Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Clop cybercriminals found leveraging an Oracle zero-day vulnerability to obtain private information of company executives

Clop cybercriminals found leveraging an Oracle zero-day vulnerability to obtain private information of company executives

Bitget-RWA2025/10/06 19:03
By:Bitget-RWA

Oracle has addressed a zero-day flaw in one of its leading enterprise software solutions, which a cybercriminal group has been exploiting to obtain confidential details about business executives. 

In a short update posted over the weekend, Oracle’s chief security officer Rob Duhart announced that the company had issued a fresh security patch for its Oracle E-Business Suite and strongly recommended that users apply the update without delay.  

According to the security notice, the vulnerability—cataloged as CVE-2025-61882—can be “abused remotely without requiring authentication.” The advisory included several indicators of compromise to assist Oracle clients in detecting signs of unauthorized access, indicating that attackers are actively leveraging the flaw to extract sensitive information. 

Oracle reports that its E-Business Suite is used by thousands of companies worldwide to manage operations, including storing customer records and employee HR data. 

This vulnerability is classified as a zero-day because Oracle had no opportunity to address it before it was exploited by malicious actors. 

Duhart’s revised statement marks a shift from earlier in the week, when a previous version noted Oracle was aware that some executives “have received extortion emails” related to vulnerabilities fixed in July, implying the extortion activity had ended. The discovery of this new zero-day flaw indicates that attackers continued to take advantage of previously unknown weaknesses in Oracle’s E-Business software. 

Reports about the extortion scheme targeting business leaders surfaced last week.  

On October 2, Google’s security team revealed that the well-known hacking group Clop—associated with various ransomware and extortion incidents—had sent emails to Oracle executives around September 29, threatening to release their personal data online unless paid. 

Charles Carmakal, chief technology officer at Google’s incident response division Mandiant, wrote on LinkedIn Sunday that Oracle’s E-Business Suite vulnerabilities were being exploited in a “large-scale campaign” aimed at data theft and extortion.  

Carmakal noted that much of this malicious activity took place in August, following the release of the July security patches. 

“Clop has been issuing extortion demands to multiple victims since last Monday,” Carmakal stated, but added that not every victim has been contacted by the hackers yet. 

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Bitcoin News Update: Stability-Focused Crypto Pioneers Take On Unpredictable Industry Leaders

- Bitcoin's 2025 price forecasts predict $168,000 peaks amid technical/macroeconomic optimism, but correction risks persist if key support levels fail. - Solana (SOL) struggles with bearish technical patterns near $130, while Bitcoin Munari and Astra Bitcoin emerge as stability-focused alternatives via structured presales and gold/real-estate backing. - Regulatory developments like Binance's HNWI services and Nasdaq's ETF options expansion highlight crypto's institutional maturation, though legal challenge

Bitget-RWA2025/11/30 01:52
Bitcoin News Update: Stability-Focused Crypto Pioneers Take On Unpredictable Industry Leaders

Chainlink Faces $13.50 Showdown: Bulls Target Breakout While Bears Caution of Potential Drop

- Chainlink (LINK) tests $13.50 resistance as bulls anticipate a potential breakout after years of consolidation. - Analysts highlight $13.50-$16 as critical thresholds, with failure to hold above risking a drop to $11.80 support. - Mixed technical signals show $648M daily volume and $9.16B market cap, but indecisive closes challenge bullish momentum. - Market watchers debate December's potential breakout, emphasizing LINK's strategic role in DeFi infrastructure.

Bitget-RWA2025/11/30 01:52
Chainlink Faces $13.50 Showdown: Bulls Target Breakout While Bears Caution of Potential Drop

Bitcoin Updates: AI-Induced Systemic Turmoil Drives Move Toward Bitcoin and Gold, Kiyosaki Issues Caution

- Robert Kiyosaki warns of AI-driven global financial crisis, urging investors to prioritize Bitcoin , Ethereum , gold , and silver as inflation-resistant assets. - He attributes structural collapse to AI-driven job losses, remote work, and the unraveling yen carry trade, which destabilizes traditional investment strategies. - Kiyosaki forecasts Bitcoin at $250,000 by 2026, Ethereum as a smart contract alternative to gold, and silver surging to $200/ounce amid systemic risk. - Despite selling $2.25M in Bit

Bitget-RWA2025/11/30 01:52
Bitcoin Updates: AI-Induced Systemic Turmoil Drives Move Toward Bitcoin and Gold, Kiyosaki Issues Caution