Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Cybersecurity firms brace for impact of potential Oracle Cloud breach

By CIO Dive by By CIO Dive
March 31, 2025
Home Enterprise IT
Share on FacebookShare on Twitter


This audio is auto-generated. Please let us know if you have feedback.

Information security firms are taking measures to protect customers and their own networks as they wait for official guidance following claims of a massive attack against Oracle Cloud. 

A threat actor last week claimed to have stolen 6 million data records, including user credentials, from Oracle Cloud, which could affect more than 140,000 customers. After initially releasing strong denials, Oracle has been silent this week, while security researchers have compiled evidence backing claims of an actual attack. 

Security providers are assessing any potential impacts across their networks and advising customers to take precautionary measures until they are provided formal guidance from Oracle or official government agencies.

Rapid7 researchers are aware of the reported breach and are making high-level assessments of the potential impact across its customer base, Brian Bartholomew, director of information security at Rapid7, said via email. 

Rapid7 said it maintains a very small footprint as a customer on Oracle Cloud, which is used exclusively for testing and research purposes. There is no production or customer data involved. 

“At this time, there is no evidence to suggest any impact to the Rapid7 test systems on OCI,” Bartholomew said. 

However, the firm is rotating credentials stored in its test and research accounts as a precautionary measure.

As previously reported, researchers at CloudSEK disclosed multiple pieces of evidence that supported the hacker’s claims. Researchers said the attacker exploited a critical vulnerability in Oracle Cloud’s login endpoint. The threat actor claimed to have exploited CVE-2021-35587, a critical vulnerability in Oracle Access Manager.

CloudSEK has also been examining a data sample provided by the threat actor to assess its authenticity. 

Palo Alto Networks declined to comment on cases involving other firms but confirmed it is closely monitoring the Oracle Cloud situation. 

“Given the potential impact and uncertainty of the situation, we suggest that organizations that feel they may have been impacted identify and rotate credentials for any Oracle Cloud accounts,” a Palo Alto Networks spokesperson said via email. 

Orca Security said it was initially skeptical of the reported breach and has not seen any confirmation that the hacker obtained user credentials. However, the firm did not consider Oracle’s initial denials to be fully transparent.

“We still believe that the risk outweighs our skepticism and that organizations should take immediate action to rotate credentials and otherwise protect their Oracle Cloud tenants as appropriate,” Neil Carpenter, field CTO at Orca Security, said via email.



Source link

By CIO Dive

By CIO Dive

Next Post
BlackRock CEO Larry Fink says protectionism ‘has returned with force’

BlackRock CEO Larry Fink says protectionism 'has returned with force'

Recommended.

Researchers Spot XZ Utils Backdoor in Dozens of Docker Hub Images, Fueling Supply Chain Risks

Researchers Spot XZ Utils Backdoor in Dozens of Docker Hub Images, Fueling Supply Chain Risks

August 12, 2025
Chinese Smishing Kit Powers Widespread Toll Fraud Campaign Targeting U.S. Users in 8 States

Chinese Smishing Kit Powers Widespread Toll Fraud Campaign Targeting U.S. Users in 8 States

April 18, 2025

Trending.

Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices

Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices

July 18, 2025
Stocks making the biggest moves premarket: Salesforce, American Eagle, Hewlett Packard Enterprise and more

Stocks making the biggest moves premarket: Salesforce, American Eagle, Hewlett Packard Enterprise and more

September 4, 2025
Wesco Declares Quarterly Dividend on Common Stock

Wesco Declares Quarterly Dividend on Common Stock

December 1, 2025
⚡ THN Weekly Recap: New Attacks, Old Tricks, Bigger Impact

⚡ THN Weekly Recap: New Attacks, Old Tricks, Bigger Impact

March 10, 2025
Bloody Wolf Targets Uzbekistan, Russia Using NetSupport RAT in Spear-Phishing Campaign

Bloody Wolf Targets Uzbekistan, Russia Using NetSupport RAT in Spear-Phishing Campaign

February 9, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio