More

    Oracle forced to rush out patch for zero-day exploited in attacks




    • Oracle patched a critical zero-day RCE flaw in E-Business Suite, actively exploited by ransomware actors
    • Attackers used compromised email accounts to extort victims; FIN11 and Cl0p may be involved
    • CVE-2025-61882 scored 9.8/10; exploitation requires no authentication and enables full system takeover

    Oracle has released a patch to address a zero-day vulnerability in its E-Business Suite which was being actively exploited by ransomware actors.

    In early October 2025, cybercriminals started mailing executives at various American organizations, claiming to have stolen sensitive files from their Oracle E-Business Suite systems. At the time, both Oracle and the wider cybersecurity community were not certain if the breaches actually happened, or if this was just a bluff to get the victims to pay a ransom demand.


    https://cdn.mos.cms.futurecdn.net/d1435f2e8502b951cabe11c5a1c09bd9-900-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img