Emergency patch for vulnerability in Oracle E-Business Suite
Critical Oracle E-Business Suite vulnerability CVE-2025-61884 allows unauthenticated attackers to disclose sensitive data across EBS versions 12.2.3–12.2.14; urgent patching recommended.
Sophisticated Malware Deployed in Oracle EBS Zero-Day Attacks
Attackers exploited Oracle E-Business Suite, including CVE-2025-61882, to deploy malware such as GoldVein.Java and deliver second-stage payloads for extortion.
Clop raid on Oracle EBS started months ago, say researchers
Clop exploited multiple Oracle E-Business Suite vulnerabilities since August 2025, stole data, sent extortion demands, and public proof-of-concept exploit code now enables widespread attacks.
Cl0p-linked actors actively exploit a critical Oracle E-Business Suite zero-day for large-scale data theft while stealthy groups use compromised WordPress sites to deliver information-stealers.
Update on the emerging CL0P extortion campaign targeting Oracle E-Business Suite - DataBreaches.Net
CL0P exploited CVE-2025-61882 to exfiltrate large volumes of Oracle E-Business Suite data; apply Oracle patches and investigate for historical compromise.