Oracle and Cybercriminals: Recent EBS Security Breaches and Extortion Attacks

TL;DR Summary
Oracle has issued a critical security update for a zero-day vulnerability (CVE-2025-61882) in its E-Business Suite, actively exploited by the Clop ransomware gang to steal data. The flaw allows unauthenticated remote code execution and has been linked to recent data theft attacks, with threat actors sharing exploit code and indicators of compromise. Oracle urges immediate patching to prevent further exploitation.
- Oracle patches EBS zero-day exploited in Clop data theft attacks BleepingComputer
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks The Hacker News
- Google says hackers are sending extortion emails to corporate executives Reuters
- Oracle Investigating Hacks of Customers’ E-Business Suite Yahoo Finance
- Cyber Group Extorts Executives After Claiming Oracle Apps Breach Bloomberg.com
Reading Insights
Total Reads
0
Unique Readers
2
Time Saved
5 min
vs 6 min read
Condensed
94%
1,021 → 60 words
Want the full story? Read the original article
Read on BleepingComputer