https://www.oracle.com/security-alerts/cpujul2026.html
Security works great since those layoffs!
F'ing clowns.
https://www.oracle.com/security-alerts/cpujul2026.html
Security works great since those layoffs!
F'ing clowns.
@dk that’s a real interesting but stressful setup. Wow. That is crazy. I didn’t do security when I was at oracle but I get all your points. I got into it over last 5 years but boy do I see a ton of companies who will constantly say “we’ve identified all of these vulns and open doors in your package/software….our product can help your dev folks see it before it goes out to the public….try our product for 1 million a month scans or ingest and we will help you…” security industry is a mess and ton of very greedy people. I left.
oh and the "best" part of that bullsh-t vulnerabilities reported by kiwi is that for us devs it's easier and faster to accept and fix whatever theoretical conjecture it's claiming, than reject it and argue with security people.
so we don't even have an incentive to provide real feedback to top management that it's all bullsh-t so they would push back on kiwi people.
@d8 thank you for the clarification….so it’s a total assumption….that’s not cool.
@bf none of them did in aggregate, because those are Oracle components, they are not 3rd party independent components, so they are delivered and deployed together. and as an aggregate they had none of those vulnerabilities they claim they have. but kiwi doesn't see an aggregate, it assumes each component independent and start think, oh boy what if everything around it is misconfigured and compromised.
kiwi creators have an incentives to overreport to sell their product/service.
Bet you stopped reading after the headline. It’s across 334 products. Tons in Siebel and PeopleSoft… who cares.
@bf 1200 could is really a lot fewer unique open source dependencies in more than 50 products, each counted separately.
@a2 fair enough. So the one component did have CVE’s or didn’t? I used to work at O but got into security so I’m really interested in this topic. Having few CVE’s not huge shock. Having 1200….not good. You’re saying the kiwi is doing a guilty by association?
They have to be repackaged third party AI slop fixes as none are equipped to deliver so many original fixes on CVEs reported in 2026.
Kiwi scan raised over 100 "critical" security issues in our codebases. After actual triage we did - every single one of those claim is complete bullsh-t and there is not single real vulnerabilities found. All kiwi findings are isolated to a single component, so it's justification is "what if other components are written by re--rds and compromised".
Sorry, OVER 1,200. A new world record!