Oracle EBS Zero-Day (CVE-2025-61882) Under Active RCE Exploitation by GRACEFUL SPIDER
ID: d43631ea-9245-50c7-befb-7ae45a507d27
STIX ID: report--d43631ea-9245-50c7-befb-7ae45a507d27
Feed Name: securityonline.info
**Active zero-day mass exploitation against Oracle E-Business Suite (CVE-2025-61882)** — CrowdStrike reports an ongoing campaign beginning in August 2025 that uses an unauthenticated RCE to bypass EBS authentication, upload malicious XSLT templates via XML Publisher, and deploy web shells for data exfiltration and persistence; attribution is assessed with moderate confidence to GRACEFUL SPIDER (linked to Clop), and a publicly leaked PoC has increased the immediate threat, prompting urgent patching and defensive actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
