Bimbo Bakeries USA has confirmed that attackers accessed employee information through a zero-day vulnerability affecting Oracle E-Business Suite (EBS). The incident was connected to a third-party vendor using Oracle EBS, and the company determined that attackers had obtained files stored within the platform. One of the stolen files was later found to contain employee names and Social Security numbers. The incident is part of a wider exploitation campaign targeting Oracle EBS customers. The vulnerability associated with the campaign is CVE-2025-61882, a critical unauthenticated remote code execution flaw in the BI Publisher Integration component of Oracle EBS Concurrent Processing. The vulnerability has a CVSS score of 9.8 and can allow attackers to execute arbitrary code on vulnerable systems without valid credentials. According to the report, exploitation was observed before Oracle released an emergency security update in October 2025. Attackers used the flaw to access and steal files from affected Oracle EBS environments. Bimbo Bakeries discovered the exploitation on December 6, 2025, and applied Oracle's emergency patches after learning about the vulnerability. A forensic investigation continued for several months before the company confirmed on August 19, 2026, that sensitive employee information had been exposed. The company has not publicly confirmed the number of affected individuals or directly attributed the incident to Clop, although researchers have linked the broader Oracle EBS exploitation campaign to the extortion group. Organizations running Oracle EBS should verify patch status, review historical logs for suspicious BI Publisher activity, and rotate credentials associated with EBS integrations.
A new Linux malware bot named Tengu has been identified as a stealthy threat capable of turning compromised Linux servers, embedded systems, and IoT-adjacent devices into DDoS atta...
The Linux kernel development team has officially ended support for the Linux Kernel 7.1 branch, meaning it will no longer receive security patches, bug fixes, or maintenance update...
Threat actors are abusing legitimate Google services to conceal phishing campaigns designed to steal corporate credentials and, in some cases, install remote-access software. The c...