{"id":8447,"date":"2025-11-14T10:03:41","date_gmt":"2025-11-14T10:03:41","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/14\/cl0p-ransomware-group-allegedly-claims-breach-of-entrust-in-oracle-0-day-ebs-hack\/"},"modified":"2025-11-14T10:03:41","modified_gmt":"2025-11-14T10:03:41","slug":"cl0p-ransomware-group-allegedly-claims-breach-of-entrust-in-oracle-0-day-ebs-hack","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/14\/cl0p-ransomware-group-allegedly-claims-breach-of-entrust-in-oracle-0-day-ebs-hack\/","title":{"rendered":"Cl0P Ransomware Group Allegedly Claims Breach of Entrust in Oracle 0-Day EBS Hack"},"content":{"rendered":"<p>    Cl0P Ransomware Group Allegedly Claims Breach of Entrust in Oracle 0-Day EBS Hack<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The notorious Cl0P ransomware group has claimed responsibility for breaching digital security firm Entrust, exploiting a critical zero-day vulnerability in Oracle E-Business Suite (EBS).<\/p>\n<p>The attack, tied to <a href=\"https:\/\/cybersecuritynews.com\/oracle-e-business-suite-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-61882<\/a>, marks another high-profile victim in Cl0P\u2019s relentless assault on organizations using Oracle\u2019s enterprise software.<\/p>\n<p>Cl0P, known for high-impact extortion schemes, announced the breach on their dark web leak site earlier this week. According to the post, attackers gained unauthorized access to Entrust\u2019s systems via an unpatched flaw that allows remote code execution (RCE) in Oracle EBS environments.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjmRclYOUiTZmZGTCvJmKlLYUjjLVPLkZROy92PF98sew8VIZp-BbZYNqU12rAxGogRaHJK8eOKqtBhXPD70_RFsZGg3pEQmMeB1ms0Yd5P7B6SNww5uqwNQ5BVjbaoQaUxjsPN6L1Q3op8Hn9YObS80fZU5ESXxg9PPYsaYrF9NpVQ4PD3j6yTQdq3-lrd\/w640-h412\/Clop%2520Breach.webp?ssl=1\" alt=\"Clop ransomware claim\"><figcaption class=\"wp-element-caption\">Clop ransomware claim<\/figcaption><\/figure>\n<\/div>\n<p>The vulnerability, rated CVSS 9.8 for its ease of exploitation without authentication, affects multiple versions of EBS, a widely used platform for financial and supply chain management. Oracle patched it in October 2025\u2019s Critical Patch Update, but delayed adoption has left many firms exposed.<\/p>\n<p>Entrust, a provider of identity and access management solutions, confirmed the incident in a brief statement, noting that no customer data appears compromised.<\/p>\n<p>\u201cWe are investigating the matter with urgency and have implemented enhanced security measures,\u201d the company said. However, cybersecurity experts warn that the breach could undermine trust in Entrust\u2019s services, given its role in securing digital certificates and authentication for global enterprises.<\/p>\n<p>This isn\u2019t Cl0P\u2019s first rodeo with <a href=\"https:\/\/cybersecuritynews.com\/cl0p-ransomware-oracle-e-business-suite-0-day\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-61882<\/a>. Since disclosing the zero-day in September 2025, the group has listed over a dozen victims, including manufacturing giants and financial institutions.<\/p>\n<p>Their tactic exfiltrating data before encryption has netted millions in ransoms while pressuring targets through public shaming. Analysts at Mandiant attribute the spree to Cl0P\u2019s shift toward \u201cbig game hunting,\u201d targeting <a href=\"https:\/\/cybersecuritynews.com\/defending-against-owasp-top-10-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerabilities<\/a> in legacy enterprise systems.<\/p>\n<p>The breach highlights persistent risks in supply chain security. Organizations relying on Oracle EBS should prioritize patching and conduct vulnerability scans immediately. As Cl0P\u2019s list grows, the incident underscores the need for proactive threat hunting in an era of sophisticated ransomware operations.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/entrust-oracle-0-day-ebs-hack\/\">Cl0P Ransomware Group Allegedly Claims Breach of Entrust in Oracle 0-Day EBS Hack<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/entrust-oracle-0-day-ebs-hack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cl0P Ransomware Group Allegedly Claims Breach of Entrust in Oracle 0-Day EBS Hack The notorious Cl0P ransomware group has claimed responsibility for breaching digital security firm Entrust, exploiting a critical zero-day vulnerability in Oracle E-Business Suite (EBS). The attack, tied to CVE-2025-61882, marks another high-profile victim in Cl0P\u2019s relentless assault on organizations using Oracle\u2019s enterprise [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-8447","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8447"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8447"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8447\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8447"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8447"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}