Oracle has released a fix for a new Oracle E‑Business Suite vulnerability that can be exploited remotely without authentication to access sensitive data. It’s not yet clear if the flaw is being exploited in the wild, but the exposure of business-critical ERP data makes rapid patching and internet-exposure reviews urgent for EBS customers.
Source: Security Week
Google, Mandiant tie Oracle EBS extortion to malware, patched bugs, and likely zero‑day (CVE‑2025‑61882)
Google Threat Intelligence and Mandiant analyzed an Oracle E‑Business Suite extortion campaign that used malware, July‑patched vulnerabilities, and a likely zero‑day (CVE‑2025‑61882) to pressure executives. Their findings underscore a shift from opportunistic scanning to targeted ERP exploitation, with attackers chaining flaws and extortion tactics against high‑value apps.
Source: Security Affairs
Extortion group leaks millions of records from Salesforce-related breaches
An extortion group has posted data allegedly tied to major organizations using Salesforce, including Albertsons, Engie Resources, Fujifilm, GAP, Qantas, and Vietnam Airlines. The incident highlights the growing risk of third‑party SaaS ecosystems and the need to harden integrations, tokens, and access scopes tied to cloud CRM platforms.
Source: Security Week
Microsoft locks down Edge’s IE mode after threat actors abused it as a backdoor
Microsoft revamped Internet Explorer mode in Edge following credible reports that attackers combined social engineering with unpatched IE JavaScript exploits to gain unauthorized device access. Organizations should reassess any dependency on IE mode, apply the latest browser updates, and tighten policies for legacy compatibility features.
Source: TheHackerNews
RondoDox botnet now exploits 50+ vulnerabilities across 30+ vendors
Researchers warn the RondoDox botnet has broadened its “exploit shotgun” approach to target more than 50 flaws in routers, DVRs/NVRs, CCTV systems, web servers, and other internet‑exposed infrastructure. The campaign underscores the need to minimize external attack surface, promptly patch embedded/IoT devices, and segment networks to contain compromises.
Source: TheHackerNews
New Rust-based ChaosBot uses Discord channels for command-and-control
eSentire detailed “ChaosBot,” a Rust backdoor capable of reconnaissance and arbitrary command execution, controlled via Discord channels. The intrusion leveraged compromised credentials tied to both a Cisco VPN and an over‑privileged Active Directory “serviceaccount,” highlighting the compound risks of credential theft and excessive privileges.
Source: TheHackerNews
Spain dismantles ‘GXC Team’ crime‑as‑a‑service ring behind phishing kits and Android malware
Spanish authorities arrested “GoogleXcoder,” the alleged admin of the GXC Team service that supplied phishing kits and Android malware to cybercriminals. The takedown could disrupt multiple phishing and mobile malware campaigns in the near term, though defenders should anticipate copycats and reconstituted operations.
Source: Security Week
You May Also Be Interested In...
Wireshark 4.4.10 and 4.6.0 Released
Astaroth Banking Trojan Abuses GitHub to Remain Operational After Takedowns