
October 13, 2025 - Daily Cybersecurity News
ChaosBot: Rust-Based Malware Exploiting Discord for Command-and-Control
HighWhat happened
A new Rust-based malware named ChaosBot has been identified, utilizing Discord channels as command-and-control (C2) infrastructure to execute commands on compromised systems. Attackers gained initial access through compromised credentials and deployed the malware via Windows Management Instrumentation (WMI).
Who is affected
Organizations, particularly in the financial services sector, are at risk, especially those with exposed or weak credential management practices.
Why it matters
The use of legitimate platforms like Discord for C2 operations allows malware to blend with normal network traffic, making detection challenging. This technique signifies an evolution in malware tactics, emphasizing the need for advanced detection mechanisms.
How it could have been prevented
Implementing robust credential management practices, including regular audits and enforcing multi-factor authentication, can mitigate initial access vectors. Monitoring for unusual use of legitimate platforms for C2 communications is also crucial.
Relevant professional terms
- Command-and-Control (C2)
- A server or infrastructure used by attackers to send commands to compromised systems and receive data from them.
- Windows Management Instrumentation (WMI)
- A set of specifications from Microsoft for consolidating the management of devices and applications in a network.
Recommended reading: securityonline.info
Critical Vulnerability CVE-2025-61882 in Oracle E-Business Suite Exploited in the Wild
CriticalWhat happened
A critical vulnerability, CVE-2025-61882, has been identified in Oracle E-Business Suite's Concurrent Processing component, allowing unauthenticated remote code execution. This flaw has been actively exploited in the wild since at least August 2025.
Who is affected
Organizations using Oracle E-Business Suite versions 12.2.3 through 12.2.14 are vulnerable. The Cl0p ransomware gang is suspected to be exploiting this vulnerability.
Why it matters
Exploitation of this vulnerability can lead to unauthorized access, data exfiltration, and full system compromise, posing significant risks to sensitive business operations and data integrity.
How it could have been prevented
Timely application of security patches provided by Oracle and restricting unnecessary network access to Oracle E-Business Suite instances.
Relevant professional terms
- Remote Code Execution (RCE)
- A type of vulnerability that allows an attacker to execute arbitrary code on a target system remotely.
- Zero-Day Vulnerability
- A security flaw that is exploited by attackers before the software vendor has released a fix.
Recommended reading: Oracle Security Alert Advisory - CVE-2025-61882
Cyberattacks Disrupt Patient Care in U.S. Healthcare Organizations
CriticalWhat happened
A recent study revealed that 93% of U.S. healthcare organizations experienced at least one cyberattack in the past year, averaging 43 incidents per organization. These attacks primarily involved cloud account compromises, ransomware, supply chain intrusions, and business email compromise, leading to disruptions in patient care.
Who is affected
U.S. healthcare organizations, including hospitals and clinics, along with their patients, are significantly impacted by these cyberattacks.
Why it matters
Cyberattacks have been linked to poor clinical outcomes and, in some cases, increased patient mortality. Disruptions caused by these incidents lead to delayed procedures, longer hospital stays, and compromised patient safety.
How it could have been prevented
Implementing comprehensive cybersecurity frameworks, conducting regular staff training on security protocols, and ensuring timely software updates and patches could mitigate the risk of such attacks.
Relevant professional terms
- Ransomware
- A type of malicious software designed to block access to a computer system until a sum of money is paid.
- Supply Chain Intrusion
- A cyberattack that targets an organization by compromising elements within its supply chain, such as vendors or service providers.
Recommended reading: Breaches are up, budgets are too, so why isn't healthcare safer?
Rapid Execution of Cyber Attacks on Windows Systems
HighWhat happened
Cyber attackers are accelerating their operations, executing payloads on Windows systems within minutes of gaining access, prioritizing speed over stealth.
Who is affected
Organizations utilizing Windows systems, particularly those operating within cloud environments such as Azure, AWS, and Google Cloud.
Why it matters
The swift execution of attacks reduces the window for detection and response, increasing the risk of data breaches and system compromises.
How it could have been prevented
Implementing behavior-driven analytics to detect rapid execution patterns and enhancing identity protection measures to prevent unauthorized access.
Relevant professional terms
- Execution Tactic
- A phase in the cyber attack lifecycle where adversaries run malicious code on a target system.
- Identity Compromise
- Unauthorized access to user credentials, allowing attackers to impersonate legitimate users.
Recommended reading: Adversarial groups adapt to exploit systems in new ways
Critical Remote Vulnerability in Oracle E-Business Suite (CVE-2025-61884)
CriticalWhat happened
A critical vulnerability (CVE-2025-61884) has been identified in the Oracle Configurator component of Oracle E-Business Suite (EBS), allowing unauthenticated attackers to gain unauthorized access to sensitive data via HTTP.
Who is affected
Organizations using Oracle EBS versions 12.2.3 through 12.2.14 are affected. Reports suggest earlier versions, such as 12.1.3, may also be vulnerable.
Why it matters
Exploitation of this vulnerability can lead to unauthorized access to critical data, posing significant risks to business operations and data integrity.
How it could have been prevented
Regularly applying security patches and updates, conducting thorough security assessments, and monitoring for unusual network activity can help prevent such vulnerabilities.
Relevant professional terms
- Unauthenticated Attack
- An attack executed without the need for user credentials or authentication.
- Oracle E-Business Suite (EBS)
- A comprehensive suite of integrated business applications for enterprise resource planning.
Recommended reading: NVD - CVE-2025-61884
Hackers Extort Salesforce Customers; CentreStack 0-Day Exploited
CriticalWhat happened
A hacking group named Scattered Lapsus$ Hunters launched a data leak site to extort organizations whose Salesforce databases they have compromised. Simultaneously, the Cl0p extortion gang exploited a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite to steal substantial data from multiple victims.
Who is affected
Organizations utilizing Salesforce databases and Oracle E-Business Suite are targeted, with specific victims not publicly disclosed.
Why it matters
These incidents highlight the increasing sophistication of cyber extortion tactics and the critical need for organizations to secure their enterprise software environments against emerging threats.
How it could have been prevented
Regularly updating and patching enterprise software to address known vulnerabilities. Implementing robust access controls and monitoring systems to detect unauthorized activities.
Relevant professional terms
- Zero-day vulnerability
- A software flaw unknown to the vendor, leaving systems exposed until a patch is developed.
- Data leak site
- A platform where cybercriminals publish stolen data to pressure victims into meeting extortion demands.
Recommended reading: Help Net Security