Tag: Oracle


  • Hackers Hide Khunt Toolkit Inside Oracle Database After SQL Injection Attack

    Researchers have uncovered an Oracle database attack in which hackers used a SQL injection flaw to install a post-exploitation toolkit directly inside a database. The incident shows how attackers can turn a vulnerable public-facing application into a path for deeper network access. Instead of dropping standard malware files on the server, the group stored Java…

  • Oracle E-Business Suite Vulnerability Enters Active Exploitation as Attacks Begin

    Attackers have begun targeting a critical Oracle EBS vulnerability, increasing the pressure on organizations that still run unpatched systems. Security researchers recently detected real-world attacks, confirming that cybercriminals have moved beyond analyzing the flaw and started exploiting vulnerable servers. The Oracle EBS vulnerability, tracked as CVE-2026-46817, affects Oracle Payments and allows remote attackers to compromise…

  • Oracle RCE flaw triggers urgent emergency patch

    A critical vulnerability in Oracle’s identity systems has forced an emergency response outside the normal patch cycle. The Oracle RCE flaw affects core infrastructure used to manage access and authentication across enterprise environments. More importantly, its severity comes from how easily it can be exploited and the level of control it can grant to attackers.…

  • Oracle E-Business Suite breach hits Cox Enterprises

    Cox Enterprises confirmed an Oracle E-Business Suite breach after attackers exploited a zero-day flaw in the widely used enterprise platform. The intrusion affected thousands of people and exposed sensitive data stored inside the company’s back-office environment. Cox launched a full investigation once internal systems raised an alert and found that the breach had started weeks…

  • Oracle EBS Breach Linked to Washington Post Hack Reveals Zero-Day Exposure

    The Oracle EBS breach has emerged as a critical factor in a recent cyberattack that targeted internal systems at The Washington Post. New research links the intrusion to a zero-day vulnerability in Oracle’s widely used enterprise suite. The Clop ransomware group exploited this flaw during an operation that affected multiple organizations. The findings highlight the…

  • Oracle Zero-Day Exploited by Cl0p Months Before Patch

    The Oracle zero-day vulnerability (CVE-2025-61882) was exploited by the Cl0p ransomware group months before Oracle released a patch. The attackers used stealthy, fileless Java malware to infiltrate Oracle’s E-Business Suite systems and launch a large-scale extortion campaign. Security researchers say the operation went undetected for months, exposing organizations to serious risks. How Cl0p Exploited the…

  • Hackers Exploit Critical Oracle EBS Flaw for Extortion

    A new Oracle EBS flaw has triggered global warnings from cybersecurity authorities. Hackers are actively exploiting the vulnerability, tracked as CVE-2025-61882, to gain full control over unpatched systems. The flaw affects multiple versions of Oracle E-Business Suite (EBS) and allows attackers to execute remote code without authentication. Once inside, they can steal sensitive data, encrypt…

  • Oracle EBS zero-day exploited in Clop data theft attacks patched

    A critical Oracle EBS zero-day flaw exploited in Clop data theft attacks has now been patched. The vulnerability allowed hackers to execute code remotely and steal sensitive data from major organizations. Oracle confirmed that the Clop ransomware group exploited the flaw before a fix was available. The Oracle EBS Zero-Day Explained The vulnerability, tracked as…