Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Canon Allegedly Breached by Clop Ransomware via Oracle E-Business Suite 0-Day Hack

Posted on November 25, 2025November 25, 2025 By CWS

Canon has formally confirmed that it was focused in the course of the widespread hacking marketing campaign exploiting a essential zero-day vulnerability in Oracle E-Enterprise Suite (EBS).

The assault, orchestrated by the infamous Clop ransomware gang, has impacted dozens of main organizations worldwide. The group listed Canon on its darkish internet leak web site, publishing the corporate’s area alongside different alleged victims.

Whereas the itemizing on the leak web site raised issues a few huge information breach, Canon clarified that the affect was contained. The digital camera and imaging big acknowledged that the compromise affected solely a particular atmosphere inside one among its subsidiaries.

In keeping with the corporate, the attackers didn’t encrypt the broader community or disrupt international operations, which distinguishes this incident from the devastating Maze ransomware assault Canon suffered in 2020.

Canon’s safety group detected the intrusion and instantly remoted the affected programs. In an announcement shared with SecurityWeek, the corporate emphasised that the breach didn’t unfold past an online server operated by a Canon U.S.A., Inc. subsidiary.

The fast containment doubtless prevented the theft of delicate buyer information or mental property, which the Clop group typically seeks for extortion.​

“We’ve got confirmed that the incident solely affected the net server, and now we have already taken safety measures and resumed service,” Canon mentioned. “As well as, we’re persevering with to research additional to make sure that there isn’t a different affect”.​

The Oracle EBS Zero-Day Exploit

The vulnerability used on this marketing campaign is tracked as CVE-2025-61882, a essential safety flaw in Oracle E-Enterprise Suite. This zero-day allowed unauthenticated attackers to execute arbitrary code remotely on susceptible servers.

Safety researchers found that Clop associates, tracked as Swish Spider, started exploiting this flaw as early as August 2025 to plant internet shells and exfiltrate information earlier than Oracle may difficulty a patch in October.​

DetailDescriptionCVE IDCVE-2025-61882CVSS Score9.8 (Vital)Affected ProductOracle E-Enterprise Suite (EBS)Affected Versions12.2.3 by means of 12.2.14Vulnerability TypeUnauthenticated Distant Code Execution (RCE)Exploit VectorNetwork (No person interplay required)

This incident is an element of a bigger “move-it-style” extortion wave the place Clop leveraged the zero-day to breach almost 30 organizations. As a substitute of deploying encryption malware instantly, the group targeted on information theft and subsequently despatched extortion emails to executives beginning in late September 2025.

These emails threatened to leak stolen paperwork until a ransom was paid. The group’s leak web site at the moment lists domains, together with Canon, suggesting these entities had been efficiently compromised in the course of the automated exploitation section.​

Indicators of Compromise (IoCs)

Indicator TypeValueDescriptionIPv4 Address200.107.207.26Malicious command and management (C2) IPIPv4 Address185.181.60.11Observed exploitation supply IPSHA256 Hash76b6d36e04e367a2334c445b51e1ecce97e4c614e88dfb4f72b104ca0f31235dMalicious zip archive containing exploit toolsSHA256 Hash6fd538e4a8e3493dda6f9fcdc96e814bdd14f3e2ef8aa46f0143bff34b882c1bPython script used for server-side exploitationFile NameFileUtils.javaMalicious internet shell downloader

Safety groups are suggested to scan their Oracle EBS environments for these indicators and apply the official patches instantly to forestall additional unauthorized entry.​

Observe us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:0Day, Allegedly, Breached, Canon, Clop, EBusiness, Hack, Oracle, Ransomware, Suite

Post navigation

Previous Post: HashiCorp Vault Vulnerability Allow Attackers to Authenticate to Vault Without Valid Credentials
Next Post: 640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack

Related Posts

New PoC Exploit Released for Sudo Chroot Privilege Escalation Vulnerability Cyber Security News
North Korean Chollima Actors Added BeaverTail and OtterCookie to Its Arsenal Cyber Security News
Hackers Posing as Google Careers Recruiter to Steal Gmail Login Details Cyber Security News
Hackers Exploiting Three-Year-Old FortiGate Vulnerability to Bypass 2FA on Firewalls Cyber Security News
Azure Apps Vulnerability Lets Hackers Create Malicious Apps Mimicking Microsoft Teams Cyber Security News
HackerOne Paid $81 In Bug Bounty With Emergence of Bionic Hackers Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data
  • Instagram Data Leak Exposes Sensitive Info of 17.5M Accounts
  • Hackers Expose All User Records from Popular Dark Web Forum
  • China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
  • xRAT Malware Attacking Windows Users Disguised as Adult Game

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data
  • Instagram Data Leak Exposes Sensitive Info of 17.5M Accounts
  • Hackers Expose All User Records from Popular Dark Web Forum
  • China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
  • xRAT Malware Attacking Windows Users Disguised as Adult Game

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark