More

    Oracle races to patch a another zero-day following rise in attacks




    • Oracle patched CVE-2025-61884, a critical unauthenticated E-Business Suite vulnerability
    • ShinyHunters allegedly exploited the flaw to steal sensitive corporate data from multiple organizations
    • This is Oracle’s second patch addressing exploit chains used in recent ransomware extortion campaigns

    Oracle has patched yet another E-Business Suite vulnerability that was allegedly used by the ShinyHunters team to exfiltrate sensitive corporate data from numerous organizations.

    Earlier this week, the company published a new security advisory, announcing a patch for CVE-2025-61884. This vulnerability, discovered in E-Business Suite, “is remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password,” Oracle explained. “If successfully exploited, this vulnerability may allow access to sensitive resources.”


    https://cdn.mos.cms.futurecdn.net/d1435f2e8502b951cabe11c5a1c09bd9-900-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img