oracle Enterprise Manager Base Platform</td>
					<td>Enterprise Manager</td>
					<td><strong>13</strong></td>
					<td>6</td>
					<td>-</td>
					<td>9</td>
			</tr>
			<tr>
					<td>JD Edwards EnterpriseOne Tools</td>
					<td>JD Edwards</td>
					<td><strong>13</strong></td>
					<td>1</td>
					<td>-</td>
					<td>11</td>
			</tr>
			<tr>
					<td>Oracle WebCenter Enterprise Capture</td>
					<td>Fusion Middleware</td>
					<td><strong>10</strong></td>
					<td>-</td>
					<td>-</td>
					<td>2</td>
			</tr>
			<tr>
					<td>Oracle WebCenter Portal</td>
					<td>Fusion Middleware</td>
					<td><strong>10</strong></td>
					<td>-</td>
					<td>-</td>
					<td>3</td>
			</tr>
			<tr>
					<td>Oracle WebCenter Sites</td>
					<td>Fusion Middleware</td>
					<td><strong>8</strong></td>
					<td>3</td>
					<td>-</td>
					<td>8</td>
			</tr>
			<tr>
					<td>Oracle Enterprise Command Center Framework</td>
					<td>E-Business Suite</td>
					<td><strong>7</strong></td>
					<td>1</td>
					<td>-</td>
					<td>2</td>
			</tr>
			<tr>
					<td>Oracle Coherence</td>
					<td>Fusion Middleware</td>
					<td><strong>7</strong></td>
					<td>-</td>
					<td>-</td>
					<td><strong>7</strong></td>
			</tr>
			<tr>
					<td>Oracle iSupport</td>
					<td>E-Business Suite</td>
					<td><strong>3</strong></td>
					<td>-</td>
					<td>-</td>
					<td>-</td>
			</tr>
	</tbody>
</table>
<h2 id="family-level-highlights">Family-level highlights</h2>
<p><strong>Oracle Fusion Middleware</strong> is the dominant risk surface consisting of 69 Critical CVEs across 14 products, 49 of them remotely exploitable without authentication. The WebCenter stack alone (Content, Portal, Sites, Enterprise Capture, Imaging) accounts for 47 Critical vulnerabilities. Oracle Coherence stands out with 7 Critical CVEs all scoring 9.3–10.0 and all RNoAuth.</p>]]></description></item><item><title>Waratek Appoints Apostolos Giannakidis as Chief Technology Officer</title><link>https://waratek.com/news/waratek-appoints-apostolos-giannakidis-as-chief-technology-officer/</link><pubDate>Mon, 15 Jun 2026 08:52:23 +0000</pubDate><guid>https://waratek.com/news/waratek-appoints-apostolos-giannakidis-as-chief-technology-officer/</guid><description><![CDATA[<p><strong>Veteran runtime security architect to lead Waratek’s technology strategy as enterprises confront a new wave of AI-generated code vulnerabilities and exploits</strong></p>
<p><strong>DUBLIN - 15 June, 2026</strong> - Waratek, the leader in runtime application security, today announced the appointment of Apostolos Giannakidis as Chief Technology Officer. In his new role, Giannakidis will lead Waratek’s technology vision, product strategy, and security research as the company expands its runtime protection platform to address the surge in software vulnerabilities and exploits introduced by AI-generated code.</p>]]></description></item><item><title>Oracle Launches Monthly Security Patching</title><link>https://waratek.com/news/oracle-launches-monthly-security-patching/</link><pubDate>Fri, 29 May 2026 09:57:46 +0000</pubDate><guid>https://waratek.com/news/oracle-launches-monthly-security-patching/</guid><description><![CDATA[<p><em>Summary and analysis of the first Oracles first monthly Critical Security Patch Update (CSPU)</em></p>
<p><strong>–URGENT ACTION RECOMMENDED–</strong></p>
<p><em>For Waratek customers and prospects</em></p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Oracle has moved from quarterly to monthly &amp; quarterly security patching. The first Critical Security Patch Update (CSPU) shipped on Thursday, May 28, 2026; subsequent CSPUs land on the third Tuesday of each month outside the quarterly CPU window.</li>
<li>This first CSPU is targeted and compact: 35 new security patches across five product families – a deliberately smaller footprint than the 483-patch April CPU.</li>
<li>Headline severity is a CVSS 10.0 in Oracle REST Data Services (ORDS) – the maximum possible score, unauthenticated, network-exploitable.</li>
<li>Oracle E-Business Suite ships 12 patches with a max CVSS 9.9 – attacker focus on EBS remains high after October 2025’s Cl0p extortion campaign (CVE-2025-61882).</li>
<li>Action: Waratek customers should contact <a href="mailto:customersuccess@waratek.com">customersuccess@waratek.com</a> for RASP rule coverage; prospects can request a same-week protection assessment from <a href="mailto:sales@waratek.com">sales@waratek.com</a>.</li>
</ul>
<h2 id="what-changed-oracles-new-monthly-cadence">What Changed: Oracle’s New Monthly Cadence</h2>
<p>For more than two decades Oracle has shipped security fixes on a quarterly Critical Patch Update (CPU) rhythm. As of May 28, 2026, Oracle has introduced an additional, monthly Critical Security Patch Update (CSPU) stream that fills the gap between quarterly releases. The change is a direct response to a year in which Oracle products were targeted by ransomware operators (Cl0p / CVE-2025-61882) and Identity Manager flaws (CVE-2025-61757, CVE-2026-21992) reached CISA’s KEV catalog within days of disclosure.</p>]]></description></item><item><title>Waratek Redefines Secure Development with Launch of Waratek IAST at JavaOne 2026</title><link>https://waratek.com/news/waratek-redefines-secure-development-with-launch-of-waratek-iast-at-javaone-2026/</link><pubDate>Fri, 20 Mar 2026 10:36:50 +0000</pubDate><guid>https://waratek.com/news/waratek-redefines-secure-development-with-launch-of-waratek-iast-at-javaone-2026/</guid><description><![CDATA[<p><strong>FOR IMMEDIATE RELEASE</strong></p>
<p><strong>REDWOOD SHORES, Calif. - March 18, 2026</strong> - Waratek, a leader in next-generation application security, today announced the official launch of Waratek IAST (Interactive Application Security Testing). The announcement was made during the JavaOne 2026 conference, where Waratek CEO Doug Ennis delivered a featured session on securing the software development lifecycle (SDLC) in the age of AI-generated code.</p>
<p>The launch addresses a critical and growing risk for enterprises relying on Large Language Models (LLMs) to accelerate Java development. While AI boosts productivity, new data from industry leaders reveals that this increased code volume comes with a significant security trade-off, specifically for the Java language.</p>]]></description></item><item><title>Waratek Selected for Ireland INC US 250 Index 2024</title><link>https://waratek.com/news/waratek-selected-for-ireland-inc-us-250-index-2024/</link><pubDate>Wed, 13 Nov 2024 17:46:54 +0000</pubDate><guid>https://waratek.com/news/waratek-selected-for-ireland-inc-us-250-index-2024/</guid><description><![CDATA[<p><em>November 13th, 2024</em></p>
<p>We’re thrilled to share that Waratek has been included in the <a href="https://irelandinc.com/download-ireland-inc-index-250-2023/"><strong>Ireland INC US 250 Index 2024</strong></a>, a special report curated by <strong>Business &amp; Finance Magazine</strong> which showcases 250 leading Irish companies that are actively investing in the United States. This annual index highlights the contributions of Irish companies that are driving economic growth, creating jobs, and fostering innovation across the Atlantic.</p>
<p>The Ireland INC US 250 Index celebrates a remarkable year of growth in Irish foreign direct investment (FDI) in the US. As of 2023, Irish companies have invested a record <strong>$240 billion</strong> in the US economy. The impact of this investment is far-reaching, with nearly <strong>100,000 US workers</strong> employed by the US affiliates of Irish-owned companies and a presence in over <strong>2,200 locations</strong> across the country. Approximately <strong>900 Irish companies</strong> export to the US, supporting vital industries across technology, healthcare, financial services, and more.</p>]]></description></item></channel></rss>