Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

Posted on November 21, 2025November 21, 2025 By CWS

The Cl0p ransomware group has claimed duty for infiltrating Broadcom’s inside techniques as a part of an ongoing exploitation marketing campaign focusing on Oracle E-Enterprise Suite vulnerabilities.

The hack makes use of a crucial zero-day vulnerability (CVE-2025-61882) rated 9.8 on the CVSS scale, permitting attackers to execute arbitrary code with out authentication.​

Broadcom, a serious semiconductor and infrastructure software program supplier, turns into the most recent high-profile sufferer in a large extortion marketing campaign that started in late September 2025.

Zero-Day Flaw Permits Unauthorized Entry

The menace actors declare to have accessed inside enterprise useful resource planning (ERP) archives, design documentation, and delicate semiconductor information.

Given Broadcom’s affect throughout telecommunications, knowledge facilities, and AI accelerator manufacturing. The potential publicity of inside documentation raises issues for provide chain integrity and companion ecosystems.​

Safety researchers from Google Risk Intelligence Group and Mandiant traced the underlying breach exercise again to July 10, 2025, with confirmed exploitation starting August 9, 2025, weeks earlier than Oracle launched patches.

The Cl0p group gathered data and moved by sufferer networks earlier than beginning a coordinated electronic mail blackmail marketing campaign in September, hitting executives at many corporations on the similar time.

warning and cyber situational consciousness

The assault exploited Oracle E-Enterprise Suite’s Enterprise Intelligence Writer integration throughout the Concurrent Processing element, granting attackers full system management.

Cl0p supplemented the zero-day with extra beforehand patched vulnerabilities to maximise its foothold throughout enterprise networks.​

The broader marketing campaign has reportedly compromised a minimum of 29 organizations, based on latest postings on the Cl0p data-leak web site.

The attackers used hacked third-party electronic mail accounts bought from infostealer markets to bypass spam filters and make their extortion emails seem extra plausible.

Oracle launched emergency patches in October 2024, although organizations operating older E-Enterprise Suite variations stay susceptible if patches haven’t been utilized.

Safety specialists suggest speedy patching and enhanced monitoring for suspicious POST requests to the/OA_HTML/SyncServlet endpoints, that are high-fidelity compromise indicators.

Comply with us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:0Day, Allegedly, Breached, Broadcom, Clop, EBusiness, Hack, Ransomware, Suite

Post navigation

Previous Post: Critical Grafana Vulnerability Let Attackers Escalate Privilege
Next Post: SquareX and Perplexity Quarrel Over Alleged Comet Browser Vulnerability

Related Posts

FileFix Attack Exploits Windows Browser Features to Bypass Mark-of-the-Web Protection FileFix Attack Exploits Windows Browser Features to Bypass Mark-of-the-Web Protection Cyber Security News
Microsoft Teams Down – Users Face Messaging Delays and Service Disruptions Worldwide Microsoft Teams Down – Users Face Messaging Delays and Service Disruptions Worldwide Cyber Security News
NCSC Warns of ‘UMBRELLA STAND’ Malware Attacking Fortinet FortiGate Firewalls NCSC Warns of ‘UMBRELLA STAND’ Malware Attacking Fortinet FortiGate Firewalls Cyber Security News
Threat Actors Attacking Gen Z Gamers With Weaponized Versions of Popular Games Threat Actors Attacking Gen Z Gamers With Weaponized Versions of Popular Games Cyber Security News
New 7-Zip Vulnerability Enables Malicious RAR5 File to Crash Your System New 7-Zip Vulnerability Enables Malicious RAR5 File to Crash Your System Cyber Security News
Phishing Campaign Exploits OAuth Tokens in Microsoft 365 Phishing Campaign Exploits OAuth Tokens in Microsoft 365 Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark