# Oracle warns of security bug that hackers abused to breach 100+ companies — News, Sentiment & Analysis

**Source:** TrendWatcher — https://www.trendwatcher.in/topic/oracle-warns-of-security-bug-that-hackers-abused-to-breach-1  
**As of:** 2026-09-12 (UTC)  
**Sentiment:** neutral (50/100)  
**Sources analysed:** 7

As of 2026-09-12, TrendWatcher scores Oracle warns of security bug that hackers abused to breach 100+ companies sentiment as **neutral** at 50/100, based on 7 news sources analysed over the past 24 hours.

## Summary

Multiple sources report that a cybercrime group has targeted organizations using Oracle software, resulting in a breach affecting over 100 companies. While TechCrunch identifies the group as ShinyHunters targeting PeopleSoft, other sources report that the group CL0P targeted Oracle's E-Business Suite (EBS) using a vulnerability identified as CVE-2025-61882. The attackers reportedly utilized sophisticated methods, including Java-based implants and in-memory execution, to exfiltrate sensitive corporate and executive data for the purpose of extortion.

Oracle has acknowledged the security issues and issued advisories urging customers to apply patches or mitigations. The incidents highlight a trend of attackers targeting enterprise-level software to gain unauthorized access to data. While some organizations have successfully remediated the vulnerabilities, others have reported data theft, with hackers threatening to publish stolen information if ransom demands are not met.

## Key points

- Over 100 global organizations have been impacted by security breaches involving Oracle software.
- The attacks involved the use of sophisticated techniques, including Java-based implants and in-memory execution, to exfiltrate data.
- Oracle has issued security advisories, including CVE-2025-61882, and urged customers to apply patches to secure their systems.
- The attackers are employing extortion tactics, contacting executives to demand payment in exchange for not publishing stolen data.

## Frequently asked questions

### What software is affected by these security breaches?

Reports indicate that vulnerabilities were exploited in Oracle's PeopleSoft and E-Business Suite (EBS) platforms.

### How are the attackers gaining access to corporate systems?

Attackers are exploiting software vulnerabilities to gain unauthorized access, often without requiring authentication, and deploying malicious implants to steal data.

### What should organizations using Oracle software do?

Oracle and security experts recommend that customers immediately apply the latest security patches and mitigations to protect their systems from exploitation.

## Latest coverage

- [CISA Warns of Active Exploitation of Oracle WebLogic Flaw](https://www.trendwatcher.in/article/5a14b996-7898-4287-b0f6-2e4ceb386567) — neutral, 2026-06-11: CISA has added a critical Oracle WebLogic vulnerability, CVE-2024-21182, to its Known Exploited Vulnerabilities catalog following reports of active attacks.
- [Cl0p exploits Oracle E‑Business Suite zero‑day, extorts hundreds of](https://www.trendwatcher.in/article/5682d183-710f-43a4-af64-6e8a16be8069) — neutral, 2026-06-11: Cl0p’s latest ransomware campaign leverages a zero‑day in Oracle E‑Business Suite, breaching dozens of organizations and prompting a large‑scale extortion
- [Oracle warns of critical PeopleSoft bug exploited by ShinyHunters](https://www.trendwatcher.in/article/5b8025e4-ec73-401e-9563-39864490bf30) — neutral, 2026-06-11: Oracle alerts customers to a zero‑day flaw in PeopleSoft that was used by the ShinyHunters group to breach over 100 organizations, many in higher education.
- [Oracle PeopleSoft zero‑day exploited in mass hack of 100+ firms](https://www.trendwatcher.in/article/a5c649e6-4efd-4014-8fcd-b6e041943964) — neutral, 2026-06-11: Oracle warned of a critical PeopleSoft flaw after the ShinyHunters group claimed to breach over 100 organizations, prompting Mandiant to alert affected
- [Google confirms Oracle breach affecting over 100 companies](https://www.trendwatcher.in/article/e156286d-e4d9-4612-828d-48aa5f4b09cf) — neutral, 2026-06-11: Google’s security unit says a zero‑day flaw in Oracle software was exploited by CL0P, compromising more than 100 organizations worldwide.
- [Four Major Companies Remain Silent on Oracle EBS Hack](https://www.trendwatcher.in/article/171527b6-31c6-4549-8400-7e6fba9d90cc) — neutral, 2026-06-11: Major firms Broadcom, Bechtel, Estée Lauder and Abbott have not commented on the Oracle E‑Business Suite breach that Cl0p claims affected dozens of
- [Cybercrime gang ShinyHunters linked to Oracle PeopleSoft and MICROS](https://www.trendwatcher.in/article/a9ba30d8-780b-4e96-9288-c2d9d8af6b48) — neutral, 2026-06-11: ShinyHunters claims to have hacked Oracle PeopleSoft at 100+ organizations and recent malware infections hit Oracle MICROS POS systems, affecting thousands of

---
Cite as: TrendWatcher, "Oracle warns of security bug that hackers abused to breach 100+ companies — News, Sentiment & Analysis", https://www.trendwatcher.in/topic/oracle-warns-of-security-bug-that-hackers-abused-to-breach-1 (retrieved 2026-09-12).
