Group of hackers with laptops surrounding large shield with lock icon and security symbols

October 13, 2025 - Daily Cybersecurity News

ChaosBot: Rust-Based Malware Exploiting Discord for Command-and-Control

High

What happened

A new Rust-based malware named ChaosBot has been identified, utilizing Discord channels as command-and-control (C2) infrastructure to execute commands on compromised systems. Attackers gained initial access through compromised credentials and deployed the malware via Windows Management Instrumentation (WMI).

Who is affected

Organizations, particularly in the financial services sector, are at risk, especially those with exposed or weak credential management practices.

Why it matters

The use of legitimate platforms like Discord for C2 operations allows malware to blend with normal network traffic, making detection challenging. This technique signifies an evolution in malware tactics, emphasizing the need for advanced detection mechanisms.

How it could have been prevented

Implementing robust credential management practices, including regular audits and enforcing multi-factor authentication, can mitigate initial access vectors. Monitoring for unusual use of legitimate platforms for C2 communications is also crucial.

Relevant professional terms

Command-and-Control (C2)
A server or infrastructure used by attackers to send commands to compromised systems and receive data from them.
Windows Management Instrumentation (WMI)
A set of specifications from Microsoft for consolidating the management of devices and applications in a network.

Recommended reading: securityonline.info

Critical Vulnerability CVE-2025-61882 in Oracle E-Business Suite Exploited in the Wild

Critical

What happened

A critical vulnerability, CVE-2025-61882, has been identified in Oracle E-Business Suite's Concurrent Processing component, allowing unauthenticated remote code execution. This flaw has been actively exploited in the wild since at least August 2025.

Who is affected

Organizations using Oracle E-Business Suite versions 12.2.3 through 12.2.14 are vulnerable. The Cl0p ransomware gang is suspected to be exploiting this vulnerability.

Why it matters

Exploitation of this vulnerability can lead to unauthorized access, data exfiltration, and full system compromise, posing significant risks to sensitive business operations and data integrity.

How it could have been prevented

Timely application of security patches provided by Oracle and restricting unnecessary network access to Oracle E-Business Suite instances.

Relevant professional terms

Remote Code Execution (RCE)
A type of vulnerability that allows an attacker to execute arbitrary code on a target system remotely.
Zero-Day Vulnerability
A security flaw that is exploited by attackers before the software vendor has released a fix.

Recommended reading: Oracle Security Alert Advisory - CVE-2025-61882

Cyberattacks Disrupt Patient Care in U.S. Healthcare Organizations

Critical

What happened

A recent study revealed that 93% of U.S. healthcare organizations experienced at least one cyberattack in the past year, averaging 43 incidents per organization. These attacks primarily involved cloud account compromises, ransomware, supply chain intrusions, and business email compromise, leading to disruptions in patient care.

Who is affected

U.S. healthcare organizations, including hospitals and clinics, along with their patients, are significantly impacted by these cyberattacks.

Why it matters

Cyberattacks have been linked to poor clinical outcomes and, in some cases, increased patient mortality. Disruptions caused by these incidents lead to delayed procedures, longer hospital stays, and compromised patient safety.

How it could have been prevented

Implementing comprehensive cybersecurity frameworks, conducting regular staff training on security protocols, and ensuring timely software updates and patches could mitigate the risk of such attacks.

Relevant professional terms

Ransomware
A type of malicious software designed to block access to a computer system until a sum of money is paid.
Supply Chain Intrusion
A cyberattack that targets an organization by compromising elements within its supply chain, such as vendors or service providers.

Recommended reading: Breaches are up, budgets are too, so why isn't healthcare safer?

Rapid Execution of Cyber Attacks on Windows Systems

High

What happened

Cyber attackers are accelerating their operations, executing payloads on Windows systems within minutes of gaining access, prioritizing speed over stealth.

Who is affected

Organizations utilizing Windows systems, particularly those operating within cloud environments such as Azure, AWS, and Google Cloud.

Why it matters

The swift execution of attacks reduces the window for detection and response, increasing the risk of data breaches and system compromises.

How it could have been prevented

Implementing behavior-driven analytics to detect rapid execution patterns and enhancing identity protection measures to prevent unauthorized access.

Relevant professional terms

Execution Tactic
A phase in the cyber attack lifecycle where adversaries run malicious code on a target system.
Identity Compromise
Unauthorized access to user credentials, allowing attackers to impersonate legitimate users.

Recommended reading: Adversarial groups adapt to exploit systems in new ways

Critical Remote Vulnerability in Oracle E-Business Suite (CVE-2025-61884)

Critical

What happened

A critical vulnerability (CVE-2025-61884) has been identified in the Oracle Configurator component of Oracle E-Business Suite (EBS), allowing unauthenticated attackers to gain unauthorized access to sensitive data via HTTP.

Who is affected

Organizations using Oracle EBS versions 12.2.3 through 12.2.14 are affected. Reports suggest earlier versions, such as 12.1.3, may also be vulnerable.

Why it matters

Exploitation of this vulnerability can lead to unauthorized access to critical data, posing significant risks to business operations and data integrity.

How it could have been prevented

Regularly applying security patches and updates, conducting thorough security assessments, and monitoring for unusual network activity can help prevent such vulnerabilities.

Relevant professional terms

Unauthenticated Attack
An attack executed without the need for user credentials or authentication.
Oracle E-Business Suite (EBS)
A comprehensive suite of integrated business applications for enterprise resource planning.

Recommended reading: NVD - CVE-2025-61884

Hackers Extort Salesforce Customers; CentreStack 0-Day Exploited

Critical

What happened

A hacking group named Scattered Lapsus$ Hunters launched a data leak site to extort organizations whose Salesforce databases they have compromised. Simultaneously, the Cl0p extortion gang exploited a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite to steal substantial data from multiple victims.

Who is affected

Organizations utilizing Salesforce databases and Oracle E-Business Suite are targeted, with specific victims not publicly disclosed.

Why it matters

These incidents highlight the increasing sophistication of cyber extortion tactics and the critical need for organizations to secure their enterprise software environments against emerging threats.

How it could have been prevented

Regularly updating and patching enterprise software to address known vulnerabilities. Implementing robust access controls and monitoring systems to detect unauthorized activities.

Relevant professional terms

Zero-day vulnerability
A software flaw unknown to the vendor, leaving systems exposed until a patch is developed.
Data leak site
A platform where cybercriminals publish stolen data to pressure victims into meeting extortion demands.

Recommended reading: Help Net Security