Clop exploited Oracle zero-day for data theft since early August
ID: d3c39927-2287-56f0-9777-29af44f987fc
STIX ID: report--d3c39927-2287-56f0-9777-29af44f987fc
Feed Name: Bleeping Computer
Threat Score
The Clop ransomware gang has been exploiting a critical unauthenticated Oracle E-Business Suite vulnerability (CVE-2025-61882) since at least August to gain remote code execution and steal sensitive documents for extortion; vendors including CrowdStrike, Mandiant and Google observed active exploitation and extortion emails, a proof-of-concept was leaked, and Oracle issued a patch and urged immediate remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
