logo

Clop exploited Oracle zero-day for data theft since early August

ID: d3c39927-2287-56f0-9777-29af44f987fc

STIX ID: report--d3c39927-2287-56f0-9777-29af44f987fc

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-10-07

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

The Clop ransomware gang has been exploiting a critical unauthenticated Oracle E-Business Suite vulnerability (CVE-2025-61882) since at least August to gain remote code execution and steal sensitive documents for extortion; vendors including CrowdStrike, Mandiant and Google observed active exploitation and extortion emails, a proof-of-concept was leaked, and Oracle issued a patch and urged immediate remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.