Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

Posted on November 21, 2025November 21, 2025 By CWS

The Cl0p ransomware group has claimed duty for infiltrating Broadcom’s inside techniques as a part of an ongoing exploitation marketing campaign focusing on Oracle E-Enterprise Suite vulnerabilities.

The hack makes use of a crucial zero-day vulnerability (CVE-2025-61882) rated 9.8 on the CVSS scale, permitting attackers to execute arbitrary code with out authentication.​

Broadcom, a serious semiconductor and infrastructure software program supplier, turns into the most recent high-profile sufferer in a large extortion marketing campaign that started in late September 2025.

Zero-Day Flaw Permits Unauthorized Entry

The menace actors declare to have accessed inside enterprise useful resource planning (ERP) archives, design documentation, and delicate semiconductor information.

Given Broadcom’s affect throughout telecommunications, knowledge facilities, and AI accelerator manufacturing. The potential publicity of inside documentation raises issues for provide chain integrity and companion ecosystems.​

Safety researchers from Google Risk Intelligence Group and Mandiant traced the underlying breach exercise again to July 10, 2025, with confirmed exploitation starting August 9, 2025, weeks earlier than Oracle launched patches.

The Cl0p group gathered data and moved by sufferer networks earlier than beginning a coordinated electronic mail blackmail marketing campaign in September, hitting executives at many corporations on the similar time.

warning and cyber situational consciousness

The assault exploited Oracle E-Enterprise Suite’s Enterprise Intelligence Writer integration throughout the Concurrent Processing element, granting attackers full system management.

Cl0p supplemented the zero-day with extra beforehand patched vulnerabilities to maximise its foothold throughout enterprise networks.​

The broader marketing campaign has reportedly compromised a minimum of 29 organizations, based on latest postings on the Cl0p data-leak web site.

The attackers used hacked third-party electronic mail accounts bought from infostealer markets to bypass spam filters and make their extortion emails seem extra plausible.

Oracle launched emergency patches in October 2024, although organizations operating older E-Enterprise Suite variations stay susceptible if patches haven’t been utilized.

Safety specialists suggest speedy patching and enhanced monitoring for suspicious POST requests to the/OA_HTML/SyncServlet endpoints, that are high-fidelity compromise indicators.

Comply with us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:0Day, Allegedly, Breached, Broadcom, Clop, EBusiness, Hack, Ransomware, Suite

Post navigation

Previous Post: Critical Grafana Vulnerability Let Attackers Escalate Privilege
Next Post: SquareX and Perplexity Quarrel Over Alleged Comet Browser Vulnerability

Related Posts

Microsoft Details Defence Techniques Against Indirect Prompt Injection Attacks Cyber Security News
Hackers Reportedly Demand Google Fire Two Employees, Threaten Data Leak Cyber Security News
Ransomware 2.0 How AI-Powered Attacks Are Evolving Cyber Security News
New Malware Targeting WooCommerce Sites with Malicious Plugins Steals Credit Card Data Cyber Security News
New Salty 2FA PhaaS platform Attacking Microsoft 365 Users to Steal Login Credentials Cyber Security News
Hackers Abuse Microsoft Teams to Gain Remote Access With PowerShell-based Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Leveraging WhatsApp That Silently Harvest Logs and Contact Details
  • Elite Cyber Veterans Launch Blast Security with $10M to Turn Cloud Detection into Prevention
  • PoC released for W3 Total Cache Vulnerability that Exposes 1+ Million Websites to RCE Attacks
  • CISA Confirms Exploitation of Recent Oracle Identity Manager Vulnerability
  • 800+ npm Packages and Thousands of GitHub Repos Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Leveraging WhatsApp That Silently Harvest Logs and Contact Details
  • Elite Cyber Veterans Launch Blast Security with $10M to Turn Cloud Detection into Prevention
  • PoC released for W3 Total Cache Vulnerability that Exposes 1+ Million Websites to RCE Attacks
  • CISA Confirms Exploitation of Recent Oracle Identity Manager Vulnerability
  • 800+ npm Packages and Thousands of GitHub Repos Compromised

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark