• News/
  • https://www.bleepingcomputer.com/news/security/oracle-zero-day-exploited-in-clop-data-theft-attacks-since-early-august/

Clop exploited Oracle zero-day for data theft since early August

BleepingComputer
·
Sergiu Gatlan
·
Published Oct 7, 2025
·
Updated

The Clop ransomware gang has been exploiting a critical Oracle E-Business Suite (EBS) zero-day bug in data theft attacks since at least early August, according to cybersecurity company CrowdStrike. Tracked as CVE-2025-61882 and patched by Oracle over the weekend, this vulnerability was discovered in the BI Publisher Integration component of Oracle EBS's Concurrent Processing component, allowing unauthenticated attackers to gain remote code execution on unpatched systems in low-complexity attacks that don't require user interaction. However, as watchTowr Labs security researchers found while reverse-engineering a proof-of-concept (PoC) exploit leaked online by the Scattered Lapsus$ Hunters cybercrime gang (with a May 2025 timestamp), CVE-2025-61882 is actually a vulnerability chain that can let threat actors gain remote code execution without requiring authentication using a single HTTP request. On Monday, CrowdStrike analysts reported that they had first spotted the Clop ransomware gang exploiting CVE-2025-61882 as a zero-day since early August to steal sensitive documents, adding that other threat groups may have also joined the attacks. "CrowdStrike Intelligence assesses with moderate confidence that GRACEFUL SPIDER is likely involved in this campaign but cannot rule out the possibility that multiple threat actors have exploited CVE-2025-61882. The first known exploitation occurred on August 9, 2025; however, investigations remain ongoing, and this date is subject to chang...

Read full article

Affected Software

1 affected component
Oracle E-Business Suite
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of a critical Oracle zero-day vulnerability by the Clop ransomware gang for data theft.

2

What security implications are discussed in the article?

The security implications include the risk of data theft and unauthorized access to sensitive information due to the exploitation of the zero-day vulnerability.

3

What specific vulnerability is highlighted in the article?

The vulnerability highlighted is tracked as CVE-2025-61882, affecting Oracle E-Business Suite.

4

What group is responsible for the attacks mentioned in the article?

The Clop ransomware gang is responsible for the data theft attacks exploiting the Oracle zero-day.

5

Since when has the exploitation been occurring according to the article?

The exploitation of the zero-day vulnerability has been occurring since at least early August.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203