ZeroHour

Search: “Oracle Outside In Technology”

59 stories

ZDI-26-635: Oracle Outside In Technology PDF File Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-60392, an integer overflow in Oracle Outside In PDF parsing enabling remote code execution, rated CVSS 7.8.

The Zero Day Initiative published advisory ZDI-26-635 describing an integer overflow vulnerability in PDF file parsing within Oracle Outside In Technology. Successful exploitation allows remote code execution but requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI assigned the flaw a CVSS rating of 7.8.

CISA and NIST Issue Guidance to Protect Cloud Identity Tokens

CISA and NIST published Interagency Report 8587 with voluntary guidance to harden cloud identity tokens against theft, forgery, and lateral movement.

CISA and NIST released NIST Interagency Report 8587 on September 15 with final voluntary guidance for federal agencies, cloud providers, and their customers on protecting SSO, federation, and API tokens. Requirements include one-hour maximum token lifetimes, 90-day signing key rotation for high-impact systems, hardware-backed key storage, explicit audience fields, and keeping tokens out of logs. The guidance was motivated by the 2020 ADFS compromise where forged SAML assertions bypassed MFA, and an incident where a leaked consumer signing key enabled token forgery and theft of 60,000+ emails from one agency. Nearly 250 public comments shaped the text, with input from Google, Microsoft, Okta, AWS, Oracle, IBM, HashiCorp, Wiz, and the OpenID Foundation via the Joint Cyber Defense Collaborative.

Infosecurity Magazine · 7h agoAdvisory