Oracle E-Business Suite Hit by Critical Zero-Day Ransomware Attack
Cybersecurity Dive
|
Contributed by: Kate Gamble
Summary
A recent extortion campaign targeting Oracle E-Business Suite customers has been linked to a zero-day vulnerability (CVE-2025-61882) with a critical severity score of 9.8, allowing unauthenticated attackers to remotely control the system’s processing components. The Clop ransomware group has been sending threatening communications to company executives, urging immediate action to mitigate the threat. In response, Oracle emphasized the importance of updating to a critical patch released in July, as the vulnerability is part of a broader, sophisticated attack strategy that exploits multiple weaknesses. This incident underscores the urgent need for healthcare organizations using Oracle systems to prioritize cybersecurity measures to protect sensitive data.