Fortra® Security & Trust Center

Blog

August 2026 Oracle Critical Security Patch Update Analysis

Oracle’s August 2026 Critical Security Patch Update addresses 943 new security patches across affected Oracle product families, including 925 unique CVEs and 451 vulnerabilities that are remotely exploitable without authentication. The FIRE team highlights several high-risk CVEs with critical CVSS scores and recommends prioritizing patching for internet-facing systems, unauthenticated network vulnerabilities, and products with high business impact.
Blog

BEC Global Insights Report: July 2026

In July 2026, FIRE observed a 12% decrease in BEC attack volume, with gift cards remaining the most common cash-out method and Apple Store gift cards representing the largest share of gift card requests. The month also saw lower wire transfer request amounts, 31 cryptocurrency-related scams across 15 unique wallets, and continued reliance on free webmail providers for most BEC attacks.
Blog

July 2026 Patch Tuesday Analysis

Today’s Patch Tuesday Alert addresses Microsoft’s July 2026 Security Updates. The FIRE team is actively working on coverage for these vulnerabilities and expect to ship that coverage as soon as it is completed. In-the-Wild & Disclosed CVEsCVE-2026-58644A vulnerability in SharePoint could allow for an unauthenticated user to execute code due to deserialization of untrusted data. Microsoft has...
Blog

Fortra Patch Priority Index for June 2026

Microsoft’s June 2026 Patch Tuesday was its largest ever. This Patch Priority Index ranks customer-actionable vulnerabilities by operational risk, highlighting internet-facing threats, active exploitation, public PoCs, and enterprise exposure while excluding low-priority and non-actionable cloud-service CVEs.
Blog

The Financial Scam Detector (FSD): a Model to Catch the "Initial Contact" Financial Email Scam

Legacy email security systems are excellent at stopping known threats. If a malicious link has been flagged before, or if a sending domain is on a global blacklist, the email gets blocked. But what happens when an attacker uses generative AI to instantly script dozens of highly convincing lookalike domains, pairs them with short-lived disposable domain infrastructure, crafts a hyper realistic fake...