Threat Intelligence Brief
Curated summary with source attribution
Source: techradar.com
Threat Risk: High
Victim: Estée Lauder
Incident: Unauthorized access to an HR management platform resulting in a massive data breach.
Impact: Theft of highly sensitive personal, financial, and health data, including SSNs and bank account numbers.
Attacker: Unidentified threat actors
Analysis: Threat actors exploited CVE-2025-61882, a critical pre-authentication RCE vulnerability in the Oracle E-Business Suite, to access HR management systems. This incident was part of a wider campaign targeting over 100 organizations. The breach is particularly concerning due to the significant delay between the initial intrusion in August 2025 and its disclosure in June 2026.
Recommendations: Apply the emergency patch for CVE-2025-61882 to all Oracle E-Business Suite installations.; Perform a comprehensive forensic audit of ERP and HR system logs to detect signs of historical unauthorized access.; Implement strict network segmentation and enhanced monitoring for critical internal business applications.
Source: TechRadar
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source