惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
IT之家
IT之家
博客园_首页
博客园 - 【当耐特】
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
G
Google Developers Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
GbyAI
GbyAI
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
I
InfoQ
H
Help Net Security
T
Tailwind CSS Blog
B
Blog RSS Feed
Martin Fowler
Martin Fowler
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
博客园 - 叶小钗
雷峰网
雷峰网
量子位

The Register - Security: Patches

Homeland security cybercops say patch TrueConf (Russia Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update Year-long Russian attacks infect users as soon as they look at an email Cisco SD-WAN make-me-root bug under attack Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 AI is making Patch Tuesday (kinda) fun again Anthropic to release Mythos-class models to the public Clear your calendar, Drupal user: You have a critically urgent patch to install Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Critical cPanel, WHM flaw probs exploited as 0-day, pros say Microsoft patch fell short. New Windows flaw exploited More Cisco SD-WAN bugs battered in attacks Critical Fortinet sandbox bugs allow auth bypass and RCE Ancient Excel bug comes out of retirement for active attacks Microsoft's massive Patch Tuesday: It's raining bugs Ransomware scum, other crims exploit 4 old Microsoft bugs Attackers exploited the FortiClient EMS bug as a 0-day Citrix NetScaler bug may be multiple flaws in one Ransomware crims abused Cisco 0-day weeks before disclosure Google rushes Chrome update to fix zero-days under attack CISA warns max-severity n8n bug is being exploited in the wild Cisco warns of two more SD-WAN bugs under active attack LexisNexis Legal & Professional confirms data breach Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover Patch these 4 critical, make-me-root SolarWinds bugs ASAP Attacker gets into France's DB listing all bank accounts CISA gives feds 3 days to patch actively exploited Dell bug CISA gives feds 3 days to patch actively exploited Dell bug Google fixes exploited Chrome CSS zero-day
Oracle rushes out another emergency E-Business Suite patch
Carly Page Carly Page · 2025-10-14 · via The Register - Security: Patches

Patches

Oracle rushes out another emergency E-Business Suite patch as Clop fallout widens

Latest in a long line of EBS flaws leta miscreants remotely compromise enterprise systems to pinch sensitive data

Oracle is rushing out another emergency patch for its embattled E-Business Suite as the fallout from the Clop-linked attacks continues to spread.

The newly disclosed flaw, tracked as CVE-2025-61884 and slapped with a CVSS score of 7.5, affects the Runtime UI component in EBS, and Oracle's advisory warns that the flaw can be exploited remotely without authentication and "may allow access to sensitive resources."

In other words, it's another wide-open door into one of Oracle's most business-critical systems, and the kind of bug that cybercrims love to chain with others for data theft, extortion, or to delve deeper into enterprise networks.

"This vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password," Oracle said. "Oracle strongly recommends that customers apply the updates or mitigations provided by this Security Alert as soon as possible."

Big Red hasn't said whether the bug has been used in the wild or if it's tied to the same campaign that's already claimed victims from universities to major enterprises.

Oracle has yet to respond to The Register's questions.

The patch arrives a week after Oracle rushed out a fix for a nastier zero-day in the same suite, one that let attackers run code without logging in and has been tied to the ongoing Clop-linked hacking spree.

Google's Threat Intelligence Group said at the time it was aware of "dozens" of confirmed victims but expected the real number to exceed a hundred. The campaign is believed to have started months before Oracle's first fix, with attackers quietly probing EBS environments as early as July. Researchers warned that the crooks were likely chaining multiple bugs together, leaving even recently updated installations at risk if earlier fixes weren't properly applied.

While Oracle hasn't said whether this latest flaw is part of the same exploit chain, the timing raises eyebrows. The bug may have surfaced during Oracle's own post-mortem into the Clop campaign, as engineers dug through compromised systems to see just how deep the damage went – and what else might still be lurking under the hood.

Adding to the excess, Harvard University has confirmed it's investigating a cybersecurity incident apparently linked to the Oracle EBS breaches. The university said the intrusion affected "a limited number of parties associated with a small administrative unit," adding that relevant Oracle patches have since been applied. 

Whether this latest flaw represents a new front in the same campaign or simply the next in a series of overdue discoveries remains unanswered. What's certain is that Oracle's E-Business Suite has become the latest weekend wrecker for enterprise admins – and the party's nowhere near over. ®