The Cl0p ransomware group has claimed responsibility for breaching Broadcom 's internal systems through a critical zero-day vulnerability in Oracle E-Business Suite . The incident is part of a broader, ongoing exploitation campaign that began in late September 2025 and has already affected dozens of organizations worldwide.

Critical zero-day opens the door for Broadcom
The attack exploited the zero-day vulnerability CVE-2025-61882, which has a CVSS score of 9.8 , ranking it among the most severe threat categories. The security hole allowed attackers to execute arbitrary code without any authentication, providing immediate and unfettered access to sensitive business functions.
See also: Tsundere Botnet targets Windows users with gaming bait
According to initial estimates, Cl0p managed to gain access to ERP files , internal design documentation , and semiconductor -related material — data considered of strategic importance for a giant with a strong presence in telecommunications infrastructure , data centers, and artificial intelligence systems.
What the leak means for the technology supply chain
Broadcom is a critical link for global technology and telecommunications companies. The potential release of internal documents raises concerns about:
- Risk of sabotage in chip production and development.
- Bypassing technical specifications through falsified data in collaborative ecosystems.
- Leakage of know-how related to semiconductor design and networking products.
Cybersecurity analysts warn that such access could have long-term impacts, especially in areas such as cloud systems and AI accelerator solutions, where Broadcom plays a central role.
Cl0p's campaign started months ago
Researchers from Google Threat Intelligence Group and Mandiant detected signs of a breach as early as July 10, 2025, with a confirmed zero-day exploit starting on August 9 — weeks before Oracle released an official patch.
Cl0p took advantage of the Business Intelligence Publisher of Oracle E-Business Suite and its integration with the Concurrent Processing, gaining full control of the system.
See also: Sturnus banking trojan steals messages from Signal & WhatsApp

At the same time, the team combined the zero-day with older, already patched vulnerabilities, enhancing the duration and reach of the attack.
Coordinated email extortion campaign
Since mid-September, Cl0p has been launching a multi-layered extortion campaign, sending targeted emails to company executives. To increase the credibility of the messages, the attackers used compromised email accounts third-partypurchased from infostealer marketplaces, thereby bypassing anti-spam systems.
So far, it is estimated that at least 29 organizations, based on posts on the group's data breach website.
Oracle's response and guidance to organizations
Oracle released emergency security updates in October 2024, but many businesses running on older or outdated versions of E-Business Suite remain exposed.
See also: DoorDash: AI browsers pose a big threat to Amazon
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Experts recommend:
- Immediate application of all Oracle patches
- Enhanced monitoring for suspicious POST requests to the
/OA_HTML/SyncServlet— a high-confidence breach indicator. - Control for lateral movements within corporate networks.
- Review of access policies to ERP systems and cloud infrastructures.
The broader message: Zero-day attacks are becoming more targeted
The Broadcom case highlights a worrying trend: ransomware groups are no longer simple criminals demanding ransom. They follow operational penetration, build multi-month campaigns, and target critical technology infrastructure with global impact.
As tools like infostealer markets, lateral movement frameworks, and zero-day brokers become more prevalent, organizations are being challenged to strengthen their defenses — not just with software updates, but with a comprehensive security strategy that covers people, processes, and systems.
