Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Cybersecurity firms brace for impact of potential Oracle Cloud breach

By CIO Dive by By CIO Dive
March 31, 2025
Home Enterprise IT
Share on FacebookShare on Twitter


This audio is auto-generated. Please let us know if you have feedback.

Information security firms are taking measures to protect customers and their own networks as they wait for official guidance following claims of a massive attack against Oracle Cloud. 

A threat actor last week claimed to have stolen 6 million data records, including user credentials, from Oracle Cloud, which could affect more than 140,000 customers. After initially releasing strong denials, Oracle has been silent this week, while security researchers have compiled evidence backing claims of an actual attack. 

Security providers are assessing any potential impacts across their networks and advising customers to take precautionary measures until they are provided formal guidance from Oracle or official government agencies.

Rapid7 researchers are aware of the reported breach and are making high-level assessments of the potential impact across its customer base, Brian Bartholomew, director of information security at Rapid7, said via email. 

Rapid7 said it maintains a very small footprint as a customer on Oracle Cloud, which is used exclusively for testing and research purposes. There is no production or customer data involved. 

“At this time, there is no evidence to suggest any impact to the Rapid7 test systems on OCI,” Bartholomew said. 

However, the firm is rotating credentials stored in its test and research accounts as a precautionary measure.

As previously reported, researchers at CloudSEK disclosed multiple pieces of evidence that supported the hacker’s claims. Researchers said the attacker exploited a critical vulnerability in Oracle Cloud’s login endpoint. The threat actor claimed to have exploited CVE-2021-35587, a critical vulnerability in Oracle Access Manager.

CloudSEK has also been examining a data sample provided by the threat actor to assess its authenticity. 

Palo Alto Networks declined to comment on cases involving other firms but confirmed it is closely monitoring the Oracle Cloud situation. 

“Given the potential impact and uncertainty of the situation, we suggest that organizations that feel they may have been impacted identify and rotate credentials for any Oracle Cloud accounts,” a Palo Alto Networks spokesperson said via email. 

Orca Security said it was initially skeptical of the reported breach and has not seen any confirmation that the hacker obtained user credentials. However, the firm did not consider Oracle’s initial denials to be fully transparent.

“We still believe that the risk outweighs our skepticism and that organizations should take immediate action to rotate credentials and otherwise protect their Oracle Cloud tenants as appropriate,” Neil Carpenter, field CTO at Orca Security, said via email.



Source link

By CIO Dive

By CIO Dive

Next Post
BlackRock CEO Larry Fink says protectionism ‘has returned with force’

BlackRock CEO Larry Fink says protectionism 'has returned with force'

Recommended.

Salesforce Adds Data Resilience Capabilities After Own Co. Acquisition

Salesforce Adds Data Resilience Capabilities After Own Co. Acquisition

March 18, 2025
Key Trends Reshaping Manufacturing in 2025 Amid Supply Chain Volatility Revealed in New Report from Info-Tech Research Group

Key Trends Reshaping Manufacturing in 2025 Amid Supply Chain Volatility Revealed in New Report from Info-Tech Research Group

July 28, 2025

Trending.

Spirit of openness helps banks get serious about stopping scams | Computer Weekly

Spirit of openness helps banks get serious about stopping scams | Computer Weekly

April 10, 2025
Microsoft Q3 Earnings Preview: What To Watch On Azure, Copilot, OpenAI

Microsoft Q3 Earnings Preview: What To Watch On Azure, Copilot, OpenAI

April 29, 2026
Weibo Publishes 2025 Environmental, Social and Governance Report

Weibo Publishes 2025 Environmental, Social and Governance Report

April 28, 2026
It Takes 2 Minutes to Hack the EU’s New Age-Verification App

It Takes 2 Minutes to Hack the EU’s New Age-Verification App

April 18, 2026
Chunghwa Telecom 2025 Form 20-F filed with the U.S. SEC

Chunghwa Telecom 2025 Form 20-F filed with the U.S. SEC

April 15, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio