Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Clop cybercriminals found leveraging an Oracle zero-day vulnerability to obtain private information of company executives

Clop cybercriminals found leveraging an Oracle zero-day vulnerability to obtain private information of company executives

Bitget-RWA2025/10/06 19:03
By:Bitget-RWA

Oracle has addressed a zero-day flaw in one of its leading enterprise software solutions, which a cybercriminal group has been exploiting to obtain confidential details about business executives. 

In a short update posted over the weekend, Oracle’s chief security officer Rob Duhart announced that the company had issued a fresh security patch for its Oracle E-Business Suite and strongly recommended that users apply the update without delay.  

According to the security notice, the vulnerability—cataloged as CVE-2025-61882—can be “abused remotely without requiring authentication.” The advisory included several indicators of compromise to assist Oracle clients in detecting signs of unauthorized access, indicating that attackers are actively leveraging the flaw to extract sensitive information. 

Oracle reports that its E-Business Suite is used by thousands of companies worldwide to manage operations, including storing customer records and employee HR data. 

This vulnerability is classified as a zero-day because Oracle had no opportunity to address it before it was exploited by malicious actors. 

Duhart’s revised statement marks a shift from earlier in the week, when a previous version noted Oracle was aware that some executives “have received extortion emails” related to vulnerabilities fixed in July, implying the extortion activity had ended. The discovery of this new zero-day flaw indicates that attackers continued to take advantage of previously unknown weaknesses in Oracle’s E-Business software. 

Reports about the extortion scheme targeting business leaders surfaced last week.  

On October 2, Google’s security team revealed that the well-known hacking group Clop—associated with various ransomware and extortion incidents—had sent emails to Oracle executives around September 29, threatening to release their personal data online unless paid. 

Charles Carmakal, chief technology officer at Google’s incident response division Mandiant, wrote on LinkedIn Sunday that Oracle’s E-Business Suite vulnerabilities were being exploited in a “large-scale campaign” aimed at data theft and extortion.  

Carmakal noted that much of this malicious activity took place in August, following the release of the July security patches. 

“Clop has been issuing extortion demands to multiple victims since last Monday,” Carmakal stated, but added that not every victim has been contacted by the hackers yet. 

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Bitcoin News Update: Growing Optimism Faces ETF Withdrawals: The Delicate Balance of Crypto Stability

- Crypto markets show fragile stabilization as Fear & Greed Index rises to 20, but Bitcoin remains 30% below October peaks amid $3.5B ETF outflows. - Stablecoin market cap drops $4.6B and on-chain volumes fall below $25B/day, weakening Bitcoin's liquidity absorption capacity. - Select altcoins like Kaspa (22%) and Ethena (16%) gain traction while BlackRock's IBIT returns $3.2B profits, signaling mixed institutional confidence. - Technical indicators suggest tentative support at $100,937 for Bitcoin, but So

Bitget-RWA2025/11/28 05:32
Bitcoin News Update: Growing Optimism Faces ETF Withdrawals: The Delicate Balance of Crypto Stability

BCH Rises 0.09% as Momentum Fuels Outperformance

- BCH rose 0.09% in 24 hours but fell 4.22% in seven days, yet gained 22.72% annually. - It outperformed its Zacks Banks - Foreign sector with 0.66% weekly gains vs. -2.46% industry decline. - Earnings estimates rose twice in two months, boosting consensus from $2.54 to $2.56. - With a Zacks Rank #2 (Buy) and Momentum Score B, BCH shows strong momentum potential. - Annual 63.46% gains and positive revisions solidify its position as a top momentum stock.

Bitget-RWA2025/11/28 05:26
BCH Rises 0.09% as Momentum Fuels Outperformance

DOGE drops 1.36% as Bitwise ETF debuts

- Bitwise launched the first Dogecoin ETF (BWOW) on NYSE, offering institutional-grade exposure to the memecoin. - DOGE fell 1.36% in 24 hours but rose 7.34% weekly, reflecting mixed short-term market sentiment. - The ETF aligns with growing institutional adoption and regulatory momentum for altcoins, despite a 52.35% annual decline. - Similar products like Bonk’s ETP and Ethereum upgrades highlight maturing crypto infrastructure and investor demand.

Bitget-RWA2025/11/28 05:26
DOGE drops 1.36% as Bitwise ETF debuts

ZEC Falls 4.01% After Grayscale Submits Zcash ETF Conversion Application

- Zcash (ZEC) fell 4.01% in 24 hours as Grayscale files to convert its Zcash Trust into an ETF. - The ETF conversion aims to boost institutional exposure and regulated market access for ZEC. - ZEC shows 16.26% monthly gain and 736.04% annual rise despite recent 17.89% weekly drop. - Analysts highlight ETF approval could stabilize ZEC’s price and attract diversified investors. - The SEC’s decision on the ETF remains pending, shaping market perceptions and ZEC’s adoption trajectory.

Bitget-RWA2025/11/28 05:26
ZEC Falls 4.01% After Grayscale Submits Zcash ETF Conversion Application