Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Clop cybercriminals found leveraging an Oracle zero-day vulnerability to obtain private information of company executives

Clop cybercriminals found leveraging an Oracle zero-day vulnerability to obtain private information of company executives

Bitget-RWA2025/10/06 19:03
By:Bitget-RWA

Oracle has addressed a zero-day flaw in one of its leading enterprise software solutions, which a cybercriminal group has been exploiting to obtain confidential details about business executives. 

In a short update posted over the weekend, Oracle’s chief security officer Rob Duhart announced that the company had issued a fresh security patch for its Oracle E-Business Suite and strongly recommended that users apply the update without delay.  

According to the security notice, the vulnerability—cataloged as CVE-2025-61882—can be “abused remotely without requiring authentication.” The advisory included several indicators of compromise to assist Oracle clients in detecting signs of unauthorized access, indicating that attackers are actively leveraging the flaw to extract sensitive information. 

Oracle reports that its E-Business Suite is used by thousands of companies worldwide to manage operations, including storing customer records and employee HR data. 

This vulnerability is classified as a zero-day because Oracle had no opportunity to address it before it was exploited by malicious actors. 

Duhart’s revised statement marks a shift from earlier in the week, when a previous version noted Oracle was aware that some executives “have received extortion emails” related to vulnerabilities fixed in July, implying the extortion activity had ended. The discovery of this new zero-day flaw indicates that attackers continued to take advantage of previously unknown weaknesses in Oracle’s E-Business software. 

Reports about the extortion scheme targeting business leaders surfaced last week.  

On October 2, Google’s security team revealed that the well-known hacking group Clop—associated with various ransomware and extortion incidents—had sent emails to Oracle executives around September 29, threatening to release their personal data online unless paid. 

Charles Carmakal, chief technology officer at Google’s incident response division Mandiant, wrote on LinkedIn Sunday that Oracle’s E-Business Suite vulnerabilities were being exploited in a “large-scale campaign” aimed at data theft and extortion.  

Carmakal noted that much of this malicious activity took place in August, following the release of the July security patches. 

“Clop has been issuing extortion demands to multiple victims since last Monday,” Carmakal stated, but added that not every victim has been contacted by the hackers yet. 

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Dogecoin News Today: Dogecoin ETFs Indicate Growing Interest from Institutions, Yet Can the Meme Coin Demonstrate Its Value?

- U.S. Dogecoin ETFs (BWOW, GDOG) launched amid mixed market reactions, with GDOG's $1.4M debut volume far below $12M forecasts. - Both ETFs hold actual Dogecoin but lack 1940 Act registration, exposing investors to liquidity risks and regulatory uncertainty. - Market analysts cite Dogecoin's volatility, meme origins, and descending price patterns as barriers to mainstream adoption. - Fee structures (0.34-0.35%) and regulatory ambiguity highlight challenges in monetizing meme coins despite institutional in

Bitget-RWA2025/11/29 19:04
Dogecoin News Today: Dogecoin ETFs Indicate Growing Interest from Institutions, Yet Can the Meme Coin Demonstrate Its Value?

Australia's Cryptocurrency Reform Strikes a Balance Between Fostering Innovation and Safeguarding Investors

- Australia introduces 2025 Digital Assets Framework Bill to regulate crypto exchanges and custody providers under stricter licensing and ASIC oversight, aiming to protect investors and align with traditional finance standards. - The bill classifies operators into "digital asset platforms" and "tokenized custody platforms," with exemptions for small operators under A$5,000 per customer and A$10M annual transactions. - An 18-month transition period and potential A$24B annual productivity gains are expected,

Bitget-RWA2025/11/29 19:04
Australia's Cryptocurrency Reform Strikes a Balance Between Fostering Innovation and Safeguarding Investors

ZK Pumping: How Infrastructure Grants Propel Expansion in Real Estate and Technology Sectors

- Webster , NY's $9.8M FAST NY grant transforms a 300-acre Xerox brownfield into a high-tech industrial hub via infrastructure upgrades. - The project reduces development barriers, attracting $650M private investments like the fairlife® dairy plant and boosting property values by up to 30%. - Tech integration, including blockchain-based traffic systems, positions Webster as a model for linking physical and digital infrastructure in industrial growth. - "ZK Pumping" demonstrates how strategic infrastructure

Bitget-RWA2025/11/29 19:02
ZK Pumping: How Infrastructure Grants Propel Expansion in Real Estate and Technology Sectors

Bitcoin Updates Today: Assessing Bitcoin's Support Zones—Will Institutional Investments Surpass Federal Reserve Ambiguity?

- Bitcoin faces critical $84,000–$86,000 support after 31% November selloff, with institutional inflows and whale accumulation signaling ongoing bull cycle resilience. - JPMorgan upgrades miners like Cipher Mining amid rising HPC demand, while Fed rate-cut odds hit 71% for December, potentially boosting risk assets. - On-chain data shows historic BTC transfers to long-term holdings, contrasting with Binance's delistings and regulatory-driven liquidity management efforts. - 2025–2030 price forecasts range $

Bitget-RWA2025/11/29 18:50
Bitcoin Updates Today: Assessing Bitcoin's Support Zones—Will Institutional Investments Surpass Federal Reserve Ambiguity?