Clop ransomware exploits Oracle E-Business Suite zero-day vulnerability for breaches.
The Clop ransomware gang has claimed a significant breach of Oracle Corporation, exploiting a critical zero-day vulnerability (CVE-2025-61882) in the Oracle E-Business Suite, which affects versions 12.2.3 to 12.2.14. This vulnerability allows unauthenticated remote code execution, posing severe risks for organizations using unpatched systems, given its high CVSS score of 9.8. Clop has reportedly targeted several high-profile companies, threatening to publicly release sensitive data unless ransoms are paid. This incident underscores the alarming trend of ransomware attacks exploiting critical software vulnerabilities, emphasizing the need for robust cybersecurity measures across industries.
