Estée Lauder has revealed that a zero-day exploit of its Oracle E-Business Suite (EBS) instance resulted in the exfiltration of sensitive data, including personal, financial, and health information, in August 2025. The attack, which occurred before a patch was available, highlights the challenges of defending against zero-day vulnerabilities1. The fact that the exploit was used to breach a prominent company's systems underscores the severity of the threat. Oracle EBS is a widely used enterprise resource planning system, making this vulnerability a concern for numerous organizations. The breach demonstrates that even large companies with significant resources can fall victim to zero-day exploits, emphasizing the need for robust security measures. This incident matters to security practitioners because it showcases the importance of proactive defense strategies, as traditional patch-based approaches may not be sufficient to protect against zero-day threats.
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
⚡ High Priority
Why This Matters
Zero-day exploitation means the vulnerability is being used before patches exist — defenders are already behind.
References
- SecurityWeek. (2026, July 21). Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack. SecurityWeek. https://www.securityweek.com/estee-lauder-discloses-impact-from-oracle-ebs-zero-day-hack/
Original Source
SecurityWeek
Read original →