Estée Lauder discloses data breach via Oracle E-Business flaw

July 20, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: bleepingcomputer.com

Threat Risk: High
Victim: Large enterprises using Oracle E-Business Suite
Incident: Unauthorized access to the Oracle E-Business Suite resulting in the theft of sensitive HR data.
Impact: Massive exposure of highly sensitive PII, including Social Security numbers, passport numbers, and financial account details.
Attacker: Clop ransomware gang
Analysis: The breach resulted from the exploitation of CVE-2025-61882, a flaw allowing authentication bypass and remote code execution within the BI Publisher Integration component. The Clop ransomware gang leveraged this zero-day to target HR management systems across multiple high-profile organizations. This incident highlights the severe risk associated with unpatched enterprise resource planning (ERP) software.
Recommendations: Apply the latest Oracle E-Business Suite security patches immediately to remediate CVE-2025-61882; Audit ERP access logs for unauthorized activity related to BI Publisher Integration; Implement strict network segmentation for HR and financial management systems to limit lateral movement
Source: Bleeping Computer

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *