Transcript
Actually, it's Oracle eBusiness Suite specifically in here that has a CVE-2025-61884. This one has been targeting a few large organizations. There is proof of concept code publicly leaked by a threat actor called Shiny Hunters. They and Klopp have been targeting this CVE, and there's a few large organizations that have been hit by this. One article that I saw was for Harvard. There have been some other large businesses for it, but there is definitely some growing concern around this one and advisory from Oracle that you can link to in here as well. I'll pull that up in a second, but there's a number of Oracle zero days that have been targeted over the last several years. This is one of the areas that Klopp, specifically Klopp Ransomware, seems to target. They tend to find a very lucrative Oracle CVE and target that for a prolonged period of time, and then they move on to the next one. One of the articles actually went into some of the older ones that they had been targeting. I don't think it was in this one. It was in one of the other threads that I pulled up off of here. Definitely something you want to keep tabs on when Oracle does these announcements around SAP or the e-business suite. These platforms are obviously large behemoth solutions that are usually core to some pretty sensitive business-critical solutions. They are a high-profile target. They're also difficult to upgrade. That tends to be why some high-profile threat actors like Shiny Hunters and Klopp tend to specialize in targeting these. Just make sure your organization is aware of that and the unit who's responsible for those back-end solutions is actively taking steps to try to upgrade and keep up to date with those updates to those platforms. That's the latest on that front. Oracle did release, as I mentioned, a security advisory for the Oracle e-business suite. It has details of the CVE. It has the information on how to update that. It has some other information about the risks of that CVE. That could be a good read or information that the people within your organization may need. In this case, the most dangerous part about this one and the reason why Oracle is strongly urging upgrading as soon as possible is this is remotely exploitable without authentication. If the threat actor is in your network, they may be able to exploit this remotely without any need for authentication to do so. That makes this one particularly dangerous. Again, just want to make sure that people are aware of this one and your organization is taking steps to investigate and mitigate immediately with plans to remediate longer term if needed. Thank you.