Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Clop cybercriminals found leveraging an Oracle zero-day vulnerability to obtain private information of company executives

Clop cybercriminals found leveraging an Oracle zero-day vulnerability to obtain private information of company executives

Bitget-RWA2025/10/06 19:03
By:Bitget-RWA

Oracle has addressed a zero-day flaw in one of its leading enterprise software solutions, which a cybercriminal group has been exploiting to obtain confidential details about business executives. 

In a short update posted over the weekend, Oracle’s chief security officer Rob Duhart announced that the company had issued a fresh security patch for its Oracle E-Business Suite and strongly recommended that users apply the update without delay.  

According to the security notice, the vulnerability—cataloged as CVE-2025-61882—can be “abused remotely without requiring authentication.” The advisory included several indicators of compromise to assist Oracle clients in detecting signs of unauthorized access, indicating that attackers are actively leveraging the flaw to extract sensitive information. 

Oracle reports that its E-Business Suite is used by thousands of companies worldwide to manage operations, including storing customer records and employee HR data. 

This vulnerability is classified as a zero-day because Oracle had no opportunity to address it before it was exploited by malicious actors. 

Duhart’s revised statement marks a shift from earlier in the week, when a previous version noted Oracle was aware that some executives “have received extortion emails” related to vulnerabilities fixed in July, implying the extortion activity had ended. The discovery of this new zero-day flaw indicates that attackers continued to take advantage of previously unknown weaknesses in Oracle’s E-Business software. 

Reports about the extortion scheme targeting business leaders surfaced last week.  

On October 2, Google’s security team revealed that the well-known hacking group Clop—associated with various ransomware and extortion incidents—had sent emails to Oracle executives around September 29, threatening to release their personal data online unless paid. 

Charles Carmakal, chief technology officer at Google’s incident response division Mandiant, wrote on LinkedIn Sunday that Oracle’s E-Business Suite vulnerabilities were being exploited in a “large-scale campaign” aimed at data theft and extortion.  

Carmakal noted that much of this malicious activity took place in August, following the release of the July security patches. 

“Clop has been issuing extortion demands to multiple victims since last Monday,” Carmakal stated, but added that not every victim has been contacted by the hackers yet. 

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Solana News Update: Security Breaches and Structural Challenges Cast a Shadow Over Solana's Staking Growth

- Solana (SOL) broke below its November trendline, forming a bear flag pattern suggesting potential price decline toward $100. - Network activity weakened with 20% TVL drop, 16% lower fees, and 6% fewer active addresses, while ETFs saw $8.2M outflow amid security concerns. - The Upbit hack ($36M stolen) triggered liquidity restrictions, causing a 4.9% price drop to $153 despite $336M institutional inflows. - Staking demand (67% supply locked) drives yield-focused capital flows, but stagnant derivatives and

Bitget-RWA2025/11/29 03:28
Solana News Update: Security Breaches and Structural Challenges Cast a Shadow Over Solana's Staking Growth

Stablecoin infrastructure accelerates the integration of conventional and digital financial systems

- A 225M USDT transfer to OKX by a crypto "whale" triggered speculation about market liquidity shifts and regulatory scrutiny. - USDT0's $50B+ cross-chain liquidity protocol reduced stablecoin fragmentation, enabling faster institutional settlements than traditional bridges. - Bitget Wallet's bank integration in Nigeria/Mexico expanded crypto's utility by enabling instant fiat conversions for 80+ banks. - Infrastructure advances like Crossmint-Wirex partnerships enhanced stablecoin security through non-cus

Bitget-RWA2025/11/29 03:28
Stablecoin infrastructure accelerates the integration of conventional and digital financial systems

Astar (ASTR) Price Rally: Rising Interest in Blockchain Infrastructure and Cross-Chain Operations

- Astar (ASTR) surges in 2025 due to institutional adoption, technical upgrades, and cross-chain interoperability. - Its 2.0 upgrade enables 150,000 TPS, scalable to 300,000 via JAM protocol, while dynamic tokenomics balances inflation with burning. - Partnerships with Sony , Toyota , and Japan Airlines drive real-world blockchain applications like tokenized loyalty programs. - Astar maintains $2.38M TVL amid DeFi contraction, leveraging cross-chain infrastructure and enterprise-grade reliability. - Future

Bitget-RWA2025/11/29 03:10
Astar (ASTR) Price Rally: Rising Interest in Blockchain Infrastructure and Cross-Chain Operations

Astar 2.0’s New Direction: Driving DeFi Innovation and Attracting Institutional Participation

- Astar 2.0 introduces fixed-supply tokenomics, interoperability upgrades, and decentralized governance to attract institutional investors and redefine DeFi. - Tokenomics 3.0 caps ASTR supply at 10.5B, reducing inflation risks and aligning with Bitcoin’s scarcity model to boost institutional confidence. - Plaza and Startale App enhance cross-chain asset flows and user accessibility, addressing scalability and onboarding barriers for institutions. - Governance reforms shift to community-driven councils by 2

Bitget-RWA2025/11/29 03:10
Astar 2.0’s New Direction: Driving DeFi Innovation and Attracting Institutional Participation