Everything You Need to Know About Oracle Cloud Security Incident by rose87168
ID: 42f27d2d-8b41-5b0a-8471-091e3f55ae22
STIX ID: report--42f27d2d-8b41-5b0a-8471-091e3f55ae22
Feed Name: SOCRadar Blog
Allegations surfaced that threat actor "rose87168" breached Oracle Cloud in mid-February 2025, exfiltrating roughly 6 million records (including key material and encrypted credentials) from login endpoints and offering samples for sale and extortion; investigators cite possible exploitation of CVE-2021-35587 or an undisclosed flaw, while Oracle initially denied a breach but later began notifying some customers, leaving the incident partially corroborated but with serious operational impact and ongoing investigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
