{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3odebiandebian_linux8.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:thrift:*:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:a:f5:traffix_signaling_delivery_controller:*:*:*:*:*:*:*:*","cpe:2.3:a:oracle:global_lifecycle_management_opatch:*:*:*:*:*:*:*:*","cpe:2.3:a:oracle:nosql_database:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2018-1320"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Thrift"],"_cs_severities":["medium"],"_cs_tags":["thrift","network-security","initial-access","microservices"],"_cs_type":"advisory","_cs_vendors":["Apache"],"content_html":"\u003cp\u003eApache Thrift is a common framework used to facilitate scalable cross-language service development, frequently deployed within internal environments for microservice communication and data ecosystem components such as Apache HBase, Hive, Spark, and Impala. Many of these deployments assume a trusted network architecture and lack robust application-level authentication.\u003c/p\u003e\n\u003cp\u003eThe risk manifests when a Thrift listener, intended only for internal communication, is exposed to the public internet. Threat actors may exploit this exposure to perform reconnaissance, invoke unauthorized administrative methods, or execute arbitrary code via vulnerabilities such as CVE-2018-1320. This intelligence brief highlights the need to monitor for the first decoded RPC relationship between a public client address and an internal server. Defenders should treat any such connection as suspicious, as it indicates a violation of network segmentation and a potential vector for initial access or unauthorized data access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of exposed Thrift endpoints can lead to significant impact, including unauthorized access to sensitive data stores, modification of service configurations, and the execution of malicious jobs. Because Thrift services often operate with high-level service account privileges, an attacker can leverage this access to perform lateral movement or exfiltration across the Hadoop ecosystem or internal microservice mesh.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement the provided detection logic to surface the first observed connection between an external client and an internal Thrift service.\u003c/li\u003e\n\u003cli\u003eAudit existing Thrift service deployments; restrict listeners to authorized internal network segments and mandate authenticated, encrypted transport (e.g., TLS) for all RPC calls.\u003c/li\u003e\n\u003cli\u003eValidate identified connections against known partner integration and service inventories to distinguish legitimate traffic from potential reconnaissance or exploitation attempts.\u003c/li\u003e\n\u003cli\u003eReview service IDLs to determine if exposed methods permit configuration changes, resource deletion, or job execution, and prioritize these endpoints for immediate isolation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-31T19:10:46Z","date_published":"2026-07-31T19:10:46Z","id":"https://feed.craftedsignal.io/briefs/2026-07-thrift-rpc-exposure/","summary":"Detection logic targeting unauthorized Apache Thrift RPC method invocations from external IP addresses to identify exposed internal microservices or potential exploitation of data platforms.","title":"Detection of Unauthorized Apache Thrift RPC Invocations from External Networks","url":"https://feed.craftedsignal.io/briefs/2026-07-thrift-rpc-exposure/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*","cpe:2.3:a:percona:percona_server:*:*:*:*:*:*:*:*","cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:5.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:6.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:7.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:9:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_eus:7.3:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:human_resources:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2016-6662"},{"cvss":9.8,"id":"CVE-2026-60200"},{"cvss":9.8,"id":"CVE-2026-60240"},{"cvss":9.8,"id":"CVE-2026-60355"},{"cvss":7.2,"id":"CVE-2026-46954"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Oracle Application Testing Suite 13.3.0.1","Application Testing Suite (13.3.0.1)","Oracle Retail Integration Bus (RIB Kernal 14.1.3.2)","Oracle Retail Integration Bus (16.0.3)","Oracle Enterprise Manager Base Platform (13.5)","Oracle Enterprise Manager Base Platform (24.1)","Oracle Enterprise Manager Base Platform (13.5, 24.1)","Siebel CRM (17.0-26.3)","Siebel CRM Development (17.0-26.3)","Siebel Approval Manager (17.0-26.3)","Oracle Net Services","Oracle Database Server (19.3-19.31)","Oracle Database Server (21.3-21.22)","Oracle Database Server (23.4.0-23.26.2)","Oracle Data Integrator (12.2.1.4.0)","Oracle Data Integrator (14.1.2.0.0)","Oracle Hospitality Simphony (19.8-19.8.5)","Oracle Hospitality Simphony (19.9-19.9.3)","Oracle Hospitality Simphony (19.10)","Oracle BI Publisher (8.2.0.0.0, 12.2.1.4.0)","Oracle Coherence (12.2.1.4.0)","Oracle Coherence (14.1.1.0.0)","Oracle Coherence (14.1.2.0.0)","Oracle Coherence (15.1.1.0.0)","Oracle WebLogic Server (12.2.1.4.0)","Oracle WebLogic Server (14.1.1.0.0)","Oracle WebLogic Server (14.1.2.0.0)","Oracle WebLogic Server (15.1.1.0.0)","Oracle Fusion Middleware","WebLogic Server 12.2.1.4.0","WebLogic Server 14.1.1.0.0","WebLogic Server 14.1.2.0.0","WebLogic Server 15.1.1.0.0","Oracle Coherence 12.2.1.4.0","Oracle Coherence 14.1.1.0.0","Oracle Coherence 14.1.2.0.0","Oracle Coherence 15.1.1.0.0","Oracle Coherence \u003c= 12.2.1.4.0","Oracle Coherence \u003c= 14.1.1.0.0","Oracle Coherence \u003c= 14.1.2.0.0","Oracle Coherence \u003c= 15.1.1.0.0","Coherence (14.1.1.0.0)","Coherence (14.1.2.0.0)","Coherence (15.1.1.0.0)","Oracle Fusion Middleware Coherence 12.2.1.4.0","Oracle Fusion Middleware Coherence 14.1.1.0.0","Oracle Fusion Middleware Coherence 14.1.2.0.0","Oracle Fusion Middleware Coherence 15.1.1.0.0","Oracle WebLogic Server 12.2.1.4.0","Oracle WebLogic Server 14.1.1.0.0","Oracle WebLogic Server 14.1.2.0.0","Oracle WebLogic Server 15.1.1.0.0","Oracle Access Manager 12.2.1.4.0","Oracle Access Manager 14.1.2.1.0","Oracle Access Manager (12.2.1.4.0)","Oracle Access Manager (14.1.2.1.0)","Oracle Identity Manager (12.2.1.4.0)","Oracle Identity Manager (14.1.2.1.0)","Oracle Access Manager (12.2.1.4.0, 14.1.2.1.0)","Oracle Unified Directory (12.2.1.4.0)","Oracle Unified Directory (14.1.2.1.0)","Oracle HTTP Server (12.2.1.4.0)","Oracle HTTP Server (14.1.2.0.0)","Oracle Fusion Middleware (Apache Plugin)","Oracle Weblogic Server Proxy Plug-in 12.2.1.4.0","Oracle Weblogic Server Proxy Plug-in 14.1.2.0.0","Oracle Weblogic Server Proxy Plug-in (15.1.1.0.0)","Service Delivery Platform (12.2.1.4.0)","Service Delivery Platform (14.1.2.0.0)","Oracle Fusion Middleware Service Delivery Platform (12.2.1.4.0)","Oracle Fusion Middleware Service Delivery Platform (14.1.2.0.0)","Fusion Middleware Service Delivery Platform (12.2.1.4.0)","Fusion Middleware Service Delivery Platform (14.1.2.0.0)","Service Delivery Platform (component Messaging Enabler, versions 12.2.1.4.0, 14.1.2.0.0)","Oracle Fusion Middleware Service Delivery Platform (Messaging Enabler 12.2.1.4.0)","Oracle Fusion Middleware Service Delivery Platform (Messaging Enabler 14.1.2.0.0)","Oracle Fusion Middleware Service Delivery Platform 12.2.1.4.0","Oracle Fusion Middleware Service Delivery Platform 14.1.2.0.0","Oracle Fusion Middleware (Messaging Enabler) 12.2.1.4.0","Oracle Fusion Middleware (Messaging Enabler) 14.1.2.0.0","Service Delivery Platform 12.2.1.4.0","Service Delivery Platform 14.1.2.0.0","TimesTen In-Memory Database Kubernetes Operator (26.1.1.1.0)","Oracle Unified Directory 14.1.2.1.0","Oracle WebCenter Content 12.2.1.4.0","Oracle WebCenter Content 14.1.2.0.0","Oracle WebCenter Enterprise Capture (12.2.1.4.0)","Oracle WebCenter Enterprise Capture (14.1.2.0.0)","Oracle WebCenter Enterprise Capture 12.2.1.4.0","Oracle WebCenter Enterprise Capture 14.1.2.0.0","WebCenter Enterprise Capture (12.2.1.4.0)","WebCenter Enterprise Capture (14.1.2.0.0)","WebCenter Content: Imaging (12.2.1.4.0)","WebCenter Content: Imaging (14.1.2.0.0)","Oracle Identity Manager Connector (12.2.1.4.0)","Oracle Identity Manager Connector (14.1.2.1.0)","Oracle Managed File Transfer (12.2.1.4.0)","Oracle Managed File Transfer (14.1.2.0.0)","Oracle SOA Suite (12.2.1.4.0)","Oracle SOA Suite (14.1.2.0.0)","Oracle SOA Suite 12.2.1.4.0","Oracle SOA Suite 14.1.2.0.0","Oracle Business Process Management Suite (12.2.1.4.0)","Oracle Business Process Management Suite (14.1.2.0.0)","Oracle WebCenter Sites (12.2.1.4.0)","Oracle WebCenter Sites (14.1.2.0.0)","Oracle WebCenter Sites 12.2.1.4.0","Oracle WebCenter Sites 14.1.2.0.0","Oracle WebCenter Portal (12.2.1.4.0)","Oracle WebCenter Portal (14.1.2.0.0)","Oracle WebCenter Portal 12.2.1.4.0","Oracle WebCenter Portal 14.1.2.0.0","PeopleSoft Enterprise CC Common Application Objects (9.2)","Oracle Public Sector Financials (International) (12.2.3-12.2.15)","Oracle E-Business Suite","Oracle Cost Management (12.2.3-12.2.15)","Oracle Retail EFTLink (21.0.0-25.0.0)","Oracle E-Business Suite (Data Removal Tool) 12.2.3-12.2.15","Oracle Utilities Network Management System (2.5.0.1.0-2.5.0.1.17)","Oracle Utilities Network Management System (2.5.0.2.0-2.5.0.2.11)","Oracle Utilities Network Management System (2.6.0.1.0-2.6.0.1.12)","Oracle Utilities Network Management System (2.6.0.2.0-2.6.0.2.8)","Oracle Utilities Network Management System (25.12.0.0.0-25.12.0.0.2)","Oracle Enterprise Manager Base Platform (Agent Next Gen) 13.5","Oracle Enterprise Manager Base Platform (Agent Next Gen) 24.1","Metadata Plugin","Oracle Communications Pricing Design Center 15.0.0.0.0","Oracle Communications Pricing Design Center 15.0.1.0.0","Oracle Communications Pricing Design Center 15.1.0.0.0","Oracle Communications Pricing Design Center 15.2.0.0.0","Oracle Product Workbench (12.2.3-12.2.15)","PeopleSoft Enterprise PeopleTools (8.62)","PeopleSoft Enterprise PeopleTools (8.61)","Siebel CRM Cloud Applications (22.3-26.5)","Oracle Product Hub (12.2.3-12.2.15)","OpenSearch Dashboards","Oracle Document Management and Collaboration (12.2.3-12.2.15)","Oracle Bills of Material (12.2.3-12.2.15)","Oracle E-Business Suite (12.2.3-12.2.15)","Oracle Contracts Integration (12.2.3-12.2.15)","Oracle VM VirtualBox (7.2.12)","Oracle VM VirtualBox (Core) 7.2.8","VirtualBox \u003c= 7.2.12","Java SE (8u491)","Java SE (8u491-perf)","Java SE (11.0.31)","Java SE \u003c= 8u491","Java SE \u003c= 8u491-perf","Java SE \u003c= 11.0.31","Oracle E-Business Suite (Workflow Notification Mailer) (12.2.3-12.2.15)","Oracle GoldenGate (Service Manager) 19.1.0.0.0-19.29.0.0","Oracle GoldenGate (Service Manager) 21.3-21.21","Oracle GoldenGate (Service Manager) 23.4-23.26.1.0.0","Oracle VM VirtualBox (\u003c= 7.2.12)","MySQL Server (8.4.0-8.4.10)","MySQL Server (9.7.0-9.7.1)","MySQL Cluster (8.0.0-8.0.47)","MySQL Cluster (8.4.0-8.4.10)","MySQL Cluster (9.7.0-9.7.1)","Oracle Payments (12.2.3-12.2.15)","MySQL Connector/C++ (9.7.0-9.7.1)","Oracle Database Server","Oracle Commerce","Oracle Construction and Engineering","E-Business Suite","Oracle Enterprise Manager","Oracle Financial Services Applications","JD Edwards","MySQL","Oracle Retail Applications","Oracle Platform Security for Java (12.2.1.4.0)","Oracle Platform Security for Java (14.1.2.0.0)","Oracle Platform Security for Java (12.2.1.4.0, 14.1.2.0.0)","Oracle Platform Security for Java 12.2.1.4.0","Oracle Platform Security for Java 14.1.2.0.0","Oracle Process Manufacturing Systems (12.2.3 - 12.2.15)","Oracle Solaris (11.3)","Oracle Solaris (11.4)"],"_cs_severities":["high"],"_cs_tags":["roundup"],"_cs_type":"advisory","_cs_vendors":["Oracle","PeopleSoft"],"content_html":"\u003cp\u003eAggregated Oracle security advisories for July 2026. CVEs from this cycle are folded\ninto the list below as they are published.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eReview affected products and apply Oracle's July 2026 security updates.\u003c/p\u003e\n","date_modified":"2026-07-31T19:10:21Z","date_published":"2026-07-21T22:19:09Z","id":"https://feed.craftedsignal.io/briefs/2026-07-oracle-security-updates/","summary":"Roundup of Oracle security advisories published in July 2026.","title":"Oracle Security Updates — July 2026","url":"https://feed.craftedsignal.io/briefs/2026-07-oracle-security-updates/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}