Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Clop cybercriminals found leveraging an Oracle zero-day vulnerability to obtain private information of company executives

Clop cybercriminals found leveraging an Oracle zero-day vulnerability to obtain private information of company executives

Bitget-RWA2025/10/06 19:03
By:Bitget-RWA

Oracle has addressed a zero-day flaw in one of its leading enterprise software solutions, which a cybercriminal group has been exploiting to obtain confidential details about business executives. 

In a short update posted over the weekend, Oracle’s chief security officer Rob Duhart announced that the company had issued a fresh security patch for its Oracle E-Business Suite and strongly recommended that users apply the update without delay.  

According to the security notice, the vulnerability—cataloged as CVE-2025-61882—can be “abused remotely without requiring authentication.” The advisory included several indicators of compromise to assist Oracle clients in detecting signs of unauthorized access, indicating that attackers are actively leveraging the flaw to extract sensitive information. 

Oracle reports that its E-Business Suite is used by thousands of companies worldwide to manage operations, including storing customer records and employee HR data. 

This vulnerability is classified as a zero-day because Oracle had no opportunity to address it before it was exploited by malicious actors. 

Duhart’s revised statement marks a shift from earlier in the week, when a previous version noted Oracle was aware that some executives “have received extortion emails” related to vulnerabilities fixed in July, implying the extortion activity had ended. The discovery of this new zero-day flaw indicates that attackers continued to take advantage of previously unknown weaknesses in Oracle’s E-Business software. 

Reports about the extortion scheme targeting business leaders surfaced last week.  

On October 2, Google’s security team revealed that the well-known hacking group Clop—associated with various ransomware and extortion incidents—had sent emails to Oracle executives around September 29, threatening to release their personal data online unless paid. 

Charles Carmakal, chief technology officer at Google’s incident response division Mandiant, wrote on LinkedIn Sunday that Oracle’s E-Business Suite vulnerabilities were being exploited in a “large-scale campaign” aimed at data theft and extortion.  

Carmakal noted that much of this malicious activity took place in August, following the release of the July security patches. 

“Clop has been issuing extortion demands to multiple victims since last Monday,” Carmakal stated, but added that not every victim has been contacted by the hackers yet. 

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Zcash Latest Updates: Crypto in 2025—The Paradox of Progress Amid Rising Regulatory and Security Hurdles

- Grayscale's Zcash ETF filing highlights growing institutional interest in privacy coins, with ZEC surging over 1,000% year-to-date. - BNB's price decline below $900 contrasts with Zcash's rise, exposing divergent crypto market dynamics between privacy and utility tokens. - Securitize's EU-approved tokenized securities platform on Avalanche aims to digitize $18 trillion in assets by 2033, pending regulatory alignment. - ALT5's volatile treasury model and Upbit's $36M hack underscore 2025's dual-edged inno

Bitget-RWA2025/11/30 21:46
Zcash Latest Updates: Crypto in 2025—The Paradox of Progress Amid Rising Regulatory and Security Hurdles

The Influence of City Infrastructure Funding on the Value of Commercial Properties: Insights from Webster, NY

- Webster , NY, transformed a 300-acre brownfield into a high-tech industrial hub using FAST NY and BOA grants. - Infrastructure upgrades like road realignment and power modernization boosted industrial demand, slashing vacancy rates to 2%. - Public-private partnerships enabled $650M projects like fairlife® dairy, creating 250 jobs and raising residential property values by 10.1%. - Strategic rezoning and wastewater upgrades diversified Webster’s economy, positioning it as a logistics hub near Buffalo’s tr

Bitget-RWA2025/11/30 21:44
The Influence of City Infrastructure Funding on the Value of Commercial Properties: Insights from Webster, NY

GeeFi’s Practical Ecosystem Challenges Avalanche’s Speculative Ambitions

- Avalanche (AVAX) fell to $14.94, with short-term volatility and long-term $326/2031 forecasts, contrasting GeeFi (GEE)'s $0.05 presale surge. - GeeFi's $300K+ presale (6.2M tokens sold) highlights its 3,900% ROI potential via a multi-chain wallet and 55% APR staking. - GEE's deflationary model and real-world crypto tools (DEX, spending card) challenge AVAX's speculative reliance on network upgrades. - With 80% Phase 1 completion and 700+ investors, GeeFi's urgency contrasts Avalanche's stagnant $13–$14 s

Bitget-RWA2025/11/30 21:32
GeeFi’s Practical Ecosystem Challenges Avalanche’s Speculative Ambitions

PENGU Token's Technical Surge and Changing Market Sentiment: A Brief Momentum Opportunity Among Altcoins

- PENGU Token offers high-risk, high-reward potential for short-term momentum traders, driven by technical indicators and ecosystem growth. - Structural risks like regulatory uncertainty and declining NFT demand pose significant challenges to its volatility-driven strategy. - Traders are advised to use tight stop-loss orders and position sizing, treating PENGU as a speculative, short-term play. - The upcoming Cboe ETF decision will be pivotal in determining PENGU's transition from volatile altcoin to viabl

Bitget-RWA2025/11/30 21:28