The Clop ransomware gang has been exploiting a critical Oracle E-Business Suite (EBS) zero-day bug in data theft attacks since at least early August, according to cybersecurity company CrowdStrike. Tracked as CVE-2025-61882 and patched by Oracle over the weekend, this vulnerability was discovered in the BI Publisher Integration component of Oracle EBS's Concurrent Processing component, allowing unauthenticated attackers to gain remote code execution on unpatched systems in low-complexity attacks that don't require user interaction. However, as watchTowr Labs security researchers found while reverse-engineering a proof-of-concept (PoC) exploit leaked online by the Scattered Lapsus$ Hunters cybercrime gang (with a May 2025 timestamp), CVE-2025-61882 is actually a vulnerability chain that can let threat actors gain remote code execution without requiring authentication using a single HTTP request. On Monday, CrowdStrike analysts reported that they had first spotted the Clop ransomware gang exploiting CVE-2025-61882 as a zero-day since early August to steal sensitive documents, adding that other threat groups may have also joined the attacks. "CrowdStrike Intelligence assesses with moderate confidence that GRACEFUL SPIDER is likely involved in this campaign but cannot rule out the possibility that multiple threat actors have exploited CVE-2025-61882. The first known exploitation occurred on August 9, 2025; however, investigations remain ongoing, and this date is subject to chang...
Clop exploited Oracle zero-day for data theft since early August
BleepingComputer
·Sergiu Gatlan
·Published Oct 7, 2025
·Updated
Affected Software
1 affected component
Oracle E-Business Suite
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of a critical Oracle zero-day vulnerability by the Clop ransomware gang for data theft.
2
What security implications are discussed in the article?
The security implications include the risk of data theft and unauthorized access to sensitive information due to the exploitation of the zero-day vulnerability.
3
What specific vulnerability is highlighted in the article?
The vulnerability highlighted is tracked as CVE-2025-61882, affecting Oracle E-Business Suite.
4
What group is responsible for the attacks mentioned in the article?
The Clop ransomware gang is responsible for the data theft attacks exploiting the Oracle zero-day.
5
Since when has the exploitation been occurring according to the article?
The exploitation of the zero-day vulnerability has been occurring since at least early August.