Find notable cyber news and cases, enriched with sources, timelines, and signals.

Oracle EBS zero-day exploitation wave (dozens of victims)

Exploitation Wave
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

A multi-victim Oracle E-Business Suite (EBS) exploitation wave is affecting dozens of victims, with the total possibly exceeding 100. The activity is tied to zero-day vulnerabilities in October 2025, signaling broad abuse of exposed Oracle EBS deployments. At this scale, the wave raises the risk of repeated compromise, downstream data theft, and extortion across multiple organizations.

Related Happenings

ShinyHunters Oracle PeopleSoft data theft from 300 instances

Data Leak
H score46 First: 11.06.2026 22:39 Last: 11.06.2026 22:39 Sources 1

About this happening: The **ShinyHunters** data-leak event against **Oracle PeopleSoft** instances exposed data from **300 instances** across **100+ organizations**, expanding the risk of theft-driven...

Oracle PeopleSoft PeopleTools zero-day RCE (CVE-2026-35273)

Vulnerability
H score58 First: 11.06.2026 22:39 Last: 11.06.2026 22:39 Sources 1

About this happening: **Oracle PeopleSoft PeopleTools** **CVE-2026-35273** is a critical **zero-day RCE** affecting **versions 8.61 and 8.62**. Oracle has released **emergency mitigations** while a pat...

Oracle WebLogic Server CVE-2026-21962 rapid exploitation wave

Exploitation Wave
H score52 First: 26.03.2026 18:00 Last: 26.03.2026 18:00 Sources 1

About this happening: **Oracle WebLogic Server** systems faced a rapid **CVE-2026-21962** exploitation wave after public exploit code appeared, creating immediate **RCE risk** for exposed servers. The...

Oracle Identity Manager and Oracle Web Services Manager unauthenticated RCE (CVE-2026-21992)

Vulnerability
H score55 First: 20.03.2026 20:48 Last: 20.03.2026 20:48 Sources 1

About this happening: Oracle issued an **out-of-band update** to fix **CVE-2026-21992**, a **critical unauthenticated remote code execution** flaw in **Oracle Identity Manager** and **Oracle Web Servic...

Cl0p Oracle E-Business Suite zero-day extortion campaign

Campaign
H score50 First: 02.03.2026 15:53 Last: 02.03.2026 15:53 Sources 1

About this happening: The **Cl0p ransomware and extortion group** is running an **Oracle E-Business Suite** extortion campaign that used **zero-day vulnerabilities** to access data from **more than 100...

Timeline

  1. 12.11.2025 17:30 1 articles · 7mo ago

    Oracle EBS exploitation observed

    Exploitation Observed

    Oracle confirmed that threat actors were likely exploiting vulnerabilities against Oracle E-Business Suite environments on October 2, 2025, indicating active abuse of a previously unknown zero-day path affecting exposed Oracle instances.

    Show sources
  2. 12.11.2025 17:30 1 articles · 7mo ago

    Oracle issues zero-day security advisory

    Mitigation Patch Update

    Oracle issued a security advisory on October 4, 2025 about a previously unknown zero-day exploit affecting Oracle E-Business Suite, establishing the vendor response that prompted customers to assess exposure and patch affected systems.

    Show sources
  3. 12.11.2025 17:30 1 articles · 7mo ago

    Data exfiltration confirmed from GlobalLogic Oracle instance

    Victim Impact Update

    GlobalLogic's investigation confirmed that data was exfiltrated from its Oracle environment on October 9, 2025, turning the Oracle E-Business Suite compromise into a confirmed data theft event affecting employee information.

    Show sources
  4. 12.11.2025 17:30 2 articles · 7mo ago

    GlobalLogic discloses Oracle EBS compromise to 10,471 people

    Initial Disclosure

    GlobalLogic notified 10,471 current and former employees that personal data from its Oracle E-Business Suite platform was compromised in a large-scale data extortion campaign, with exposed HR records including names, addresses, phone numbers, dates of birth, passport information, salary information, and bank account details.

    Show sources