Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Oracle Identity Manager Flaw Possibly Exploited as Zero-Day

Critical Oracle Identity Manager Flaw Possibly Exploited as Zero-Day

Posted on November 21, 2025November 21, 2025 By CWS

A lately patched Oracle Identification Supervisor vulnerability might have been exploited as a zero-day.

The vulnerability, tracked as CVE-2025-61757, was disclosed on Thursday by Searchlight Cyber, whose researchers found the difficulty and reported it to Oracle.

The safety agency described it as a important pre-authentication distant code execution vulnerability in Oracle Identification Supervisor. The exploit, which chains an authentication bypass weak spot and arbitrary code execution, can enable an attacker to realize full system compromise. 

Oracle fastened CVE-2025-61757 with its October 2025 patches and confirmed that it’s a important subject that may be simply exploited with out authentication. 

Searchlight Cyber warned on Thursday that the vulnerability can “enable attackers to control authentication flows, escalate privileges, and transfer laterally throughout an organisation’s core methods”, noting that it may “result in the breach of servers dealing with person PII and credentials”.

The SANS Expertise Institute used the technical data and PoC code made public by Searchlight on Thursday to verify its honeypot logs for indicators of potential exploitation. 

Based on SANS’s Johannes Ullrich, potential exploitation was seen a number of occasions between August 30 and September 9, weeks earlier than Oracle launched a patch. 

“There are a number of totally different IP addresses scanning for it, however all of them use the identical person agent, which means that we could also be coping with a single attacker,” Ullrich defined. Commercial. Scroll to proceed studying.

“Sadly, we didn’t seize the our bodies for these requests, however they had been all POST requests,” he added.

The professional stated the identical IP addresses had been beforehand seen scanning the net for a Liferay product vulnerability (CVE-2025-4581) and conducting scans that look like related to bug bounties. The IPs additionally scanned for URLs related to the exploitation of the Log4j vulnerability. 

SecurityWeek has reached out to Oracle for remark and can replace this text if the corporate responds. Searchlight has additionally been requested whether or not the exercise seen by SANS might have been performed by its personal researchers whereas analyzing the vulnerability. 

Associated: Fortinet Discloses Second Exploited FortiWeb Zero-Day in a Week

Associated: Current 7-Zip Vulnerability Exploited in Assaults

Associated: Two-Yr-Outdated Ray AI Framework Flaw Exploited in Ongoing Marketing campaign

Security Week News Tags:Critical, Exploited, Flaw, Identity, Manager, Oracle, Possibly, ZeroDay

Post navigation

Previous Post: Over 370 Organizations Take Part in GridEx VIII Grid Security Exercise
Next Post: In Other News: ATM Jackpotting, WhatsApp-NSO Lawsuit Continues, CISA Hiring

Related Posts

Irregular Raises  Million for AI Security Testing Lab Irregular Raises $80 Million for AI Security Testing Lab Security Week News
US Indicts Extradited Ukrainian on Charges of Aiding Russian Hacking Groups US Indicts Extradited Ukrainian on Charges of Aiding Russian Hacking Groups Security Week News
Cyber Insights 2026: Malware and Cyberattacks in the Age of AI Cyber Insights 2026: Malware and Cyberattacks in the Age of AI Security Week News
Black Hat USA 2025 – Summary of Vendor Announcements (Part 2) Black Hat USA 2025 – Summary of Vendor Announcements (Part 2) Security Week News
Myanmar Military Shuts Down Major Cybercrime Center and Detains Over 2,000 People Myanmar Military Shuts Down Major Cybercrime Center and Detains Over 2,000 People Security Week News
Reflectiz Raises  Million for Website Security Solution Reflectiz Raises $22 Million for Website Security Solution Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News