#oracle-e-business-suite

[ follow ]
Information security
fromTechzine Global
1 day ago

CISA: Oracle vulnerability is being actively exploited

CISA added CVE-2025-61884 (SSRF in Oracle Configurator) to its actively exploited list and mandated patches for US agencies by November 10, 2025.
Information security
fromSecuritymagazine
1 day ago

Security Leaders Discuss Cyberattack on American Airlines Subsidiary

Envoy Air suffered a cyberattack tied to an Oracle E-Business Suite campaign; customer data appears unaffected, but some business contact information may have been compromised.
#cve-2025-61884
fromTheregister
5 days ago

Envoy caught in Clop's Oracle EBS raid

We are aware of the incident involving Envoy's Oracle E-Business Suite application,
Information security
#cl0p
#cve-2025-61882
#clop
fromTechCrunch
1 week ago
Information security

'Dozens' of organizations had data stolen in Oracle-linked hacks | TechCrunch

fromTechCrunch
2 weeks ago
Information security

Hackers are sending extortion emails to executives after claiming Oracle apps' data breach | TechCrunch

fromTechCrunch
1 week ago
Information security

'Dozens' of organizations had data stolen in Oracle-linked hacks | TechCrunch

fromTechCrunch
2 weeks ago
Information security

Hackers are sending extortion emails to executives after claiming Oracle apps' data breach | TechCrunch

fromIT Pro
2 weeks ago

Oracle patches EBS amid extortion attacks

And over the weekend, exploit code for the recently patched flaw was made public, making it even easier for other attackers to make use of it. "It's likely that almost no one patched over the weekend," noted Jake Knott, principal security researcher at watchTowr. "So we're waking up to a critical vulnerability with public exploit code and unpatched systems everywhere. Based on the evidence, we believe this is Cl0p activity, and we fully expect to see mass, indiscriminate exploitation from multiple groups within days."
Information security
fromTechCrunch
2 weeks ago

Clop hackers caught exploiting Oracle zero-day bug to steal executives' personal data | TechCrunch

The security advisory said the bug, tracked officially as CVE-2025-61882, can be "exploited over a network without the need for a username and password." The advisory provided several so-called indicators of compromise to help Oracle customers identify evidence of hackers on their systems, suggesting that hackers are currently exploiting the vulnerability to steal customers' sensitive data. Oracle says thousands of organizations around the world use its E-Business Suite to run their companies, including storing their customer data and their employee's human resources files.
Information security
fromTheregister
2 weeks ago

Oracle tells Clop-targeted EBS users to apply July patch

Oracle has finally broken its silence on those Clop-linked extortion emails, but only to tell customers what they already should have known: patch your damn systems. The database giant posted an impressively short blog post overnight, confirming that some E-Business Suite (EBS) users have been targeted by cybercriminals claiming to have siphoned off sensitive data, adding that the crooks appear to be exploiting holes Oracle already plugged in July.
Information security
Information security
fromSecurityWeek
2 weeks ago

Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks

Extortion emails targeting Oracle E-Business Suite customers indicate possible exploitation of vulnerabilities fixed in Oracle's July 2025 Critical Patch Update; Cl0p and FIN11 links suspected.
#extortion
fromIT Pro
3 weeks ago
Information security

Google warns executives are being targeted for extortion with leaked Oracle data

fromIT Pro
3 weeks ago
Information security

Google warns executives are being targeted for extortion with leaked Oracle data

[ Load more ]