Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day Vulnerability in the Wild

Posted on October 7, 2025October 7, 2025 By CWS

Oracle has issued an emergency safety alert for a vital zero-day vulnerability (CVE-2025-61882) in its E-Enterprise Suite after the infamous Cl0p ransomware group started extorting clients who didn’t patch their techniques. 

The vulnerability, carrying a most CVSS rating of 9.8, impacts the Enterprise Intelligence Writer (BI Writer) Integration part and permits distant code execution with out authentication.

The vulnerability CVE-2025-61882 represents a major menace to Oracle E-Enterprise Suite deployments worldwide. Safety researchers have confirmed that public proof-of-concept exploits at the moment are out there, dramatically growing the danger for unpatched techniques. 

The flaw impacts Oracle EBS variations 12.2.3 via 12.2.14, requiring organizations to implement Oracle’s October 2023 CPU as a prerequisite earlier than making use of the newest safety patches.

Tenable investigation revealed that Cl0p ransomware operators have been systematically concentrating on Oracle E-Enterprise Suite installations, leveraging this zero-day vulnerability to realize unauthorized entry to enterprise techniques. 

Cl0p Exploiting Unpatched Oracle EBS Vulnerability

The assault marketing campaign got here to mild when a number of Oracle clients acquired extortion emails from the Cl0p group, claiming to have efficiently infiltrated their EBS environments and stolen delicate enterprise information.

Tenable acknowledged that the Oracle Concurrent Processing part vulnerability permits attackers to execute arbitrary code remotely with out requiring authentication credentials, making it a beautiful goal for cybercriminals. 

Safety specialists emphasize that the mixture of widespread Oracle EBS deployment in enterprise environments and the vulnerability’s excessive severity rating creates an ideal storm for large-scale assaults.

The Cl0p ransomware group, also referred to as TA505 and FIN11, has established a sample of concentrating on zero-day vulnerabilities in enterprise file switch and enterprise software software program. 

Earlier campaigns efficiently exploited vulnerabilities in Accellion, MOVEit Switch, GoAnywhere, and Cleo platforms, demonstrating the group’s refined functionality to establish and weaponize high-impact safety flaws.

Threat FactorsDetailsAffected ProductsOracle E-Enterprise Suite, Enterprise Intelligence Writer (BI Writer) Integration 12.2.3 via 12.2.14ImpactRemote Code ExecutionExploit PrerequisitesNetwork entry to Oracle EBS occasion, No authentication requiredCVSS 3.1 Score9.8 (Crucial)

Mitigations

Oracle’s safety advisory consists of a number of indicators of compromise (IOCs) to assist organizations detect potential intrusions. 

The corporate has launched patches addressing not solely CVE-2025-61882 but in addition 9 further vulnerabilities from the July 2025 Crucial Patch Replace that will have been exploited along side the zero-day flaw.

Safety groups should prioritize quick patching of affected Oracle EBS techniques, significantly given the supply of public exploits. 

Organizations also needs to implement community monitoring for suspicious exercise concentrating on the BI Writer Integration part and evaluate entry logs for unauthorized administrative actions. 

The incident underscores the vital significance of sustaining present patch ranges and implementing defense-in-depth methods to guard in opposition to zero-day exploitation campaigns.

Cyber Consciousness Month Provide: Upskill With 100+ Premium Cybersecurity Programs From EHA’s Diamond Membership: Be a part of As we speak

Cyber Security News Tags:0Day, Actively, Cl0p, EBusiness, Exploiting, Oracle, Ransomware, Suite, Vulnerability, Wild

Post navigation

Previous Post: Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks
Next Post: OpenSSH Vulnerability Exploited Via ProxyCommand to Execute Remote Code

Related Posts

New SHUYAL Attacking 19 Popular Browsers to Steal Login Credentials Cyber Security News
New Malware Attack Leverages SVGs, Email Attachments to Deliver XWorm and Remcos RAT Cyber Security News
Chrome Emergency Update to Patch Multiple Vulnerabilities that Enable Remote Code Execution Cyber Security News
Preventing Phishing Attacks on Cryptocurrency Exchanges Cyber Security News
Securing Remote Endpoints in Distributed Enterprise Systems Cyber Security News
Qilin Emerged as The Most Active Group, Exploiting Unpatched Fortinet Vulnerabilities Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Leveraging WhatsApp That Silently Harvest Logs and Contact Details
  • Elite Cyber Veterans Launch Blast Security with $10M to Turn Cloud Detection into Prevention
  • PoC released for W3 Total Cache Vulnerability that Exposes 1+ Million Websites to RCE Attacks
  • CISA Confirms Exploitation of Recent Oracle Identity Manager Vulnerability
  • 800+ npm Packages and Thousands of GitHub Repos Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Leveraging WhatsApp That Silently Harvest Logs and Contact Details
  • Elite Cyber Veterans Launch Blast Security with $10M to Turn Cloud Detection into Prevention
  • PoC released for W3 Total Cache Vulnerability that Exposes 1+ Million Websites to RCE Attacks
  • CISA Confirms Exploitation of Recent Oracle Identity Manager Vulnerability
  • 800+ npm Packages and Thousands of GitHub Repos Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark