Critical Alert: Attack Exploits Vulnerability in Oracle E-Business Suite Triggering Emergency Patches

A collaboration between the Google Threat Intelligence Group (GTIG) and Mandiant has revealed an alarming extortion campaign that exploits a zero-day vulnerability in Oracle E-Business Suite (EBS). The group responsible, which shows affinity with the well-known CL0P brand, has carried out months of silent intrusion and data exfiltration, culminating in a series of extortion emails addressed to executives in several sectors beginning on September 29, 2025. Oracle has responded by publishing emergency patches and urges that they be applied immediately.

The vulnerability, identified as CVE-2025-61882 with a CVSS score of 9.8, has been exploited since July 2025. The main objective has been to access Oracle EBS, a critical platform for finance, purchasing, human resources, and operations. The extortion campaign has used emails sent from compromised accounts, displaying real lists of stolen files to lend credibility to their demands.

The intrusion method was carried out through two vulnerabilities in EBS: UiServlet and SyncServlet, which allowed remote code execution without requiring authentication. Once inside, the attackers used a set of sophisticated tools, including the GOLDVEIN.JAVA variant, to connect to command-and-control (C2) servers and deploy additional payloads.

The campaign poses a serious risk due to access to critical data stored in EBS, the use of in-memory payloads that hinder detection by security systems, and CL0P's ability to carry out large-scale repeated attacks.

In light of this threat, experts recommend immediate measures: apply the emergency patches, audit XDO templates to detect unusual activities, limit Internet access from EBS servers, intensify monitoring, and be prepared to respond to extortion situations.

The situation underscores the importance of rapid patching and of being alert to indicators of compromise to mitigate any potential damage and protect critical information.

More information and references in Cloud News.

Silvia Pastor
Silvia Pastor
Silvia Pastor is a prominent journalist for Noticias.Madrid, specializing in investigative journalism. Her daily work includes covering important events in the capital, writing current affairs articles, and producing audiovisual segments. Silvia conducts interviews with key figures, provides expert analysis, and maintains an active presence on social media, sharing her articles and providing real-time updates. Her professional approach, focused on truthfulness, objectivity, and journalistic ethics, makes her a reliable source of information for her audience.

More popular

More articles like this one.
Relacionados

Tragedia en Murcia: Hombre presuntamente asesina a su novia de 19 años en su hogar

Una joven de 19 años fue hallada muerta en...

Lando Norris Resplandece en México y Toma las Riendas del Campeonato Mundial

El piloto británico logró una victoria impresionante, cruzando la..

Norris Triunfa en México; Verstappen Llega Imparable | Fórmula 1 | Deportes

McLaren ha estado enfrentando una situación inesperada en el...

Formula 1 Live: Results and Latest News from the Mexican Grand Prix

The Formula One Mexican Grand Prix...
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.