• ABOUT
  • CONTACT
  • BLOG
techpinions_logo_transparent techpinions__white_logo_transparent
  • STOCKS
  • IPOs
  • AI
  • Tech
  • Invest
  • Future
  • Lifestyle
  • Opinions
Reading: Oracle releases emergency patch for critical E-Business Suite vulnerability exploited by Clop ransomware
Share
TechpinionsTechpinions
Font ResizerAa
  • AI
  • Tech
  • Invest
  • Future
  • Lifestyle
  • Opinions
Search
  • AI
  • Tech
  • Invest
  • Future
  • Lifestyle
  • Opinions
Follow US
© Copyright 2025, Techpinions. All Rights Reserved.
Home » Blog » Oracle releases emergency patch for critical E-Business Suite vulnerability exploited by Clop ransomware
Tech

Oracle releases emergency patch for critical E-Business Suite vulnerability exploited by Clop ransomware

Editorial Team
Last updated: October 7, 2025 11:59 AM
Editorial Team
Published: October 7, 2025
Share
Emergency Patch
Image Credit: Techpinions

Oracle has released an emergency patch for a critical zero-day vulnerability (CVE-2025-61882) in its E-Business Suite (EBS) that was actively exploited by the Clop ransomware gang in recent data theft attacks.

Why it matters: The vulnerability, with a CVSS score of 9.8, allows unauthenticated remote code execution, posing significant security risks to organizations using affected EBS versions (12.2.3-12.2.14).

The details:

  • The flaw resides in the Oracle Concurrent Processing product, specifically the BI Publisher Integration component.
  • Oracle advises installing the October 2023 Critical Patch Update before applying the new security updates.
  • Indicators of compromise include IP addresses 200.107.207.26 and 185.181.60.11, a reverse shell command, and an exploit code archive.

The vulnerability was first publicized by a group called “Scattered Lapsus$ Hunters,” who leaked exploit code and Oracle source code on Telegram.

Clop’s extortion campaign:

  • Clop exploited the EBS vulnerability to steal large amounts of data from several victims in August 2025.
  • Multiple companies received extortion emails threatening to leak stolen data unless a ransom was paid.
  • The emails boasted of the breach and held victim data as hostage.

“Clop exploited multiple vulnerabilities in Oracle EBS which enabled them to steal large amounts of data from several victims,” said Charles Carmakal, CTO of Mandiant – Google Cloud.

What’s next: Organizations using affected EBS versions should swiftly apply the necessary patches to mitigate the risk of exploitation. The incident highlights the persistent threat posed by ransomware gangs and the critical need for robust cyber defenses.

Unrivaled women’s basketball league valued at $340 million with Serena Williams’ support
Apple Watch introduces new hypertension detection feature in watchOS 26
SpaceX launches 24 Starlink satellites from Vandenberg Space Force Base
Study reveals why some gamers prefer inverted controls and the cognitive science behind it
ANZ Bank shuts down popular Australian shopping app Cashrewards
Previous Article Biggest Mistake Sam Bankman-Fried reveals his biggest mistake during FTX collapse
Next Article Fading Shine Earth’s fading shine in the northern hemisphere could disrupt global climate balance, scientists warn

In the last week:

Which quantum computing startups are worth betting on right now
February 23, 2026
Why the smartest telecom brands are outsourcing their infrastructure
March 10, 2026
Why some executives still resist AI and how to change their minds
February 23, 2026
Why winning the AI talent war comes down to more than salary
February 23, 2026
Why autonomous retail is harder than anyone expected
February 23, 2026
techpinions_logo_transparent techpinions__white_logo_transparent

We help business owners and managers stay ahead of technology, and effectively use AI & automation to gain strategic advantages.

Topics

  • AI
  • Tech
  • Invest
  • Future
  • Lifestyle
  • Opinions
© Copyright 2025, Techpinions. All Rights Reserved.