logo

Securing data in the cloud: Lessons from the Oracle legacy breach

ID: 27dd98da-36a2-5650-8efb-0afe1147b80d

STIX ID: report--27dd98da-36a2-5650-8efb-0afe1147b80d

Feed Name: ThreatLocker Blog

Threat Score
75/100

Date Published: 2025-07-23

Date Updated: 2026-05-01

...
...

Allegations surfaced that in early 2025 a threat actor exploited an unpatched Oracle Cloud Classic server to install a web shell and malware, exfiltrating over 6 million records (SSO/LDAP credentials, JKS/JPS keys); CISA issued guidance on credential risks, researchers received data samples, and legal action followed, although Oracle's public disclosures and the dataset's significance remain contested.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.