logo

Addressing CL0P Extortion Campaign Targeting Oracle EBS CVE-2025-61882

ID: effd4ebe-5051-5417-bbc0-c395b2b20db6

STIX ID: report--effd4ebe-5051-5417-bbc0-c395b2b20db6

Feed Name: Cybereason Blog

Threat Score
80/100

Date Published: 2025-10-05

Date Updated: 2026-04-27

Author: Cybereason Consulting Team

...
...

**Executive summary:** Cybereason reports that CL0P exploited one or more Oracle E-Business Suite vulnerabilities (including CVE-2025-61882) to achieve unauthenticated remote code execution, enumerate and exfiltrate on-premise EBS data at scale, and conduct a widespread extortion campaign via mass emails using compromised sender accounts; Oracle and incident responders recommend immediate patching (July 2025 CPU and the Oct 5, 2025 fix), SSO/MFA, and DFIR investigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.