Oracle patches EBS zero-day exploited in Clop data theft attacks
ID: ca67189c-d1b0-5aa1-88a1-c00039951340
STIX ID: report--ca67189c-d1b0-5aa1-88a1-c00039951340
Feed Name: Bleeping Computer
Threat Score
Oracle disclosed a critical unauthenticated RCE zero-day in Oracle E-Business Suite (CVE-2025-61882, CVSS 9.8) that has been actively exploited by the Clop ransomware group in large-scale data theft/extortion; Oracle published emergency updates and indicators of compromise while exploit code and related Oracle source data were leaked to the public by other threat actors, substantially increasing the risk of further compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
