Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

CrowdStrike Alerts on Oracle E-Business Suite 0-Day Under Mass Exploitation

A zero-day vulnerability, CVE-2025-61882, has been identified in the Oracle E-Business Suite. This vulnerability is currently being exploited in a large-scale data exfiltration campaign. CrowdStrike Intelligence has attributed the primary involvement to…

A zero-day vulnerability, CVE-2025-61882, has been identified in the Oracle E-Business Suite. This vulnerability is currently being exploited in a large-scale data exfiltration campaign. CrowdStrike Intelligence has attributed the primary involvement to the threat group GRACEFUL SPIDER, noting that the release of public proof-of-concept details may lead to further attacks.

Oracle disclosed CVE-2025-61882 on October 4, 2025, describing it as an unauthenticated remote code execution (RCE) vulnerability within Oracle E-Business Suite. The exploit begins with an HTTP POST request to /OA_HTML/SyncServlet, which bypasses authentication and allows code execution via the XML Publisher Template Manager.

Adversaries utilize GET and POST requests to /OA_HTML/RF.jsp and /OA_HTML/OA.jsp to upload a malicious XSLT template, which executes commands when previewed. Successful exploitation establishes an outbound connection from the Java web server process to attacker-controlled infrastructure over port 443.

Threat actors have been observed using this channel to deploy web shells, granting persistence and command execution capabilities. In certain incidents, the adversary employed FileUtils.java to fetch Log4jConfigQpgsubFilter.java, which functioned as a downloader and backdoor, respectively.

A zero-day vulnerability, CVE-2025-61882, has been identified in the Oracle E-Business Suite.
Olivia Harper · Thehackingpost

Oracle’s advisory includes indicators of compromise, such as malicious IP addresses, observed commands, and filenames, indicating active exploitation in the wild. The technical alignment between CrowdStrike’s telemetry and the published proof-of-concept supports the conclusion that this zero-day vulnerability underpins the campaign.

The public disclosure of the proof-of-concept on October 3, along with Oracle’s patch release, is likely to motivate additional threat actors to exploit the vulnerability. Historical trends show that public proof-of-concepts accelerate exploit development, increasing the number of potential attackers.

Organizations using Oracle E-Business Suite should prioritize the following actions to mitigate risk:

Advertisement

Apply Oracle’s CVE-2025-61882 security updates immediately. Monitor outbound connections from EBS instances to known malicious infrastructure and investigate unexpected network activity. Query the xdo_templates_vl database table for unauthorized template entries matching proof-of-concept references. Review sysadmin (UserID 0) and guest (UserID 6) sessions in icx_sessions for anomalies indicative of authentication bypass. Consider disabling direct internet access for EBS environments or deploying a web application firewall to filter malicious requests.

By quickly patching vulnerable instances and implementing vigilant monitoring, organizations can disrupt the exploitation chain and protect sensitive data from emerging zero-day threats in Oracle E-Business Suite.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories