Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Oracle E-Business Suite Zero-Day Exploited in Cl0p Attacks

Oracle has informed customers that it has patched a critical remote code execution vulnerability tracked as CVE-2025-61882.

Oracle

The recent data theft and extortion campaign targeting Oracle E-Business Suite customers has been confirmed to be the work of the notorious Cl0p ransomware group, and Oracle has admitted that the hackers have exploited a zero-day vulnerability.

The attacks targeting Oracle E-Business Suite (EBS) customers came to light last week, when Google Threat Intelligence Group (GTIG) and Mandiant warned that executives at many organizations using the enterprise resource planning product received extortion emails.

The emails, apparently coming from the Cl0p group, informed recipients that sensitive data had been stolen from their Oracle EBS instance and urged them to get in touch with the cybercriminals.

GTIG and Mandiant researchers, who found that the emails were coming from compromised accounts previously associated with the FIN11 cybercrime group, initially could not confirm that Cl0p was behind the attacks. However, the researchers have now confirmed that Cl0p is indeed responsible.

This is not surprising considering that Cl0p previously conducted several other similar campaigns, including ones targeting Cleo, MOVEit, and Fortra file transfer products through the exploitation of zero-day vulnerabilities.

Charles Carmakal, CTO of Mandiant, explained that the hackers stole data from EBS customers in August and started sending out extortion emails in late September. 

Advertisement. Scroll to continue reading.

While Oracle initially said the recent EBS data theft campaign involved exploitation of unspecified vulnerabilities patched in July, on Saturday the software giant’s CSO, Rob Duhart, confirmed that a zero-day has also been leveraged by the attackers.

The zero-day flaw is tracked as CVE-2025-61882 and it can be exploited for remote code execution by an unauthenticated attacker.

The vulnerability, which impacts Oracle E-Business Suite versions 12.2.3-12.2.14, has been assigned a ‘critical’ severity rating with a CVSS score of 9.8. The security hole impacts the BI Publishing Integration component of Oracle Concurrent Processing.

Oracle has released patches and shared indicators of compromise (IoCs) that customers can use to detect potential attacks. 

Mandiant has confirmed that the Cl0p attacks exploited vulnerabilities patched in July alongside CVE-2025-61882.

Other threat actors are now expected to add the vulnerabilities exploited in this campaign to their arsenal.

“Given the broad mass 0-day exploitation that has already occurred (and the n-day exploitation that will likely continue by other actors), irrespective of when the patch is applied, organizations should examine whether they were already compromised,” Carmakal warned.

The cybercrime groups Scattered Spider and ShinyHunters, which recently announced their retirement but continue to be active, might also be involved in the Oracle attack. The hackers created a new Telegram channel and posted what appear to be the EBS exploits used in the attack.

Related: Red Hat Confirms GitLab Instance Hack, Data Theft

Related: Broadcom Fails to Disclose Zero-Day Exploitation of VMware Vulnerability

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.