Clop extortion campaign targets Oracle E-Business Suite
Summary
Hide ▲
Show ▼
The Clop ransomware gang has been exploiting multiple vulnerabilities in Oracle E-Business Suite since at least August 2025, including the zero-day vulnerability CVE-2025-61882. The gang has been sending extortion emails to executives at multiple organizations, claiming to have stolen sensitive data. The campaign involves a high-volume email blast from hundreds of compromised accounts, some previously linked to the FIN11 threat group. The emails contain contact addresses known to be listed on the Clop ransomware gang's data leak site. CrowdStrike attributes the exploitation of CVE-2025-61882 to the Cl0p ransomware gang with moderate confidence, and the first known exploitation occurred on August 9, 2025. The exploit involves an HTTP request to /OA_HTML/SyncServlet, resulting in an authentication bypass. Oracle has released an emergency patch for the zero-day vulnerability and shared indicators of compromise. The exploit was leaked by a group called Scattered Lapsus$ Hunters, raising questions about their potential collaboration with Clop. Envoy Air, a subsidiary of American Airlines, confirms that data was compromised from its Oracle E-Business Suite application after the Clop extortion gang listed American Airlines on its data leak site. Envoy Air stated that no sensitive or customer data was affected, but a limited amount of business information and commercial contact details may have been compromised. The Clop gang is also extorting Harvard University, with the university confirming that the incident impacts a limited number of parties associated with a small administrative unit. GlobalLogic, a digital engineering services provider, has notified over 10,000 current and former employees that their data was stolen in an Oracle E-Business Suite (EBS) data breach. The attackers exploited an Oracle EBS zero-day vulnerability (CVE-2025-61882) to steal personal information belonging to 10,471 employees. GlobalLogic's investigation identified access and exfiltration on October 9, 2025, with the earliest date of threat actor activity as July 10, 2025, and the most recent activity occurring on August 20, 2025. The stolen data includes names, addresses, phone numbers, emergency contact details, email addresses, dates of birth, nationalities, countries of birth, passport information, national identifiers or tax identifiers (e.g., Social Security Numbers), salary information, and bank account details. Clop has yet to add GlobalLogic to its leak site, suggesting the company is still negotiating with the threat group or has already paid a ransom. The Washington Post is also among the victims, with nearly 10,000 employees and contractors affected by the data breach. The hackers leveraged a then-zero-day vulnerability in Oracle E-Business Suite software, stole data, and attempted to extort the firm in late September. The compromised data includes full names, bank account numbers and routing numbers, Social Security numbers (SSNs), and tax and ID numbers. Logitech International S.A. confirmed a data breach after a cyberattack by the Clop extortion gang, which exploited a third-party zero-day vulnerability in Oracle E-Business Suite. Logitech filed a Form 8-K with the U.S. Securities and Exchange Commission confirming the data breach. The breach likely includes limited information about employees, consumers, customers, and suppliers, but not sensitive data like national ID numbers or credit card information. Clop added Logitech to its data-leak extortion site, leaking almost 1.8 TB of data allegedly stolen from the company. Logitech confirmed that the breach occurred through a third-party zero-day vulnerability that was patched as soon as a fix was available. Cox Enterprises detected a data breach in late September 2025, which occurred between August 9-14, 2025, due to a zero-day vulnerability in Oracle E-Business Suite. The Cl0p ransomware gang has taken credit for exploiting CVE-2025-61882 as a zero-day vulnerability in Oracle E-Business Suite. The threat actor added Cox Enterprises to their data leak website on the dark web on October 27 and published the stolen information. Cl0p listed 29 new companies as their victims earlier today, including major organizations in the automotive, software, and technology sectors. Cox Enterprises is offering identity theft protection and credit monitoring services through IDX at no cost for 12 months to 9,479 impacted individuals. Canon has confirmed being targeted in the recent Oracle E-Business Suite (EBS) hacking campaign. The incident is limited to a subsidiary of Canon U.S.A., Inc., and only affected the web server. Canon has taken security measures and resumed service, but is continuing to investigate further to ensure that there is no other impact. No Canon data has been leaked at the time of writing. Canon was previously targeted in a ransomware attack back in 2020, where hackers stole employee information from the firm’s systems. More than 100 organizations have been named to date on the Cl0p ransomware website as alleged victims of the campaign. Nearly half of the named organizations are major companies in sectors such as IT and telecoms, heavy industry and manufacturing, healthcare and pharma, retail, automotive and transportation, media, and energy and utilities. The United Kingdom’s National Health Service (NHS) is conducting an investigation but has yet to confirm a data breach. The list of big companies that have yet to publicly confirm a data breach includes Michelin, Broadcom, and Bechtel. Cl0p has been the public-facing group to take credit for the Oracle campaign, but an unknown cluster of a threat actor tracked as FIN11 is believed to be behind the attacks. FIN11 conducted similar campaigns targeting other widely used enterprise products in the past. Organizations are typically not listed on the Cl0p website without cause, but the actual scope of the breach may be exaggerated by the threat actors. Dartmouth College has disclosed a data breach after the Clop extortion gang leaked data allegedly stolen from the school's Oracle E-Business Suite servers on its dark web leak site. The private Ivy League research university, founded in 1769, has an endowment of $9 billion as of June 30, 2025, over 40 academic departments and programs, and more than 4,000 undergraduate students, with a 7:1 undergraduate-to-faculty ratio. In a breach notification letter filed with the office of Maine's Attorney General, Dartmouth says the attackers exploited an Oracle E-Business Suite (EBS) zero-day vulnerability to steal personal information belonging to 1,494 individuals. The total number of people potentially impacted by this data breach is likely much larger, given that the school is headquartered in Hanover, New Hampshire, and it hasn't yet filed a breach notice with the state's Attorney General. "Through the investigation, we determined that an unauthorized actor took certain files between August 9, 2025, and August 12, 2025. We reviewed the files and on October 30, 2025, identified one or more that contained your name and Social Security number," the college says in letters mailed to those affected by the data leak. In a separate appendix filed with Maine's AG, Dartmouth added that the threat actors also stole documents containing the financial account information of impacted individuals. A Dartmouth College spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today regarding the ransom demanded by the Clop gang and the total number of individuals impacted by the breach. The incident is part of a much larger extortion campaign in which the Clop ransomware gang has exploited a zero-day flaw (CVE-2025-61882) since early August 2025 to steal sensitive files from many victims' Oracle EBS platforms. While Clop has yet to disclose the total number of impacted organizations, Google Threat Intelligence Group chief analyst John Hultquist has told BleepingComputer that dozens of organizations were likely breached. The extortion group has also targeted Harvard University, The Washington Post, Logitech, GlobalLogic, and American Airlines subsidiary Envoy Air in this campaign, with their data also leaked online and now available for download via Torrent.
Timeline
-
17.10.2025 22:11 1 articles · 1mo ago
Clop ransomware operation history of exploiting zero-day vulnerabilities
The Clop ransomware operation, also tracked as TA505, Cl0p, and FIN11, launched in 2019 when it began breaching corporate networks to deploy a variant of the CryptoMix ransomware and steal data. Since 2020, the extortion gang shifted from primarily ransomware to exploiting zero-day vulnerabilities in secure file transfer or data storage platforms to steal data. Notable campaigns include exploiting zero-days in Accellion FTA, SolarWinds Serv-U FTP, GoAnywhere MFT, MOVEit Transfer, and Cleo file transfer products.
Show sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
-
13.10.2025 14:14 3 articles · 1mo ago
Clop extortion gang lists Harvard University in data leak site
The Clop gang is also extorting Harvard University, with the university confirming that the incident impacts a limited number of parties associated with a small administrative unit. Envoy Air, a subsidiary of American Airlines, confirms that data was compromised from its Oracle E-Business Suite application after the Clop extortion gang listed American Airlines on its data leak site.
Show sources
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
-
06.10.2025 04:37 8 articles · 1mo ago
Oracle patches zero-day vulnerability exploited in Clop data theft attacks
The campaign followed months of intrusion activity targeting EBS customer environments, dating as far back as July 10, 2025. After Oracle released a Critical Patch Update in July 2025, which addressed nine flaws affecting EBS, Mandiant observed more likely exploitation attempts. Threat actors began exploiting the zero-day CVE-2025-61882 against Oracle EBS customers as early as August 9, 2025, weeks before a patch was made available. GTIG assessed that Oracle EBS servers updated through the patch are likely no longer vulnerable to known exploitation chains. GlobalLogic's investigation identified access and exfiltration on October 9, 2025, with the earliest date of threat actor activity as July 10, 2025, and the most recent activity occurring on August 20, 2025.
Show sources
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
-
02.10.2025 06:13 23 articles · 1mo ago
Clop extortion emails claim theft of Oracle E-Business Suite data
Envoy Air, a subsidiary of American Airlines, confirms that data was compromised from its Oracle E-Business Suite application after the Clop extortion gang listed American Airlines on its data leak site. Envoy Air stated that no sensitive or customer data was affected, but a limited amount of business information and commercial contact details may have been compromised. The Clop gang is also extorting Harvard University, with the university confirming that the incident impacts a limited number of parties associated with a small administrative unit. GlobalLogic, a digital engineering services provider, has notified over 10,000 current and former employees that their data was stolen in an Oracle E-Business Suite (EBS) data breach. The attackers exploited an Oracle EBS zero-day vulnerability (CVE-2025-61882) to steal personal information belonging to 10,471 employees. GlobalLogic's investigation identified access and exfiltration on October 9, 2025, with the earliest date of threat actor activity as July 10, 2025, and the most recent activity occurring on August 20, 2025. The stolen data includes names, addresses, phone numbers, emergency contact details, email addresses, dates of birth, nationalities, countries of birth, passport information, national identifiers or tax identifiers (e.g., Social Security Numbers), salary information, and bank account details. Clop has yet to add GlobalLogic to its leak site, suggesting the company is still negotiating with the threat group or has already paid a ransom. The Washington Post is also among the victims, with nearly 10,000 employees and contractors affected by the data breach. The hackers leveraged a then-zero-day vulnerability in Oracle E-Business Suite software, stole data, and attempted to extort the firm in late September. The compromised data includes full names, bank account numbers and routing numbers, Social Security numbers (SSNs), and tax and ID numbers. Logitech International S.A. confirmed a data breach after a cyberattack by the Clop extortion gang, which exploited a third-party zero-day vulnerability in Oracle E-Business Suite. Logitech filed a Form 8-K with the U.S. Securities and Exchange Commission confirming the data breach. The breach likely includes limited information about employees, consumers, customers, and suppliers, but not sensitive data like national ID numbers or credit card information. Clop added Logitech to its data-leak extortion site, leaking almost 1.8 TB of data allegedly stolen from the company. Logitech confirmed that the breach occurred through a third-party zero-day vulnerability that was patched as soon as a fix was available. Cox Enterprises detected a data breach in late September 2025, which occurred between August 9-14, 2025, due to a zero-day vulnerability in Oracle E-Business Suite. The Cl0p ransomware gang has taken credit for exploiting CVE-2025-61882 as a zero-day vulnerability in Oracle E-Business Suite. The threat actor added Cox Enterprises to their data leak website on the dark web on October 27 and published the stolen information. Cl0p listed 29 new companies as their victims earlier today, including major organizations in the automotive, software, and technology sectors. Cox Enterprises is offering identity theft protection and credit monitoring services through IDX at no cost for 12 months to 9,479 impacted individuals. Canon has confirmed being targeted in the recent Oracle E-Business Suite (EBS) hacking campaign. The incident is limited to a subsidiary of Canon U.S.A., Inc., and only affected the web server. Canon has taken security measures and resumed service, but is continuing to investigate further to ensure that there is no other impact. No Canon data has been leaked at the time of writing. Canon was previously targeted in a ransomware attack back in 2020, where hackers stole employee information from the firm’s systems. More than 100 organizations have been named to date on the Cl0p ransomware website as alleged victims of the campaign. Nearly half of the named organizations are major companies in sectors such as IT and telecoms, heavy industry and manufacturing, healthcare and pharma, retail, automotive and transportation, media, and energy and utilities. The United Kingdom’s National Health Service (NHS) is conducting an investigation but has yet to confirm a data breach. The list of big companies that have yet to publicly confirm a data breach includes Michelin, Broadcom, and Bechtel. Cl0p has been the public-facing group to take credit for the Oracle campaign, but an unknown cluster of a threat actor tracked as FIN11 is believed to be behind the attacks. FIN11 conducted similar campaigns targeting other widely used enterprise products in the past. Organizations are typically not listed on the Cl0p website without cause, but the actual scope of the breach may be exaggerated by the threat actors. Dartmouth College has disclosed a data breach after the Clop extortion gang leaked data allegedly stolen from the school's Oracle E-Business Suite servers on its dark web leak site. The private Ivy League research university, founded in 1769, has an endowment of $9 billion as of June 30, 2025, over 40 academic departments and programs, and more than 4,000 undergraduate students, with a 7:1 undergraduate-to-faculty ratio. In a breach notification letter filed with the office of Maine's Attorney General, Dartmouth says the attackers exploited an Oracle E-Business Suite (EBS) zero-day vulnerability to steal personal information belonging to 1,494 individuals. The total number of people potentially impacted by this data breach is likely much larger, given that the school is headquartered in Hanover, New Hampshire, and it hasn't yet filed a breach notice with the state's Attorney General. "Through the investigation, we determined that an unauthorized actor took certain files between August 9, 2025, and August 12, 2025. We reviewed the files and on October 30, 2025, identified one or more that contained your name and Social Security number," the college says in letters mailed to those affected by the data leak. In a separate appendix filed with Maine's AG, Dartmouth added that the threat actors also stole documents containing the financial account information of impacted individuals. A Dartmouth College spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today regarding the ransom demanded by the Clop gang and the total number of individuals impacted by the breach. The incident is part of a much larger extortion campaign in which the Clop ransomware gang has exploited a zero-day flaw (CVE-2025-61882) since early August 2025 to steal sensitive files from many victims' Oracle EBS platforms. While Clop has yet to disclose the total number of impacted organizations, Google Threat Intelligence Group chief analyst John Hultquist has told BleepingComputer that dozens of organizations were likely breached. The extortion group has also targeted Harvard University, The Washington Post, Logitech, GlobalLogic, and American Airlines subsidiary Envoy Air in this campaign, with their data also leaked online and now available for download via Torrent.
Show sources
- Clop extortion emails claim theft of Oracle E-Business Suite data — www.bleepingcomputer.com — 02.10.2025 06:13
- Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware — thehackernews.com — 02.10.2025 14:25
- Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks — www.securityweek.com — 03.10.2025 12:55
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
Information Snippets
-
The extortion campaign began in late September 2025.
First reported: 02.10.2025 06:134 sources, 14 articlesShow sources
- Clop extortion emails claim theft of Oracle E-Business Suite data — www.bleepingcomputer.com — 02.10.2025 06:13
- Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware — thehackernews.com — 02.10.2025 14:25
- Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks — www.securityweek.com — 03.10.2025 12:55
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
-
The emails were sent from a large number of compromised email accounts.
First reported: 02.10.2025 06:134 sources, 17 articlesShow sources
- Clop extortion emails claim theft of Oracle E-Business Suite data — www.bleepingcomputer.com — 02.10.2025 06:13
- Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware — thehackernews.com — 02.10.2025 14:25
- Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks — www.securityweek.com — 03.10.2025 12:55
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
At least one compromised account has been previously associated with the FIN11 threat group.
First reported: 02.10.2025 06:134 sources, 18 articlesShow sources
- Clop extortion emails claim theft of Oracle E-Business Suite data — www.bleepingcomputer.com — 02.10.2025 06:13
- Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware — thehackernews.com — 02.10.2025 14:25
- Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks — www.securityweek.com — 03.10.2025 12:55
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
-
The emails contain contact addresses known to be listed on the Clop ransomware gang's data leak site.
First reported: 02.10.2025 06:134 sources, 18 articlesShow sources
- Clop extortion emails claim theft of Oracle E-Business Suite data — www.bleepingcomputer.com — 02.10.2025 06:13
- Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware — thehackernews.com — 02.10.2025 14:25
- Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks — www.securityweek.com — 03.10.2025 12:55
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
-
The Clop ransomware gang is known for exploiting zero-day vulnerabilities in secure file transfer platforms to steal data.
First reported: 02.10.2025 06:133 sources, 10 articlesShow sources
- Clop extortion emails claim theft of Oracle E-Business Suite data — www.bleepingcomputer.com — 02.10.2025 06:13
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
-
The most recent campaign associated with Clop was in October 2024, exploiting two Cleo file transfer zero-days.
First reported: 02.10.2025 06:133 sources, 12 articlesShow sources
- Clop extortion emails claim theft of Oracle E-Business Suite data — www.bleepingcomputer.com — 02.10.2025 06:13
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
-
The campaign began on or before September 29, 2025.
First reported: 02.10.2025 14:254 sources, 17 articlesShow sources
- Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware — thehackernews.com — 02.10.2025 14:25
- Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks — www.securityweek.com — 03.10.2025 12:55
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
-
The extortion emails are part of a "high-volume email campaign" launched from hundreds of compromised accounts.
First reported: 02.10.2025 14:254 sources, 16 articlesShow sources
- Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware — thehackernews.com — 02.10.2025 14:25
- Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks — www.securityweek.com — 03.10.2025 12:55
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
FIN11, a subset within the TA505 group, has engaged in ransomware and extortion attacks since 2020.
First reported: 02.10.2025 14:254 sources, 16 articlesShow sources
- Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware — thehackernews.com — 02.10.2025 14:25
- Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks — www.securityweek.com — 03.10.2025 12:55
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
FIN11 has previously distributed malware families like FlawedAmmyy, FRIENDSPEAK, and MIXLABEL.
First reported: 02.10.2025 14:253 sources, 13 articlesShow sources
- Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware — thehackernews.com — 02.10.2025 14:25
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
The attackers may have compromised user emails and abused the default password reset function to gain valid credentials of internet-facing Oracle E-Business Suite portals.
First reported: 02.10.2025 14:253 sources, 15 articlesShow sources
- Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware — thehackernews.com — 02.10.2025 14:25
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
The Clop ransomware gang has exploited zero-day flaws in Accellion FTA, SolarWinds Serv-U FTP, Fortra GoAnywhere MFT, and Progress MOVEit Transfer platforms.
First reported: 02.10.2025 14:254 sources, 15 articlesShow sources
- Google Mandiant Probes New Oracle Extortion Wave Possibly Linked to Cl0p Ransomware — thehackernews.com — 02.10.2025 14:25
- Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks — www.securityweek.com — 03.10.2025 12:55
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
Oracle has confirmed that known vulnerabilities in its E-Business Suite may have been exploited in the recent extortion attacks.
First reported: 03.10.2025 12:554 sources, 14 articlesShow sources
- Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks — www.securityweek.com — 03.10.2025 12:55
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
Oracle's July 2025 Critical Patch Update addressed roughly 200 vulnerabilities, including nine for E-Business Suite.
First reported: 03.10.2025 12:554 sources, 14 articlesShow sources
- Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks — www.securityweek.com — 03.10.2025 12:55
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
Three of the E-Business Suite vulnerabilities fixed in July 2025 can be exploited remotely without authentication, rated as medium severity.
First reported: 03.10.2025 12:554 sources, 14 articlesShow sources
- Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks — www.securityweek.com — 03.10.2025 12:55
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
Three other E-Business Suite vulnerabilities fixed in July 2025 are rated as high severity, requiring no user interaction for exploitation.
First reported: 03.10.2025 12:554 sources, 14 articlesShow sources
- Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks — www.securityweek.com — 03.10.2025 12:55
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
Oracle's investigation into the extortion emails is ongoing, with no confirmed data breach as of October 3, 2025.
First reported: 03.10.2025 12:554 sources, 14 articlesShow sources
- Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks — www.securityweek.com — 03.10.2025 12:55
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
Oracle has linked the extortion campaign to E-Business Suite vulnerabilities patched in July 2025.
First reported: 03.10.2025 14:003 sources, 13 articlesShow sources
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
Rob Duhart, Oracle's Chief Security Officer, confirmed that customers received extortion emails from the Clop gang.
First reported: 03.10.2025 14:003 sources, 13 articlesShow sources
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
Oracle advised customers to update their software and contact support for further assistance.
First reported: 03.10.2025 14:003 sources, 13 articlesShow sources
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
The July 2025 Critical Patch Update addressed nine security flaws in E-Business Suite, including three remotely exploitable vulnerabilities.
First reported: 03.10.2025 14:003 sources, 13 articlesShow sources
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
Mandiant and GTIG confirmed that executives at multiple companies received extortion emails.
First reported: 02.10.2025 17:453 sources, 14 articlesShow sources
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
The extortion emails claim to have breached Oracle E-Business Suite and copied sensitive documents.
First reported: 02.10.2025 17:454 sources, 15 articlesShow sources
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
-
Clop claimed involvement in the extortion campaign, linking it to a bug in an Oracle product.
First reported: 03.10.2025 14:004 sources, 14 articlesShow sources
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
Clop's previous campaigns targeted zero-day vulnerabilities in Cleo, Accellion, GoAnywhere, and MOVEit Transfer.
First reported: 03.10.2025 14:004 sources, 14 articlesShow sources
- Oracle links Clop extortion attacks to July 2025 vulnerabilities — www.bleepingcomputer.com — 03.10.2025 15:14
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
-
The threat actor claims to have stolen sensitive data from Oracle E-Business Suite.
First reported: 02.10.2025 17:454 sources, 14 articlesShow sources
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
Mandiant and GTIG are investigating the claims but have not yet gathered enough evidence to substantiate them.
First reported: 02.10.2025 17:454 sources, 13 articlesShow sources
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
-
Charles Carmakal, CTO of Mandiant at Google Cloud, confirmed the high-volume email campaign from hundreds of compromised accounts.
First reported: 02.10.2025 17:453 sources, 13 articlesShow sources
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
The emails contain contact information verified to be listed on the Clop data leak site, suggesting an association with Clop.
First reported: 02.10.2025 17:453 sources, 13 articlesShow sources
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
Attribution in financially motivated cybercrime is complex, and actors often mimic established groups like Clop.
First reported: 02.10.2025 17:453 sources, 13 articlesShow sources
- Extortion Emails Sent to Executives by Self-Proclaimed Clop Gang Member — www.infosecurity-magazine.com — 02.10.2025 17:45
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
The July 2025 Critical Patch Update addressed 309 vulnerabilities across Oracle's product range.
First reported: 03.10.2025 14:003 sources, 12 articlesShow sources
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
The nine vulnerabilities in Oracle E-Business Suite include three critical and three remotely exploitable without authentication.
First reported: 03.10.2025 14:003 sources, 12 articlesShow sources
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
The vulnerabilities are in various components such as Oracle Lease and Finance Management, Oracle Mobile Field Service, Oracle Universal Work Queue, Oracle Applications Framework, Oracle iStore, Oracle MES for Process Manufacturing, Oracle CRM Technical Foundation.
First reported: 03.10.2025 14:004 sources, 13 articlesShow sources
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
Oracle's CSO, Rob Duhart, confirmed that some Oracle EBS customers have received extortion emails.
First reported: 03.10.2025 14:003 sources, 12 articlesShow sources
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
The investigation suggests the attackers may be leveraging established cybercriminal infrastructure.
First reported: 03.10.2025 14:003 sources, 12 articlesShow sources
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
The malicious emails include contact details that match addresses listed on the Clop ransomware group's data leak site, hinting at a possible connection to the notorious gang.
First reported: 03.10.2025 14:003 sources, 12 articlesShow sources
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
The attackers may be impersonating or mimicking well-known ransomware brands to enhance credibility and coercion.
First reported: 03.10.2025 14:003 sources, 12 articlesShow sources
- Hackers Target Unpatched Flaws in Oracle E-Business Suite — www.infosecurity-magazine.com — 03.10.2025 14:00
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
Oracle has released an emergency update to address the zero-day vulnerability CVE-2025-61882 in Oracle E-Business Suite.
First reported: 06.10.2025 04:373 sources, 11 articlesShow sources
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
The zero-day vulnerability CVE-2025-61882 allows for unauthenticated remote code execution in Oracle E-Business Suite.
First reported: 06.10.2025 04:373 sources, 11 articlesShow sources
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
The zero-day vulnerability CVE-2025-61882 was actively exploited in Clop data theft attacks in August 2025.
First reported: 06.10.2025 04:373 sources, 11 articlesShow sources
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
-
The Clop ransomware gang exploited multiple vulnerabilities in Oracle E-Business Suite, including those patched in July 2025 and the zero-day CVE-2025-61882.
First reported: 06.10.2025 04:373 sources, 15 articlesShow sources
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Oracle has shared indicators of compromise for the zero-day exploitation, including IP addresses and exploit files.
First reported: 06.10.2025 04:373 sources, 12 articlesShow sources
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
-
The exploit for the zero-day vulnerability was leaked by a group called Scattered Lapsus$ Hunters.
First reported: 06.10.2025 04:373 sources, 12 articlesShow sources
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
-
The exploit archive contains Python scripts used to exploit a vulnerable Oracle E-Business Suite instance and open a reverse shell.
First reported: 06.10.2025 04:373 sources, 12 articlesShow sources
- Oracle patches EBS zero-day exploited in Clop data theft attacks — www.bleepingcomputer.com — 06.10.2025 04:37
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
-
The Clop ransomware gang exploited the Oracle E-Business Suite vulnerability CVE-2025-61882 in August 2025.
First reported: 06.10.2025 08:153 sources, 14 articlesShow sources
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The vulnerability allows for unauthenticated remote code execution in Oracle E-Business Suite.
First reported: 06.10.2025 08:153 sources, 13 articlesShow sources
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Oracle has shared indicators of compromise for the zero-day exploitation, including IP addresses and exploit files.
First reported: 06.10.2025 08:153 sources, 13 articlesShow sources
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The exploit for the zero-day vulnerability was leaked by a group called Scattered Lapsus$ Hunters.
First reported: 06.10.2025 08:153 sources, 14 articlesShow sources
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The exploit archive contains Python scripts used to exploit a vulnerable Oracle E-Business Suite instance and open a reverse shell.
First reported: 06.10.2025 08:153 sources, 14 articlesShow sources
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks — thehackernews.com — 06.10.2025 08:15
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The Clop ransomware gang exploited multiple vulnerabilities in Oracle E-Business Suite, including those patched in July 2025 and the zero-day CVE-2025-61882.
First reported: 06.10.2025 14:383 sources, 13 articlesShow sources
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The zero-day vulnerability CVE-2025-61882 allows for unauthenticated remote code execution in Oracle E-Business Suite.
First reported: 06.10.2025 14:384 sources, 14 articlesShow sources
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The zero-day vulnerability CVE-2025-61882 was exploited in August 2025.
First reported: 06.10.2025 14:384 sources, 14 articlesShow sources
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The exploit for the zero-day vulnerability CVE-2025-61882 was leaked by a group called Scattered Lapsus$ Hunters.
First reported: 06.10.2025 14:384 sources, 14 articlesShow sources
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Oracle has shared indicators of compromise for the zero-day exploitation, including IP addresses and exploit files.
First reported: 06.10.2025 14:384 sources, 14 articlesShow sources
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The exploit archive contains Python scripts used to exploit a vulnerable Oracle E-Business Suite instance and open a reverse shell.
First reported: 06.10.2025 14:384 sources, 11 articlesShow sources
- ⚡ Weekly Recap: Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More — thehackernews.com — 06.10.2025 14:38
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
-
CrowdStrike attributes the exploitation of CVE-2025-61882 to the Cl0p ransomware gang with moderate confidence.
First reported: 07.10.2025 08:124 sources, 13 articlesShow sources
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The first known exploitation of CVE-2025-61882 occurred on August 9, 2025.
First reported: 07.10.2025 08:124 sources, 13 articlesShow sources
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The exploit involves an HTTP request to /OA_HTML/SyncServlet, resulting in an authentication bypass.
First reported: 07.10.2025 08:124 sources, 13 articlesShow sources
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The attacker targets Oracle's XML Publisher Template Manager by issuing GET and POST requests to /OA_HTML/RF.jsp and /OA_HTML/OA.jsp to upload and execute a malicious XSLT template.
First reported: 07.10.2025 08:124 sources, 13 articlesShow sources
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The malicious template, when previewed, executes commands that establish an outbound connection to attacker-controlled infrastructure over port 443.
First reported: 07.10.2025 08:124 sources, 13 articlesShow sources
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The connection is used to remotely load web shells to execute commands and establish persistence.
First reported: 07.10.2025 08:124 sources, 13 articlesShow sources
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The exploit chain demonstrates a high level of skill and effort, involving at least five distinct bugs.
First reported: 07.10.2025 08:124 sources, 13 articlesShow sources
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The attack uses Server-Side Request Forgery (SSRF) and Carriage Return/Line Feed (CRLF) Injection to smuggle requests to an internet-exposed Oracle EBS application.
First reported: 07.10.2025 08:124 sources, 14 articlesShow sources
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The attack takes advantage of the fact that the JSP file can load an untrusted stylesheet from a remote URL, achieving arbitrary code execution.
First reported: 07.10.2025 08:124 sources, 13 articlesShow sources
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
CVE-2025-61882 has been added to the Known Exploited Vulnerabilities (KEV) catalog by CISA.
First reported: 07.10.2025 08:124 sources, 13 articlesShow sources
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Cl0p has been exploiting multiple vulnerabilities in Oracle EBS since at least August 2025, stealing large amounts of data from several victims.
First reported: 07.10.2025 08:124 sources, 13 articlesShow sources
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Cl0p has been sending extortion emails to some of those victims since last Monday.
First reported: 07.10.2025 08:124 sources, 14 articlesShow sources
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
WatchTowr Labs warns of potential mass, indiscriminate exploitation from multiple groups within days.
First reported: 07.10.2025 08:124 sources, 14 articlesShow sources
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks — thehackernews.com — 07.10.2025 08:12
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The UK’s National Cyber Security Centre (NCSC) has advised Oracle EBS customers to patch the critical vulnerability CVE-2025-61882, which is being exploited by the Clop ransomware group.
First reported: 07.10.2025 12:454 sources, 12 articlesShow sources
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The NCSC has urged customers to apply an emergency security update from Oracle, published over the weekend, to address the zero-day vulnerability CVE-2025-61882.
First reported: 07.10.2025 12:454 sources, 12 articlesShow sources
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The vulnerability impacts Oracle EBS versions 12.2.3-12.2.14 and allows unauthenticated attackers to send specially crafted HTTP requests to the affected component, resulting in full system compromise.
First reported: 07.10.2025 12:454 sources, 12 articlesShow sources
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The NCSC has warned that the Scattered Lapsus$ Hunters group has leaked the exploit used by the Clop gang, increasing the risk of opportunistic attacks on Oracle customers.
First reported: 07.10.2025 12:454 sources, 13 articlesShow sources
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Rapid7 has advised customers of affected Oracle EBS instances to conduct threat hunting to detect any potential malicious activity, given that exploitation in-the-wild may have occurred since August 2025.
First reported: 07.10.2025 12:454 sources, 13 articlesShow sources
- NCSC: Patch Critical Oracle EBS Bug Now — www.infosecurity-magazine.com — 07.10.2025 12:45
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The Clop ransomware gang has been exploiting a critical Oracle E-Business Suite (EBS) zero-day bug in data theft attacks since at least early August.
First reported: 07.10.2025 20:274 sources, 11 articlesShow sources
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The vulnerability was discovered in the BI Publisher Integration component of Oracle EBS's Concurrent Processing component.
First reported: 07.10.2025 20:274 sources, 11 articlesShow sources
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The vulnerability allows unauthenticated attackers to gain remote code execution on unpatched systems in low-complexity attacks that don't require user interaction.
First reported: 07.10.2025 20:274 sources, 11 articlesShow sources
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The vulnerability chain can let threat actors gain remote code execution without requiring authentication using a single HTTP request.
First reported: 07.10.2025 20:274 sources, 11 articlesShow sources
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
CrowdStrike assesses with moderate confidence that GRACEFUL SPIDER is likely involved in this campaign but cannot rule out the possibility that multiple threat actors have exploited CVE-2025-61882.
First reported: 07.10.2025 20:274 sources, 11 articlesShow sources
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The first known exploitation of CVE-2025-61882 occurred on August 9, 2025.
First reported: 07.10.2025 20:274 sources, 11 articlesShow sources
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The October 3, 2025 proof-of-concept (POC) disclosure and the CVE-2025-61882 patch release will almost certainly encourage threat actors, particularly those familiar with Oracle EBS, to create weaponized POCs and attempt to leverage them against internet-exposed EBS applications.
First reported: 07.10.2025 20:274 sources, 11 articlesShow sources
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Clop has been emailing executives at multiple companies as part of an ongoing extortion campaign, requesting ransoms to prevent sensitive data allegedly stolen from their Oracle E-Business Suite systems from being leaked online.
First reported: 07.10.2025 20:274 sources, 11 articlesShow sources
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Oracle linked the extortion emails claimed by the Clop cybercrime gang to the CVE-2025-61882 Oracle EBS vulnerability.
First reported: 07.10.2025 20:274 sources, 11 articlesShow sources
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible.
First reported: 07.10.2025 20:274 sources, 11 articlesShow sources
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The Clop extortion group has a long history of abusing zero-day flaws in massive data theft campaigns, most recently extorting dozens of victims in January 2025 after stealing their files in attacks targeting a zero-day vulnerability in Cleo's secure file transfer software.
First reported: 07.10.2025 20:274 sources, 11 articlesShow sources
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Previously, Clop was linked to multiple other data theft campaigns targeting zero-days in Accellion FTA, GoAnywhere MFT, and MOVEit Transfer, with the latter impacting over 2,770 organizations.
First reported: 07.10.2025 20:274 sources, 11 articlesShow sources
- Clop exploited Oracle zero-day for data theft since early August — www.bleepingcomputer.com — 07.10.2025 20:27
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The Clop ransomware group began targeting Oracle EBS instances as early as August 9, 2025, and successfully exfiltrated a significant amount of data.
First reported: 10.10.2025 13:154 sources, 10 articlesShow sources
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The extortion campaign followed months of intrusion activity by the threat actor, with exploitation of the zero-day CVE-2025-61882 beginning before patches were available.
First reported: 10.10.2025 13:154 sources, 10 articlesShow sources
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The contact addresses listed in the extortion emails, [email protected] and [email protected], have been listed on the Clop data leak site since at least May 2025.
First reported: 10.10.2025 13:154 sources, 10 articlesShow sources
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The threat actor provided legitimate file listings from victim EBS environments to multiple organizations with data dating back to mid-August 2025.
First reported: 10.10.2025 13:154 sources, 10 articlesShow sources
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The majority of the alleged victims of the Oracle EBS campaign are associated with data theft extortion incidents stemming from the exploitation of managed file transfer (MFT) systems.
First reported: 10.10.2025 13:154 sources, 10 articlesShow sources
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The post-exploitation tooling used in the campaign shows logical similarities to malware used in another suspected Clop campaign, including the use of the in-memory Java-based loader GOLDVEIN.JAVA.
First reported: 10.10.2025 13:154 sources, 10 articlesShow sources
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The campaign followed months of intrusion activity targeting EBS customer environments, dating as far back as July 10, 2025.
First reported: 10.10.2025 13:154 sources, 10 articlesShow sources
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
After Oracle released a Critical Patch Update in July 2025, which addressed nine flaws affecting EBS, Mandiant observed more likely exploitation attempts.
First reported: 10.10.2025 13:154 sources, 10 articlesShow sources
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Threat actors began exploiting the zero-day CVE-2025-61882 against Oracle EBS customers as early as August 9, 2025, weeks before a patch was made available.
First reported: 10.10.2025 13:154 sources, 10 articlesShow sources
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
GTIG assessed that Oracle EBS servers updated through the patch are likely no longer vulnerable to known exploitation chains.
First reported: 10.10.2025 13:154 sources, 10 articlesShow sources
- Google: Clop Accessed “Significant Amount” of Data in Oracle EBS Exploit — www.infosecurity-magazine.com — 10.10.2025 13:15
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Harvard University is investigating a data breach linked to the Clop ransomware gang's exploitation of a zero-day vulnerability in Oracle's E-Business Suite.
First reported: 13.10.2025 14:143 sources, 9 articlesShow sources
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Clop listed Harvard on its data leak site, claiming the breach was due to a zero-day vulnerability in Oracle's E-Business Suite.
First reported: 13.10.2025 14:143 sources, 9 articlesShow sources
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Harvard applied a patch from Oracle to remediate the vulnerability and is monitoring for further signs of compromise.
First reported: 13.10.2025 14:143 sources, 9 articlesShow sources
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The Clop extortion gang has a history of exploiting zero-day vulnerabilities in various platforms, including Accellion FTA, SolarWinds Serv-U FTP, GoAnywhere MFT, and MOVEit Transfer.
First reported: 13.10.2025 14:143 sources, 9 articlesShow sources
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Harvard is the first known organization linked to the Oracle E-Business Suite zero-day attacks, but more are expected to be identified.
First reported: 13.10.2025 14:143 sources, 9 articlesShow sources
- Harvard investigating breach linked to Oracle zero-day exploit — www.bleepingcomputer.com — 13.10.2025 14:14
- ⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More — thehackernews.com — 13.10.2025 16:18
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Harvard University is the first confirmed victim of the recent cybercrime campaign targeting customers of Oracle’s E-Business Suite (EBS) solution.
First reported: 14.10.2025 15:472 sources, 7 articlesShow sources
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The hackers have made available over 1.3 TB of archive files that allegedly contain Harvard data.
First reported: 14.10.2025 15:472 sources, 7 articlesShow sources
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The organization believes the incident impacts a limited number of parties associated with a small administrative unit.
First reported: 14.10.2025 15:472 sources, 7 articlesShow sources
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The vulnerability exploited by the hackers has been patched and there is no evidence of other systems being compromised.
First reported: 14.10.2025 15:472 sources, 7 articlesShow sources
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Google’s Threat Intelligence Group (GTIG) and Mandiant believe dozens of organizations have been targeted.
First reported: 14.10.2025 15:472 sources, 7 articlesShow sources
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The cybercriminals behind the Oracle EBS campaign sent out extortion emails to executives at the targeted organizations on behalf of the Cl0p ransomware group.
First reported: 14.10.2025 15:472 sources, 7 articlesShow sources
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The attacks targeting Oracle EBS customers appear to have involved the exploitation of known and zero-day vulnerabilities, as well as the deployment of sophisticated malware.
First reported: 14.10.2025 15:472 sources, 7 articlesShow sources
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
CrowdStrike reported that exploitation of the software flaws appears to have started on August 9, but Google has seen some indication that the attacks may have begun as early as July 10.
First reported: 14.10.2025 15:472 sources, 7 articlesShow sources
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The cybercriminals behind the Oracle EBS campaign sent out extortion emails to executives at the targeted organizations on behalf of the Cl0p ransomware group, likely due to the reputation it has built after conducting similar campaigns in the past.
First reported: 14.10.2025 15:472 sources, 7 articlesShow sources
- Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack — www.securityweek.com — 14.10.2025 15:47
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Envoy Air, a regional airline carrier owned by American Airlines, confirms that data was compromised from its Oracle E-Business Suite application after the Clop extortion gang listed American Airlines on its data leak site.
First reported: 17.10.2025 22:111 source, 6 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Envoy Air is a subsidiary of American Airlines and operates regional flights under the American Eagle brand.
First reported: 17.10.2025 22:111 source, 5 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
-
The Clop ransomware gang is leaking what they claim to be the data stolen from Envoy on its data leak site, stating, "The company doesn't care about its customers, it ignored their security!!!"
First reported: 17.10.2025 22:111 source, 5 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
-
The Clop extortion group began emailing extortion demands to companies in September, claiming to have stolen data from Oracle E-Business Suite systems.
First reported: 17.10.2025 22:111 source, 5 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
-
CrowdStrike and Mandiant revealed that Clop exploited the flaws in early August to breach systems and deploy malware.
First reported: 17.10.2025 22:111 source, 5 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
-
Google's John Hultquist believes that dozens of organizations were affected by the Clop data theft attacks.
First reported: 17.10.2025 22:111 source, 5 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
-
The Clop gang is also extorting Harvard University as part of this same data theft campaign, with the university confirming that the incident impacts a "limited number of parties associated with a small administrative unit."
First reported: 17.10.2025 22:111 source, 5 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
-
Oracle silently patched another E-Business Suite zero-day tracked CVE-2025-61884 without disclosing that it was actively exploited in July 2025.
First reported: 17.10.2025 22:111 source, 6 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
This zero-day is linked to an exploit leaked by the Shiny Lapsus$ Hunters extortion group on Telegram.
First reported: 17.10.2025 22:111 source, 6 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The Clop ransomware operation, also tracked as TA505, Cl0p, and FIN11, launched in 2019 when it began breaching corporate networks to deploy a variant of the CryptoMix ransomware and steal data.
First reported: 17.10.2025 22:112 sources, 7 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Since 2020, the extortion gang shifted from primarily ransomware to exploiting zero-day vulnerabilities in secure file transfer or data storage platforms to steal data.
First reported: 17.10.2025 22:112 sources, 7 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
In 2020, Clop exploited a zero-day in the Accellion FTA platform, affecting nearly 100 organizations.
First reported: 17.10.2025 22:112 sources, 7 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
In 2021, Clop exploited a zero-day in SolarWinds Serv-U FTP software.
First reported: 17.10.2025 22:112 sources, 7 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
In 2023, Clop exploited a zero-day in the GoAnywhere MFT platform, breaching over 100 companies.
First reported: 17.10.2025 22:112 sources, 7 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
In 2023, Clop exploited a zero-day in MOVEit Transfer, breaching over 2,773 organizations worldwide.
First reported: 17.10.2025 22:112 sources, 7 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
In 2024, Clop exploited two Cleo file transfer zero-days (CVE-2024-50623 and CVE-2024-55956) to steal data and extort companies.
First reported: 17.10.2025 22:112 sources, 7 articlesShow sources
- American Airlines subsidiary Envoy confirms Oracle data theft attack — www.bleepingcomputer.com — 17.10.2025 22:11
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
GlobalLogic, a digital engineering services provider, is notifying over 10,000 current and former employees that their data was stolen in an Oracle E-Business Suite (EBS) data breach.
First reported: 11.11.2025 17:242 sources, 6 articlesShow sources
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The attackers exploited an Oracle EBS zero-day vulnerability (CVE-2025-61882) to steal personal information belonging to 10,471 employees.
First reported: 11.11.2025 17:243 sources, 7 articlesShow sources
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
GlobalLogic's investigation identified access and exfiltration on October 9, 2025, with the earliest date of threat actor activity as July 10, 2025, and the most recent activity occurring on August 20, 2025.
First reported: 11.11.2025 17:243 sources, 7 articlesShow sources
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The stolen data includes names, addresses, phone numbers, emergency contact details, email addresses, dates of birth, nationalities, countries of birth, passport information, national identifiers or tax identifiers (e.g., Social Security Numbers), salary information, and bank account details.
First reported: 11.11.2025 17:243 sources, 7 articlesShow sources
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Clop has yet to add GlobalLogic to its leak site, suggesting the company is still negotiating with the threat group or has already paid a ransom.
First reported: 11.11.2025 17:243 sources, 7 articlesShow sources
- GlobalLogic warns 10,000 employees of data theft after Oracle breach — www.bleepingcomputer.com — 11.11.2025 17:24
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
GlobalLogic notified 10,471 individuals about the data breach targeting its Oracle E-Business Suite (EBS) platform.
First reported: 12.11.2025 17:303 sources, 6 articlesShow sources
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The breach was confirmed to have occurred on October 9, 2025, with data exfiltration taking place on that date.
First reported: 12.11.2025 17:303 sources, 6 articlesShow sources
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The compromised data includes names, addresses, phone numbers, emergency contact details, email addresses, dates of birth, nationalities, countries of birth, passport information, national identifiers or tax identifiers (e.g., Social Security Numbers), salary information, and bank account details.
First reported: 12.11.2025 17:303 sources, 6 articlesShow sources
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
GlobalLogic patched the zero-day vulnerability but confirmed that data had already been exfiltrated.
First reported: 12.11.2025 17:303 sources, 6 articlesShow sources
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Google is aware of dozens of victims, with the final tally potentially exceeding 100 organizations.
First reported: 12.11.2025 17:303 sources, 6 articlesShow sources
- GlobalLogic Becomes Latest Cl0p Victim After Oracle EBS Attack — www.infosecurity-magazine.com — 12.11.2025 17:30
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The Washington Post is notifying nearly 10,000 employees and contractors that some of their personal and financial data has been exposed in the Oracle data theft attack.
First reported: 13.11.2025 18:002 sources, 5 articlesShow sources
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The Washington Post is one of the largest daily newspapers in the U.S. with approximately 2.5 million digital subscribers.
First reported: 13.11.2025 18:001 source, 4 articlesShow sources
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Between July 10 and August 22, threat actors accessed parts of the Washington Post's network.
First reported: 13.11.2025 18:001 source, 4 articlesShow sources
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The hackers leveraged a then-zero-day vulnerability in Oracle E-Business Suite software that the Washington Post used internally, stole data, and then attempted to extort the firm in late September.
First reported: 13.11.2025 18:001 source, 4 articlesShow sources
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Oracle E-Business Suite is a widely used enterprise resource planning (ERP) platform with HR, finance, and supply chain functions that large organizations use internally.
First reported: 13.11.2025 18:001 source, 4 articlesShow sources
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
On September 29, 2025, the Post was contacted by a bad actor who claimed to have gained access to its Oracle E-Business Suite applications.
First reported: 13.11.2025 18:001 source, 4 articlesShow sources
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The Post's investigation into the incident concluded on October 27 and revealed that the following types of data belonging to 9,720 employees and contractors had been compromised: full names, bank account numbers and routing numbers, Social Security numbers (SSNs), and tax and ID numbers.
First reported: 13.11.2025 18:001 source, 4 articlesShow sources
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Impacted individuals received a 12-month free-of-charge identity protection service coverage through IDX and are recommended to consider placing a security freeze on their credit file and setting up fraud alerts on their report.
First reported: 13.11.2025 18:001 source, 4 articlesShow sources
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
In June, the Washington Post announced that the email accounts of several of its journalists had been compromised in a cyberattack conducted by foreign state actors.
First reported: 13.11.2025 18:001 source, 4 articlesShow sources
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
While the two incidents occurred shortly after one another, there is evidence of a connection between them.
First reported: 13.11.2025 18:001 source, 4 articlesShow sources
- Washington Post data breach impacts nearly 10K employees, contractors — www.bleepingcomputer.com — 13.11.2025 18:00
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Logitech International S.A. confirmed a data breach after a cyberattack by the Clop extortion gang, which exploited a third-party zero-day vulnerability in Oracle E-Business Suite.
First reported: 15.11.2025 00:182 sources, 4 articlesShow sources
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Logitech filed a Form 8-K with the U.S. Securities and Exchange Commission confirming the data breach.
First reported: 15.11.2025 00:182 sources, 4 articlesShow sources
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The breach likely includes limited information about employees, consumers, customers, and suppliers, but not sensitive data like national ID numbers or credit card information.
First reported: 15.11.2025 00:182 sources, 4 articlesShow sources
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Clop added Logitech to its data-leak extortion site, leaking almost 1.8 TB of data allegedly stolen from the company.
First reported: 15.11.2025 00:182 sources, 4 articlesShow sources
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Logitech confirmed that the breach occurred through a third-party zero-day vulnerability that was patched as soon as a fix was available.
First reported: 15.11.2025 00:182 sources, 4 articlesShow sources
- Logitech confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 15.11.2025 00:18
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Cox Enterprises detected a data breach in late September 2025, which occurred between August 9-14, 2025, due to a zero-day vulnerability in Oracle E-Business Suite.
First reported: 22.11.2025 17:162 sources, 3 articlesShow sources
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Cox Enterprises is a major American conglomerate with 55,000 employees and an annual revenue of $23 billion, involved in media, telecommunications, and automotive services.
First reported: 22.11.2025 17:162 sources, 3 articlesShow sources
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The Cl0p ransomware gang has taken credit for exploiting CVE-2025-61882 as a zero-day vulnerability in Oracle E-Business Suite.
First reported: 22.11.2025 17:162 sources, 3 articlesShow sources
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Cl0p hackers are known for leveraging zero-days in popular software products, including Cleo file transfer in 2024, MOVEit Transfer and GoAnywhere MFT in 2023, SolarWinds Serv-U FTP in 2021, and Accellion FTA in 2020.
First reported: 22.11.2025 17:162 sources, 3 articlesShow sources
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The threat actor added Cox Enterprises to their data leak website on the dark web on October 27 and published the stolen information.
First reported: 22.11.2025 17:162 sources, 3 articlesShow sources
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Cl0p listed 29 new companies as their victims earlier today, including major organizations in the automotive, software, and technology sectors.
First reported: 22.11.2025 17:162 sources, 3 articlesShow sources
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Cox Enterprises is offering identity theft protection and credit monitoring services through IDX at no cost for 12 months to 9,479 impacted individuals.
First reported: 22.11.2025 17:162 sources, 3 articlesShow sources
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Cox Communications suffered a separate breach in June 2024, where attackers exploited an exposed backend API to reset millions of customer modems and steal their personal data.
First reported: 22.11.2025 17:162 sources, 3 articlesShow sources
- Cox Enterprises discloses Oracle E-Business Suite data breach — www.bleepingcomputer.com — 22.11.2025 17:16
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Canon has confirmed being targeted in the recent Oracle E-Business Suite (EBS) hacking campaign.
First reported: 25.11.2025 09:222 sources, 2 articlesShow sources
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The incident is limited to a subsidiary of Canon U.S.A., Inc., and only affected the web server.
First reported: 25.11.2025 09:222 sources, 2 articlesShow sources
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Canon has taken security measures and resumed service, but is continuing to investigate further to ensure that there is no other impact.
First reported: 25.11.2025 09:222 sources, 2 articlesShow sources
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
No Canon data has been leaked at the time of writing.
First reported: 25.11.2025 09:222 sources, 2 articlesShow sources
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Canon was previously targeted in a ransomware attack back in 2020, where hackers stole employee information from the firm’s systems.
First reported: 25.11.2025 09:222 sources, 2 articlesShow sources
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
More than 100 organizations have been named to date on the Cl0p ransomware website as alleged victims of the campaign.
First reported: 25.11.2025 09:222 sources, 2 articlesShow sources
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Nearly half of the named organizations are major companies in sectors such as IT and telecoms, heavy industry and manufacturing, healthcare and pharma, retail, automotive and transportation, media, and energy and utilities.
First reported: 25.11.2025 09:222 sources, 2 articlesShow sources
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The United Kingdom’s National Health Service (NHS) is conducting an investigation but has yet to confirm a data breach.
First reported: 25.11.2025 09:222 sources, 2 articlesShow sources
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The list of big companies that have yet to publicly confirm a data breach includes Michelin, Broadcom, and Bechtel.
First reported: 25.11.2025 09:222 sources, 2 articlesShow sources
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Cl0p has been the public-facing group to take credit for the Oracle campaign, but an unknown cluster of a threat actor tracked as FIN11 is believed to be behind the attacks.
First reported: 25.11.2025 09:222 sources, 2 articlesShow sources
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
FIN11 conducted similar campaigns targeting other widely used enterprise products in the past.
First reported: 25.11.2025 09:222 sources, 2 articlesShow sources
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Organizations are typically not listed on the Cl0p website without cause, but the actual scope of the breach may be exaggerated by the threat actors.
First reported: 25.11.2025 09:222 sources, 2 articlesShow sources
- Canon Says Subsidiary Impacted by Oracle EBS Hack — www.securityweek.com — 25.11.2025 09:22
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
Dartmouth College has disclosed a data breach after the Clop extortion gang leaked data allegedly stolen from the school's Oracle E-Business Suite servers on its dark web leak site.
First reported: 25.11.2025 13:121 source, 1 articleShow sources
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The private Ivy League research university, founded in 1769, has an endowment of $9 billion as of June 30, 2025, over 40 academic departments and programs, and more than 4,000 undergraduate students, with a 7:1 undergraduate-to-faculty ratio.
First reported: 25.11.2025 13:121 source, 1 articleShow sources
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
In a breach notification letter filed with the office of Maine's Attorney General, Dartmouth says the attackers exploited an Oracle E-Business Suite (EBS) zero-day vulnerability to steal personal information belonging to 1,494 individuals.
First reported: 25.11.2025 13:121 source, 1 articleShow sources
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The total number of people potentially impacted by this data breach is likely much larger, given that the school is headquartered in Hanover, New Hampshire, and it hasn't yet filed a breach notice with the state's Attorney General.
First reported: 25.11.2025 13:121 source, 1 articleShow sources
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
"Through the investigation, we determined that an unauthorized actor took certain files between August 9, 2025, and August 12, 2025. We reviewed the files and on October 30, 2025, identified one or more that contained your name and Social Security number," the college says in letters mailed to those affected by the data leak.
First reported: 25.11.2025 13:121 source, 1 articleShow sources
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
In a separate appendix filed with Maine's AG, Dartmouth added that the threat actors also stole documents containing the financial account information of impacted individuals.
First reported: 25.11.2025 13:121 source, 1 articleShow sources
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
A Dartmouth College spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today regarding the ransom demanded by the Clop gang and the total number of individuals impacted by the breach.
First reported: 25.11.2025 13:121 source, 1 articleShow sources
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The incident is part of a much larger extortion campaign in which the Clop ransomware gang has exploited a zero-day flaw (CVE-2025-61882) since early August 2025 to steal sensitive files from many victims' Oracle EBS platforms.
First reported: 25.11.2025 13:121 source, 1 articleShow sources
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
While Clop has yet to disclose the total number of impacted organizations, Google Threat Intelligence Group chief analyst John Hultquist has told BleepingComputer that dozens of organizations were likely breached.
First reported: 25.11.2025 13:121 source, 1 articleShow sources
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
-
The extortion group has also targeted Harvard University, The Washington Post, Logitech, GlobalLogic, and American Airlines subsidiary Envoy Air in this campaign, with their data also leaked online and now available for download via Torrent.
First reported: 25.11.2025 13:121 source, 1 articleShow sources
- Dartmouth College confirms data breach after Clop extortion attack — www.bleepingcomputer.com — 25.11.2025 13:12
Similar Happenings
Princeton University Database Compromised in Phishing Attack
On November 10, 2025, Princeton University suffered a data breach after a phishing attack targeted an employee. The breach exposed personal information of alumni, donors, faculty, and students, including names, email addresses, phone numbers, and home and business addresses. The compromised database did not contain financial information, credentials, or records protected by privacy regulations. The university has since blocked the attackers' access and advised affected individuals to be cautious of phishing attempts. On November 18, 2025, Harvard University experienced a similar data breach due to a voice phishing attack. The breach exposed personal information of students, alumni, donors, staff, and faculty members. The compromised systems did not contain Social Security numbers, passwords, payment card information, or financial information. Harvard is working with law enforcement and third-party cybersecurity experts to investigate the incident and has sent data breach notifications to affected individuals. The breach was discovered on November 18, 2025, and involved unauthorized access to systems used by Harvard's Alumni Affairs and Development department. Harvard University is also one of the many victims of the recent Oracle E-Business Suite hacking campaign.
Five Vulnerabilities Added to CISA's Known Exploited Vulnerabilities Catalog
Five new vulnerabilities have been added to the CISA Known Exploited Vulnerabilities (KEV) Catalog. These include a server-side request forgery (SSRF) flaw in Oracle E-Business Suite (EBS) and four other vulnerabilities affecting Microsoft Windows SMB Client, Kentico Xperience CMS, and Apple's JavaScriptCore. The SSRF vulnerability in Oracle EBS has been actively exploited in real-world attacks. The vulnerabilities affect widely used software and have varying CVSS scores, indicating different levels of severity. Federal Civilian Executive Branch (FCEB) agencies must remediate these vulnerabilities by November 10, 2025, to protect against active threats.
Capita fined £14m for 2023 data breach affecting 6.6 million people
Capita has been fined £14 million for security failings that led to a 2023 data breach impacting nearly 6.6 million people. The breach was caused by an employee downloading malware, which allowed the Black Basta ransomware group to gain access to the network. The ICO initially planned to fine Capita £45 million but reduced the penalty due to improvements made after the attack and cooperation with regulators. The ICO fined Capita plc £8 million and Capita Pension Solutions Limited £6 million. The breach compromised sensitive information, including pension and staff records, criminal records, financial data, and special category data. Over half of the 600 Capita Pension Solutions clients were affected, and 8,000 claimants brought a High Court case against Capita. The breach impacted 325 pension scheme providers in the UK. The ICO highlighted several security failures, including inadequate privilege management, delayed responses to security alerts, and insufficient penetration testing. The cyberattack occurred on March 22, 2023, and nearly one terabyte of data was exfiltrated between March 29 and 30, 2023.
Unauthenticated access vulnerability in Oracle E-Business Suite Configurator
A critical vulnerability in Oracle E-Business Suite (EBS) allows unauthenticated attackers to access sensitive data via HTTP. The flaw, CVE-2025-61884, affects versions 12.2.3 through 12.2.14 and has a CVSS score of 7.5. CISA has confirmed that the vulnerability is being exploited in attacks and has added it to its Known Exploited Vulnerabilities catalog. Oracle has issued an emergency security update and patch, but exploitation in the wild has been reported. The vulnerability is in the Runtime UI component and could lead to unauthorized access to critical data. Oracle has silently fixed the vulnerability after it was actively exploited and a proof-of-concept exploit was leaked by the ShinyHunters extortion group. This development follows recent disclosures of zero-day exploitation in EBS software, attributed to a group with ties to the Clop ransomware group. The Clop group has been involved in major data theft campaigns targeting zero-days in Accellion FTA, GoAnywhere MFT, Cleo, and MOVEit Transfer.
TwoNet hacktivists target critical infrastructure with realistic honeypot attack
The pro-Russian hacktivist group TwoNet, previously known for DDoS attacks, targeted a water treatment facility in September 2025. The facility was a realistic honeypot set up by Forescout researchers to observe adversaries’ movements. The attack demonstrated TwoNet’s ability to move from initial access to disruptive actions in approximately 26 hours. The group exploited default credentials, SQL vulnerabilities, and an XSS flaw to gain access and disrupt operations. They created a new user account, displayed a hacking message, and disabled real-time updates and alarms. The intrusion was detected and logged by Forescout researchers monitoring the honeypot. TwoNet publicly claimed responsibility for the attack on its Telegram channel. The attack originated from an IP address linked to a German hosting provider, and the attacker used the Firefox browser on the Linux operating system. The attacker conducted defacement, process disruption, manipulation, and evasion activities. TwoNet has expanded its activities to include targeting HMI and SCADA interfaces, publishing personal details of personnel, and offering cybercrime services. The group has also ceased operations as of September 30, 2025, according to a message in an affiliated group, CyberTroops.