back to article Crims had 3-month head start on defenders in Oracle EBS invasion

The raid on Oracle E-Business Suite (EBS) likely began as early as July - about three months before any public detections - with extortionists compromising "dozens" of organizations, a Google investigation has determined. New analysis by Google Threat Intelligence Group (GTIG) and Mandiant indicates that, while the criminals …

  1. Anonymous Coward
    Anonymous Coward

    Article needs more acronyms, and more pictures.

    1. Random as if !

      GTIG + MNDT confirm CRIM OPS began JUL10-25, exploiting CVE-2025-61882 (PRE-PATCH RCE) in O-EBS → MASS COMP & EXTORT.

      Attack chain = HTTP → UiS → SSRF → SYNC-RCE → GOLDVEIN → SAGELEAF/SAGEWAVE → C2 → CL0P DLS.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like