A recent wave of cybersecurity threats has highlighted the escalating risks faced by organizations in the digital landscape. Hackers have launched aggressive attacks on Microsoft 365 accounts, exploiting vulnerabilities in Oracle E-Business, and leveraging AI-driven tactics to evade detection.
What Happened
A password-spraying campaign targeting Microsoft 365 environments generated over 81 million login attempts in just two weeks. The threat actor used valid username and password combinations exposed in past breaches to authenticate via Microsoft's Azure command-line interface (CLI). This campaign compromised 78 Microsoft accounts across 64 organizations.
Meanwhile, over 900 Oracle E-Business Suite (EBS) instances have been found exposed online, leaving them vulnerable to ongoing attacks exploiting a critical security flaw (CVE-2026-46817). This vulnerability allows malicious actors to take over vulnerable systems through low-complexity attacks.
Why It Matters
The increasing sophistication of cyber threats poses significant risks to organizations. AI-driven attacks, such as "Phantom Squatting," can evade detection by creating hallucinated web domains for legitimate brands. This emerging threat vector is difficult to detect and requires advanced threat intelligence to mitigate.
The sheer volume of security data can also become a liability. As one CISO noted, rapid growth can turn routine firewall logs into a security and budget liability. Artificial intelligence can help filter out irrelevant data, but the challenge of managing security data remains a pressing concern.
What Experts Say
"CVE-2026-46817 (CVSS 9.8 unauth HTTP takeover in Oracle E-Business) is being exploited. Over the weekend, we observed an actor exploiting the vulnerability on our Oracle E-Business honeypots." — Defused, threat intelligence company
Key Numbers
- 81 million: The number of login attempts made by hackers targeting Microsoft 365 accounts in two weeks
- 78: The number of Microsoft accounts compromised across 64 organizations
- 900: The number of Oracle E-Business Suite instances exposed online
- 9.8: The CVSS score of the vulnerability (CVE-2026-46817) exploited in Oracle E-Business attacks
Key Facts
- Who: Hackers and threat actors
- What: Aggressive password-spraying campaign and exploitation of Oracle E-Business vulnerability
- When: June 12-26 (Microsoft 365 campaign) and ongoing (Oracle E-Business attacks)
- Where: Global
- Impact: Compromised Microsoft accounts and exposed Oracle E-Business instances
What Comes Next
As cybersecurity threats continue to escalate, organizations must prioritize threat intelligence and invest in advanced security measures to mitigate the risks. The integration of AI-driven solutions, such as OpenCTI with Criminal IP, can help transform indicators into structured intelligence and support investigation, correlation, and decision-making.