Team standing on laptop with masked hackers above, warning icons, caution signs, and phishing threats displayed

Daily Dose of Cybersecurity News - October 6, 2025

Oracle E-Business Suite Zero-Day (CVE-2025-61882) Exploited by Clop Ransomware Group

Critical

What happened

A critical zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite (EBS) was exploited by the Clop ransomware group to perform unauthenticated remote code execution, leading to data theft and extortion attempts.

Who is affected

Organizations using Oracle E-Business Suite versions 12.2.3 through 12.2.14 are impacted, with the Clop ransomware group identified as the threat actor.

Why it matters

The exploitation of this vulnerability allows attackers to execute code remotely without authentication, potentially leading to significant data breaches and financial losses due to extortion.

How it could have been prevented

Timely application of security patches and updates, along with regular vulnerability assessments, could have mitigated the risk of exploitation.

Relevant professional terms

Zero-Day Vulnerability
A software flaw unknown to the vendor, leaving systems vulnerable until a patch is developed.
Remote Code Execution (RCE)
The ability of an attacker to execute arbitrary code on a target system remotely.

Recommended reading: Cybereason Blog on Oracle EBS Extortion Campaign

Zimbra CVE-2025-27915 Exploited via iCalendar Files

High

What happened

Threat actors exploited CVE-2025-27915, a cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) versions 9.0, 10.0, and 10.1, by embedding malicious JavaScript within iCalendar (.ICS) files to execute arbitrary code within victims' sessions.

Who is affected

Organizations using ZCS versions 9.0, 10.0, and 10.1 prior to the release of patches on January 27, 2025, are affected.

Why it matters

Exploitation of this vulnerability allows attackers to steal sensitive information, such as credentials, emails, contacts, and shared folders, potentially leading to unauthorized access and data breaches.

How it could have been prevented

Timely application of security patches released by Zimbra on January 27, 2025, and monitoring for unusually large .ICS files containing JavaScript code.

Relevant professional terms

Cross-Site Scripting (XSS)
A security vulnerability that allows attackers to inject malicious scripts into web pages viewed by others.
iCalendar (.ICS) Files
A file format used to store and exchange calendar and scheduling information.

Recommended reading: Zimbra patches zero-day vulnerability exploited in XSS attacks

AI-Enhanced Phishing Attacks Escalate Cybersecurity Threats

High

What happened

Cybercriminals are increasingly leveraging artificial intelligence to craft sophisticated phishing campaigns and malware, significantly enhancing the scale and effectiveness of their attacks.

Who is affected

Organizations across various sectors are at heightened risk, particularly those with insufficient AI defenses or lacking comprehensive security awareness programs.

Why it matters

The integration of AI into cyberattacks lowers the barrier for less skilled attackers, leading to a surge in both the volume and sophistication of threats. This evolution challenges traditional security measures and necessitates advanced defensive strategies.

How it could have been prevented

Implementing AI-driven security solutions to detect and respond to anomalies, conducting regular employee training on recognizing sophisticated phishing attempts, and enforcing strict policies against the use of unauthorized AI tools within the organization.

Relevant professional terms

Shadow AI
Unauthorized use of AI tools by employees, leading to potential security vulnerabilities.
Zero-Trust Approach
A security model that requires strict verification for every user and device attempting to access resources, regardless of their location.

Recommended reading: CISOs pursuing AI readiness should start by updating the org’s email security policy

Red Hat's GitLab Breach Exposes Sensitive Customer Data

High

What happened

Red Hat confirmed a security incident where unauthorized access was gained to its self-managed GitLab instance used by its Consulting division. The attackers, identified as the Crimson Collective, claim to have stolen approximately 570GB of data, including around 800 Customer Engagement Reports (CERs).

Who is affected

Clients of Red Hat's Consulting services, spanning sectors such as finance, healthcare, retail, government, and defense, may be impacted due to the potential exposure of sensitive data contained in the stolen CERs.

Why it matters

The breach exposes detailed information about client infrastructures, including network configurations and authentication tokens. This data could be exploited by malicious actors to infiltrate client systems, leading to further security incidents and data breaches.

How it could have been prevented

Implementing stringent access controls and regular security audits on internal repositories could have mitigated unauthorized access. Additionally, ensuring that sensitive data, such as authentication tokens, are not stored in repositories or are adequately encrypted would reduce the risk of data exposure.

Relevant professional terms

Customer Engagement Reports (CERs)
Detailed documents prepared during consulting engagements that often contain sensitive information about a client's network, configurations, and authentication details.
Self-managed GitLab instance
A privately hosted version of the GitLab platform, maintained and secured by the organization rather than by GitLab's managed services.

Recommended reading: BleepingComputer