HomeVulnerabilityOracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft...

Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks

Oracle has launched an emergency replace to deal with a crucial security flaw in its E-Enterprise Suite that it mentioned has been exploited within the latest wave of Cl0p knowledge theft assaults.

The vulnerability, tracked as CVE-2025-61882 (CVSS rating: 9.8), issues an unspecified bug that might permit an unauthenticated attacker with community entry through HTTP to compromise and take management of the Oracle Concurrent Processing element.

“This vulnerability is remotely exploitable with out authentication, i.e., it could be exploited over a community with out the necessity for a username and password,” Oracle mentioned in an advisory. “If efficiently exploited, this vulnerability might lead to distant code execution.”

In a separate alert, Oracle’s Chief Safety Officer Rob Duhart mentioned the corporate has launched fixes for CVE-2025-61882 to “present updates towards extra potential exploitation that have been found throughout our investigation.”

DFIR Retainer Services

As indicators of compromise (IoCs), the expertise shared the next IP addresses and artifacts, indicating the seemingly involvement of the Scattered LAPSUS$ Hunters group as properly within the exploit –

See also  Danger evaluation important when selecting an AI mannequin, say specialists

Information of the Oracle zero-day comes days after studies emerged of a brand new marketing campaign seemingly undertaken by the Cl0p ransomware group focusing on Oracle E-Enterprise Suite. Google-owned Mandiant described the continuing exercise as a “high-volume e-mail marketing campaign” launched from a whole bunch of compromised accounts.

In a put up shared on LinkedIn, Charles Carmakal, CTO of Mandiant at Google Cloud, mentioned “Cl0p exploited a number of vulnerabilities in Oracle EBS which enabled them to steal giant quantities of information from a number of victims in August 2025,” including “a number of vulnerabilities have been exploited together with vulnerabilities that have been patched in Oracle’s July 2025 replace in addition to one which was patched this weekend (CVE-2025-61882).”

“Given the broad mass zero-day exploitation that has already occurred (and the n-day exploitation that can seemingly proceed by different actors), no matter when the patch is utilized, organizations ought to look at whether or not they have been already compromised,” Carmakal famous.

See also  Main GitHub repos leak entry tokens placing code and clouds in danger

(This can be a creating story. Please test again for extra particulars.)

- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular