logo

Oracle silently fixes zero-day exploit leaked by ShinyHunters

ID: fe8aa1b1-304b-58ac-a254-209a60880d31

STIX ID: report--fe8aa1b1-304b-58ac-a254-209a60880d31

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-10-14

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

Oracle E-Business Suite suffered multiple serious vulnerabilities (CVE-2025-61882 and CVE-2025-61884) that were actively exploited or subject to public proof-of-concept leaks; Clop extortion emails and a ShinyHunters-released exploit were linked to these issues. Oracle released out-of-band patches (including fixes that validate return_url to block SSRF and mod_security rules for SyncServlet) but advisories contained mismatched IOCs and incomplete disclosure. Organizations using Oracle EBS are strongly advised to apply the October emergency updates immediately or, as a temporary mitigation, add mod_security rules to block /configurator/UiServlet and related endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.