惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
博客园 - 司徒正美
WordPress大学
WordPress大学
爱范儿
爱范儿
小众软件
小众软件
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
罗磊的独立博客
博客园_首页
V
V2EX
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
Tailwind CSS Blog
大猫的无限游戏
大猫的无限游戏
The Cloudflare Blog
MyScale Blog
MyScale Blog
IT之家
IT之家
H
Help Net Security
Blog — PlanetScale
Blog — PlanetScale
Microsoft Security Blog
Microsoft Security Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
The GitHub Blog
The GitHub Blog
Y
Y Combinator Blog
人人都是产品经理
人人都是产品经理

The Register - Security: CSO

Anthropic's Mythos has The Kettle crew curious, skeptical 'People's Panel' to check if UK wants controversial Digital ID will cost £630K Top npm package backdoored to drop dirty RAT on dev machines Lightning-fast exploits mean patch fast, says Cisco Talos Lightning-fast exploits mean patch fast, says Cisco Talos Smooth criminals talking their way into cloud environments, Google says Cybercrime up 245% since the start of the Iran war Scattered Lapsus$ Hunters seeks women to defraud helpdesks Every day in every way, passwords are getting worse CISA quietly updated ransomware flags on 59 flaws last year Deepfake job seeker applied to work for an AI security firm Deepfake job seeker applied to work for an AI security firm AI-powered cyberattack kits are 'just a matter of time' AI-powered cyberattack kits are 'just a matter of time' FortiGate SSO bug still exploitable despite December patch FortiGate SSO bug still exploitable despite December patch Judge tosses CrowdStrike shareholder suit over 2024 outage DRAM shortage may drive firewall prices higher: analysts Ransomware attacks kept climbing in 2025 as gangs refused to stay dead Around 1,000 systems compromised in ransomware attack on Romanian water agency 1,000 systems pwned in Romanian Waters ransomware attack Half of exposed React servers remain unpatched amid attacks CISA warns spyware crews are breaking into Signal and WhatsApp accounts FCC guts Salt Typhoon telco rules despite espionage risk SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere SEC bails on SolarWinds lawsuit Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood Palo Alto kit sees massive surge in malicious activity Countries use cyber targeting to plan strikes: Amazon CSO Overconfidence is the new zero-day as teams stumble through cyber simulations
CISA orders feds to patch Oracle Identity Manager zero-day
Carly Page Carly Page · 2025-11-24 · via The Register - Security: CSO

CSO

CISA orders feds to patch Oracle Identity Manager zero-day after signs of abuse

Agencies have until December 12 to mitigate flaw that was likely exploited before Big Red released fix

CISA has ordered US federal agencies to patch against an actively exploited Oracle Identity Manager (OIM) flaw within three weeks – a scramble made more urgent by evidence that attackers may have been abusing the bug months before a fix was released.

The flaw, tracked as CVE-2025-61757 and now sitting in CISA's Known Exploited Vulnerabilities catalog, is "easily exploitable" and allows an unauthenticated attacker with network access to compromise OIM, enabling a full takeover of the system.

"Oracle Fusion Middleware contains a missing authentication for a critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager," CISA warned.

Agencies have been told to patch the vulnerability by December 12 or face the usual federal compliance consequences.

Searchlight Cyber researchers Adam Kues and Shubham Shah, who discovered the flaw, have published their own technical teardown of the vulnerability that doesn't mince words about the ease with which criminals can weaponize it.

The researchers call exploitation "trivial," describing a single HTTP request that bypasses OIM's normal authentication flow and ultimately gives an attacker remote system-level control. Oracle disclosed the bug in October, but didn't indicate that it was under active exploitation.

However, analysis from SANS ISC dean Johannes Ullrich suggests attackers may have known about the flaw long before Oracle did. In traffic logs Ullrich reviewed, the telltale OIM exploit URL appeared repeatedly between August 30 and September 9 – weeks before Oracle released a patch on October 21. 

"This URL was accessed several times between August 30 and September 9 this year, well before Oracle patched the issue," Ullrich wrote. "There are several different IP addresses scanning for it, but they all use the same user agent, which suggests that we may be dealing with a single attacker."

While the logs don't confirm successful compromise, they show unmistakable pre-patch reconnaissance for the vulnerability, making a credible case that CVE-2025-61757 was used as zero-day by at least one threat actor.

CISA's alert doesn't provide detail on how the flaw is being exploited in the wild, but the timing lands awkwardly for Oracle. The company is reeling from Clop's raid on Oracle E-Business Suite environments earlier this year, compromising dozens of organizations, including insurance giant Allianz UK and Bezos-owned newspaper The Washington Post.

That incident underscored the stakes when enterprise Oracle platforms fall behind on updates –  and raised fresh questions about lagging customer patch cycles and the opaque nature of Oracle's vulnerability disclosures.

Oracle did not respond to The Register's request for comment on whether it had confirmed in-the-wild exploitation prior to CISA's advisory, or had received any customer reports of incidents linked to CVE-2025-61757. The vendor's October advisory rated the issue critical but made no mention of zero-day activity or exploitation telemetry.

Fixing the flaw requires applying Oracle's October 21 Critical Patch Update, which shipped with dozens of other fixes. For federal agencies now staring at a December 12 deadline, along with the combination of confirmed exploitation, credible zero-day evidence, and Oracle's characteristically sparse patch notes, it's looking like another frantic month for already stretched security teams. ®