Stephen Kost has a new Oracle security blog
11i: How to Check for Correct APPLSYSPUB Privileges in 11i
11i: 07_DICTIONARY_ACCESSIBILITY and Auditors
Google Source Code Bug Finder
Un-patched Oracle Database Bugs - E-Business Suite Impact
and the most recent two posts that mention Black Hat and my PL/SQL unwrapping paper:
Bad Oracle Security Press Coming Soon
http://www.integrigy.com/oracle-security-blog/archive/2006/08/08/unwrap-plsql - (broken link) Unwrapping PL/SQL
keep an eye out on Steves blog it should be worth reading. I have also added it to my Oracle blogs aggregator