logo

There are perhaps 10,000 reasons to doubt Oracle Cloud's security breach denial

ID: 1c7a1e28-04de-5fd9-b82c-02f8f32f57d3

STIX ID: report--1c7a1e28-04de-5fd9-b82c-02f8f32f57d3

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-03-25

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Researchers say a threat actor, "rose87168", claims to have exfiltrated ~6 million records from Oracle Cloud login infrastructure — including customer security keys, encrypted credentials, and LDAP/SSO entries — and provided a 10,000-line sample to analysts; multiple customers and security firms (Hudson Rock, CloudSEK) have validated portions of the sample while Oracle denies any breach. The report notes the alleged exploitation of CVE-2021-35587 in Oracle Access Manager, potential widespread impact across ~1,500 organizations, and recommends rotating credentials, enforcing MFA, and initiating incident response if affected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.