Securing data in the cloud: Lessons from the Oracle legacy breach
ID: 27dd98da-36a2-5650-8efb-0afe1147b80d
STIX ID: report--27dd98da-36a2-5650-8efb-0afe1147b80d
Feed Name: ThreatLocker Blog
Threat Score
Allegations surfaced that in early 2025 a threat actor exploited an unpatched Oracle Cloud Classic server to install a web shell and malware, exfiltrating over 6 million records (SSO/LDAP credentials, JKS/JPS keys); CISA issued guidance on credential risks, researchers received data samples, and legal action followed, although Oracle's public disclosures and the dataset's significance remain contested.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
