CISA confirms hackers exploited Oracle E-Business Suite SSRF flaw
ID: 5c50964d-80d7-5d6d-8d85-08813a23fef4
STIX ID: report--5c50964d-80d7-5d6d-8d85-08813a23fef4
Feed Name: Bleeping Computer
### Executive summary CISA confirmed active exploitation of Oracle E-Business Suite CVE-2025-61884 (an unauthenticated SSRF) tied to a leaked exploit used in July attacks; Oracle issued a patch and federal agencies are required to remediate by November 10, 2025. Investigations link distinct July and August campaigns (the July campaign exploited the UiServlet SSRF; the August campaign targeted SyncServlet and is attributed to Clop), and reporting highlights disputed IOC attribution and public leaks by ShinyHunters with associated extortion activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
