logo

Oracles silently fixes zero-day exploit leaked by ShinyHunters

ID: fd6fb1db-4bac-5205-80ec-c45c046b9979

STIX ID: report--fd6fb1db-4bac-5205-80ec-c45c046b9979

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-10-14

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

Oracle E-Business Suite was found to contain multiple remotely exploitable flaws (CVE-2025-61882 and CVE-2025-61884) that were actively exploited or tied to extortion campaigns; a proof-of-concept exploit was leaked by ShinyHunters and Clop-linked activity led to data theft extortion. Oracle released out-of-band patches addressing the issues, but advisory details and IOCs were confusingly mismatched, prompting researchers to confirm that the SSRF component was fixed only after the CVE-2025-61884 update; customers are strongly advised to install the latest updates or apply temporary mod_security rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.