decrypted · 19 july 2026 · ransomware and cybercrime · vulnerabilities and patching · ai and llm security
Oracle's six-week grace period, and the Payments takeover that followed
Oracle patched a critical flaw in E-Business Suite's Payments module in May. Nobody exploited it for six weeks. Then, over the weekend of 27 June, unauthenticated requests started hitting honeypot servers with no public proof-of-concept in sight, meaning whoever wrote the exploit worked it out from the patch diff alone. On 15 July, CISA added the bug to its exploited-vulnerabilities catalogue and gave US federal agencies until Saturday to patch. That three-day window was a US regulatory deadline, not a UK one, but the software it concerns runs quietly behind the finance departments of universities, NHS trusts and large enterprises across Britain.
A file transfer tool that trusted its own network
CVE-2026-46817 sits in the File Transmission component of Oracle Payments, scoring 9.8 out of 10. The flaw lets an attacker with nothing more than HTTP access to the server reach an endpoint called ibytransmit and, through it, call an internal Java function directly rather than going through the login screen. Researchers demonstrated the bug by reading /etc/passwd off a vulnerable box: proof that the function would hand back any file it was asked for, no credentials required. Think of it as a warehouse with a manned front desk and a loading bay round the back with no lock, because whoever built the loading bay assumed only forklifts from inside the warehouse would ever use it. Shadowserver counted around 450 exposed EBS instances online when the exploitation began; how many were still unpatched by the time CISA acted is unclear, but Oracle's own May advisory gave every customer six weeks' notice.
The recurring shape of this year's worst bugs
This is now a familiar pattern in 2026's vulnerability disclosures: a function written for a trusted internal caller turns out to be reachable from the outside, because nothing at that specific boundary checks who is asking. It is a different bug in a different product each time, but the underlying design mistake, authorisation enforced at the front door instead of at every internal function that can move or expose data, keeps recurring. Oracle E-Business Suite is not an obscure system here. It underpins the NHS Electronic Staff Record, which pays over 1.9 million NHS employees every month, and large trusts including Barts Health run their finance and procurement operations on EBS versions that fall inside the 12.2.3 to 12.2.15 range this flaw affects. That is not a claim that any UK trust has been compromised: it is a reason UK IT and finance leaders should treat Oracle's May patch, and this one specifically, as urgent rather than routine. If you run EBS Payments, check your patch level and your network exposure this week, not next quarter.
Also this week
Incident responders at Sygnia published findings from a breach that compromised a large AWS environment in 72 hours, a job that would normally take a team of operators several weeks. The attacker got in through a weak internet-facing application, then chained entirely ordinary cloud techniques, credential theft, secrets harvesting, backdoor persistence, at a pace and parallelism that Sygnia says is hard to explain without AI assistance: four access keys used simultaneously from the same IP address, scripts with the fingerprints of AI-generated code. Nothing about the techniques was novel. What changed was the clock. For UK organisations leaning on cloud-native defences that assume a human attacker's pace, that compression is the actual warning, not the presence of AI itself.
City of London Police, which runs the UK's fraud and cybercrime reporting service, disclosed that 323 UK businesses reported ransomware attacks in the twelve months to March, over 26 a month, with average losses up 50% year on year to roughly £270,000. More than half the victims were small and mid-sized firms, and police were explicit that the true figure is almost certainly higher, since formal reporting is thought to capture only a fraction of actual incidents. Manufacturing took the largest share of reports, ahead of scientific and technical services and education. It is a reminder that ransomware in Britain is not primarily a story about household names; it is a steady grind against firms too small to have a dedicated security team.
Sources
- CISA orders feds to patch actively exploited Oracle flaw by Saturday
- Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)
- Successful Oracle Cloud Infrastructure Migration and E-Business Suite Upgrade for Barts Health NHS Trust
- Inside an AI-Assisted Cloud Attack
- Don't pay the ransom: warning to organisations as more than 320 businesses affected last year
- Over 300 UK Firms Hit by Ransomware in a Year
If any of this touches systems you run, get in touch.
More like this
- The phone call that gets past your passkey 12 september 2026
- The AI gateway bug that turned a failed login into a free pass 7 september 2026
- A Magento zero-day is backdooring stores while Adobe still has no patch 6 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.