Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Oracle Confirms that Hackers Targeting E-Business Suite Data With Extortion Emails

Oracle Confirms that Hackers Targeting E-Business Suite Data With Extortion Emails

Posted on October 3, 2025October 3, 2025 By CWS

Oracle Company has formally acknowledged that cybercriminals are focusing on clients of its E-Enterprise Suite (EBS) platform by means of refined extortion campaigns. 

The corporate’s Chief Safety Officer, Rob Duhart, confirmed that hackers have been exploiting beforehand recognized vulnerabilities that had been addressed in Oracle’s July 2025 Important Patch Replace (CPU). 

This newest safety incident underscores the persistent risk panorama going through enterprise functions and highlights the crucial significance of well timed safety patch deployment.

Oracle E-Enterprise Suite Prospects Focused

Bloomberg acknowledged that the cybercriminal group, claiming affiliation with the infamous Cl0p ransomware group, has been conducting a extremely coordinated assault marketing campaign towards Oracle E-Enterprise Suite installations. 

In keeping with cybersecurity agency Halcyon, the risk actors have demonstrated refined techniques, methods, and procedures (TTPs) by compromising person e-mail accounts and exploiting default password-reset capabilities to acquire legitimate credentials for internet-facing Oracle EBS portals.

The attackers have offered victims with proof of compromise, together with detailed screenshots and file tree buildings demonstrating unauthorized entry to delicate company knowledge. 

In at the very least one documented case, the extortion calls for reached as excessive as $50 million, representing one of many largest ransom calls for noticed in latest cybercriminal campaigns. 

The risk actors started distributing extortion emails on or earlier than September 29, 2025, utilizing tons of of compromised third-party e-mail accounts to evade detection mechanisms.

Oracle’s E-Enterprise Suite, which manages crucial enterprise capabilities together with monetary administration, provide chain operations, and buyer relationship administration (CRM), has turn into a pretty goal as a result of its in depth deployment throughout massive organizations. 

The vulnerability exploitation seems to leverage beforehand recognized safety flaws that had been patched in Oracle’s July 2025 Important Patch Replace, particularly addressing CVE identifiers associated to authentication bypass and privilege escalation assaults.

Genevieve Stark, head of cybercrime at Google Risk Intelligence Group, confirmed that the extortion emails include contact particulars matching these listed on Cl0p’s official darkish net infrastructure. 

The risk group’s modus operandi contains attribute grammatical errors and linguistic patterns per earlier Cl0p operations, together with their notorious 2023 MOVEit marketing campaign that compromised over 3,000 organizations in america and eight,000 globally.

Oracle has reiterated its robust suggestion for the instant deployment of the newest Important Patch Updates, emphasizing that organizations sustaining present safety patch ranges considerably scale back their assault floor. 

The corporate’s safety advisory particularly references the July 2025 CPU, which addressed a number of high-severity vulnerabilities with CVSS scores starting from 7.5 to 9.8, together with distant code execution (RCE) and SQL injection assault vectors. 

Organizations experiencing related extortion makes an attempt are suggested to contact Oracle Help instantly whereas implementing incident response procedures, together with community segmentation and the preservation of forensic knowledge.

Observe us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Confirms, Data, EBusiness, Emails, Extortion, Hackers, Oracle, Suite, Targeting

Post navigation

Previous Post: Red Hat Confirms GitLab Instance Hack, Data Theft
Next Post: HackerOne Paid $81 In Bug Bounty With Emergence of Bionic Hackers

Related Posts

Microsoft Unveils OAuth-Based Phishing Threat Microsoft Unveils OAuth-Based Phishing Threat Cyber Security News
SquidLoader Using Sophisticated Malware With Near-Zero Detection to Swim Under Radar SquidLoader Using Sophisticated Malware With Near-Zero Detection to Swim Under Radar Cyber Security News
Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics Careto Hacker Group is Back After 10 Years of Silence with New Attack Tactics Cyber Security News
LLMs are Accelerating the Ransomware Operations with Functional Tools and RaaS LLMs are Accelerating the Ransomware Operations with Functional Tools and RaaS Cyber Security News
New BRICKSTORM Stealthy Backdoor Attacking Tech and Legal Sectors New BRICKSTORM Stealthy Backdoor Attacking Tech and Legal Sectors Cyber Security News
New Multi-Stage Tycoon2FA Phishing Attack Now Beats Top Security Systems New Multi-Stage Tycoon2FA Phishing Attack Now Beats Top Security Systems Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Mythos Excels in Vulnerability Detection, Faces Varied Challenges
  • OpenAI Faces Lawsuit Over ChatGPT Data Sharing Practices
  • Revolutionizing Data Center Security with DPUs
  • Ghostwriter Intensifies Phishing Attacks on Ukraine
  • AI Enhances Security with Realistic Attack Simulations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Mythos Excels in Vulnerability Detection, Faces Varied Challenges
  • OpenAI Faces Lawsuit Over ChatGPT Data Sharing Practices
  • Revolutionizing Data Center Security with DPUs
  • Ghostwriter Intensifies Phishing Attacks on Ukraine
  • AI Enhances Security with Realistic Attack Simulations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark