Oracle Releases Emergency Patch for CVE-2025-61882 Amid Cl0p Data Theft Attacks

TL;DR Summary
Oracle released an emergency patch for a critical vulnerability (CVE-2025-61882) in its E-Business Suite, which has been exploited by the Cl0p ransomware group in recent data theft attacks. The flaw allows remote code execution without authentication, and indicators suggest involvement of the LAPSUS$ group. Organizations are advised to check for compromises, as exploitation has already occurred.
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks The Hacker News
- Google says hackers are sending extortion emails to corporate executives Reuters
- Oracle patches EBS zero-day exploited in Clop data theft attacks BleepingComputer
- Oracle Investigating Hacks of Customers’ E-Business Suite Yahoo Finance
- Oracle pushes emergency weekend patch amid 0day exploitation The Stack
Reading Insights
Total Reads
0
Unique Readers
2
Time Saved
2 min
vs 2 min read
Condensed
85%
375 → 56 words
Want the full story? Read the original article
Read on The Hacker News