Close Menu
TechUpdateAlert

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why

    December 22, 2025

    You can now buy the OnePlus 15 in the US and score free earbuds if you hurry

    December 22, 2025

    Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455

    December 22, 2025
    Facebook X (Twitter) Instagram
    Trending
    • My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why
    • You can now buy the OnePlus 15 in the US and score free earbuds if you hurry
    • Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455
    • Android might finally stop making you tap twice for Wi-Fi
    • Today’s NYT Mini Crossword Answers for Dec. 22
    • Waymo’s robotaxis didn’t know what to do when a city’s traffic lights failed
    • Today’s NYT Wordle Hints, Answer and Help for Dec. 22 #1647
    • You Asked: OLED Sunlight, VHS on 4K TVs, and HDMI Control Issues
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechUpdateAlertTechUpdateAlert
    • Home
    • Gaming
    • Laptops
    • Mobile
    • Software
    • Reviews
    • AI & Tech
    • Gadgets
    • How-To
    TechUpdateAlert
    Home»How-To»Oracle forced to rush out patch for zero-day exploited in attacks
    How-To

    Oracle forced to rush out patch for zero-day exploited in attacks

    techupdateadminBy techupdateadminOctober 6, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Oracle
    Share
    Facebook Twitter LinkedIn Pinterest Email


    • Oracle patched a critical zero-day RCE flaw in E-Business Suite, actively exploited by ransomware actors
    • Attackers used compromised email accounts to extort victims; FIN11 and Cl0p may be involved
    • CVE-2025-61882 scored 9.8/10; exploitation requires no authentication and enables full system takeover

    Oracle has released a patch to address a zero-day vulnerability in its E-Business Suite which was being actively exploited by ransomware actors.

    In early October 2025, cybercriminals started mailing executives at various American organizations, claiming to have stolen sensitive files from their Oracle E-Business Suite systems. At the time, both Oracle and the wider cybersecurity community were not certain if the breaches actually happened, or if this was just a bluff to get the victims to pay a ransom demand.

    Now, it seems the claims were legitimate since Oracle issued an emergency patch to fix a critical unauthenticated remote code execution (RCE) flaw in E-Business Suite versions 12.2.3-12.2.14.


    You may like

    Payment data secure

    The bug is tracked as CVE-2025-61882, and was given a severity score of 9.8/10 (critical). An unauthenticated attacker with HTTP network access could use it to compromise, and fully take over, the Oracle Concurrent Processing component of E-Business Suite.

    “This vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password,” Oracle said in the advisory. “If successfully exploited, this vulnerability may result in remote code execution.”

    Earlier reports linked the campaign to multiple threat actors, including the infamous Cl0p, and a financially motivated actor called FIN11.

    Charles Carmakal, CTO of Mandiant – Google Cloud, said the emails are being sent from hundreds of compromised email accounts – including one known to belong to FIN11: “We are currently observing a high-volume email campaign being launched from hundreds of compromised accounts and our initial analysis confirms that at least one of these accounts has been previously associated with activity from FIN11, a long-running financially motivated threat group known for deploying ransomware and engaging in extortion,” Carmakal said.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    At the same time, the emails held contact addresses that were previously listed on Cl0p’s data leak site, so it is possible that both groups are involved in the campaign, or are simply sharing resources. The evidence is not compelling enough to confirm the links, though.

    Oracle’s Indicators of Compromise (IoC), published with the advisory, also suggest the involvement of Scattered Lapsus$ Hunters.

    Via The Hacker News


    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

    You might also like

    Attacks exploited forced Oracle patch Rush zeroday
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleAMD lands multi-billion dollar AI partnership with OpenAI
    Next Article Point and click horror game Endacopia is carrying on Petscop’s legacy of serving up unnerving and confusing adventures
    techupdateadmin
    • Website

    Related Posts

    Gadgets

    LG forced a Copilot web app onto its TVs but will let you delete it

    December 19, 2025
    Gaming

    Nightreign’s new patch fixes the most annoying part about prepping for its toughest bosses

    December 3, 2025
    Gaming

    Cloudflare says DDoS attacks have multiplied to 1.7x last year’s count and at points there’s been about one attempt every second

    December 3, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    NYT Strands hints and answers for Monday, August 11 (game #526)

    August 11, 202545 Views

    These 2 Cities Are Pushing Back on Data Centers. Here’s What They’re Worried About

    September 13, 202542 Views

    Today’s NYT Connections: Sports Edition Hints, Answers for Sept. 4 #346

    September 4, 202540 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Best Fitbit fitness trackers and watches in 2025

    July 9, 20250 Views

    There are still 200+ Prime Day 2025 deals you can get

    July 9, 20250 Views

    The best earbuds we’ve tested for 2025

    July 9, 20250 Views
    Our Picks

    My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why

    December 22, 2025

    You can now buy the OnePlus 15 in the US and score free earbuds if you hurry

    December 22, 2025

    Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455

    December 22, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2026 techupdatealert. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.