Estée Lauder discloses data breach via Oracle E-Business flaw

2026-07-21T07:23:30Z409fb899da77bc387cfc10987495891d35b3e6913819e14572043a68c1ef3357
7-zipai-agentai-securitycredential-theftcryptotheftdata-breachhollowgraphhugging-facemalwaremicrosoft-graphoracle-ebsransomwareremote-code-executionservicenowsonicwallsupply-chainvpnwordpresswsuszero-day

What happened

Multiple high-impact incidents and active exploitations reported: Estée Lauder notified customers after a data breach via an Oracle E-Business Suite flaw; SonicWall SMA1000 VPN zero-days were exploited to deploy custom malware; Ostium lost $23.75M in an off-chain price-feed compromise; and ServiceNow AI Platform suffered a critical remote code execution being actively exploited. Other notable items include AI-sandbox escapes across several agent tools, the JadePuffer agent deploying EncForge ransomware aimed at AI assets, HollowGraph using Microsoft Graph calendars for stealthy C2, a Hugging F

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
409fb899da77bc387cfc10987495891d35b3e6913819e14572043a68c1ef3357
Enrichment time
2026-07-21T07:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Estée Lauder discloses data breach via Oracle E-Business flaw · Baitaphish