Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Confirms Exploitation of Recent Oracle Identity Manager Vulnerability

CISA Confirms Exploitation of Recent Oracle Identity Manager Vulnerability

Posted on November 24, 2025November 24, 2025 By CWS

The cybersecurity company CISA has confirmed {that a} just lately patched Oracle Id Supervisor vulnerability has been exploited within the wild.

The vulnerability in query is tracked as CVE-2025-61757 and it was patched by Oracle in Id Supervisor (a product in its Fusion Middleware platform) with the October 2025 patches. The flaw will be exploited by an unauthenticated attacker for distant code execution. 

SecurityWeek reported on Friday that CVE-2025-61757 could have been exploited within the wild as a zero-day a number of weeks earlier than Oracle launched a patch. 

Searchlight Cyber, whose researchers found the difficulty and reported it to Oracle, disclosed technical particulars and PoC code on Thursday, warning that it might simply be exploited, permitting attackers to escalate privileges and transfer laterally, probably resulting in delicate knowledge publicity. 

Based mostly on the technical data made public by Searchlight, the SANS Know-how Institute checked its honeypot logs for indicators of potential exploitation and located what regarded like assault makes an attempt coming from a number of IP addresses between August 30 and September 9.

The identical IP addresses had been additionally seen scanning the net for different product vulnerabilities, and so they additionally carried out scans related to bug bounties. 

Regardless of this, Searchlight informed SecurityWeek on Friday that the exercise seen by SANS will be attributed to its researchers, in addition to efforts to inform affected organizations.

Nevertheless, on Saturday, CISA added CVE-2025-61757 to its Recognized Exploited Vulnerabilities (KEV) catalog, instructing federal businesses to handle the flaw by December 12. Commercial. Scroll to proceed studying.

SecurityWeek is hoping to acquire extra clarifications from SANS and Searchlight relating to the potential exploitation. It’s attainable that CISA discovered of assaults from a distinct supply. 

The company up to now identified that vulnerabilities are solely added to the KEV catalog if there may be dependable proof of exploitation within the wild.

Contacted by SecurityWeek, Oracle didn’t present any clarifications and as a substitute pointed to its October 2025 safety bulletin, which doesn’t point out something about CVE-2025-61757 being exploited within the wild. 

Associated: Latest 7-Zip Vulnerability Exploited in Assaults

Associated: Fortinet Discloses Second Exploited FortiWeb Zero-Day in a Week

Associated: Two-12 months-Outdated Ray AI Framework Flaw Exploited in Ongoing Marketing campaign

Security Week News Tags:CISA, Confirms, Exploitation, Identity, Manager, Oracle, Vulnerability

Post navigation

Previous Post: 800+ npm Packages and Thousands of GitHub Repos Compromised
Next Post: PoC released for W3 Total Cache Vulnerability that Exposes 1+ Million Websites to RCE Attacks

Related Posts

Printer Company Procolored Served Infected Software for Months Printer Company Procolored Served Infected Software for Months Security Week News
CMMC Live: Pentagon Demands Verified Cybersecurity From Contractors CMMC Live: Pentagon Demands Verified Cybersecurity From Contractors Security Week News
Akira Ransomware Attacks Fuel Uptick in Exploitation of SonicWall Flaw Akira Ransomware Attacks Fuel Uptick in Exploitation of SonicWall Flaw Security Week News
Rise in Supply Chain Attacks Highlights SBOM Challenges Rise in Supply Chain Attacks Highlights SBOM Challenges Security Week News
Notepad++ Patches Updater Flaw After Reports of Traffic Hijacking Notepad++ Patches Updater Flaw After Reports of Traffic Hijacking Security Week News
Vodafone Germany Fined  Million Over Privacy, Security Failures Vodafone Germany Fined $51 Million Over Privacy, Security Failures Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark