Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Cybereason is investigating an ongoing extortion campaign orchestrated by the CL0P ransomware group targeting vulnerabilities in Oracle E-Business Suite (EBS). The campaign began in late July 2025, shortly after Oracle released security updates that included patches for nine vulnerabilities in EBS. CL0P exploited a specific vulnerability, CVE-2025-61882, which allowed remote code execution without authentication, enabling unauthorized access to on-premise, customer-managed EBS systems.
This article details a CL0P extortion campaign targeting Oracle E-Business Suite using CVE-2025-61882. Cybereason's forensic investigations show CL0P gained unauthorized access between July and September 2025, exfiltrating data.
Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually.   Contact us today for pricing or a demo!
This article from DFIR Report covers cybersecurity developments relevant to organizational defense. The content addresses threats, vulnerabilities, or security best practices that security teams should incorporate into their operations.
Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually. Contact us today for pricing or a demo!
Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually.   Contact us today for pricing or a demo!