HELLFIRE https://www.bleepingcomputer.com/news/security/oracle-denies-data-breach-after-hacker-claims-theft-of-6-million-data-records/ Oracle denies it was breached after a threat actor claimed to be selling 6 million data records allegedly stolen from the company’s Oracle Cloud federated SSO login servers. … Regards
mmmdonuts Oracle: There was no breach! Also Oracle: Starting this week customers must now use MFA to login to our sites.
HELLFIRE TheRegister take on things, and IMO alot more understandable in the nuts and bolts than the BleepingComputer version : https://www.theregister.com/2025/03/23/oracle_cloud_customers_keys_credentials/ – Oracle Cloud says it’s not true someone broke into its login servers and stole data … Meanwhile, as noted by the guys at Bleeping, the miscreant boasted of creating a text file on an Oracle Cloud login server, specifically login.us2.oraclecloud.com, captured here by the Internet Archive’s Wayback Machine in early March, as proof that systems were compromised. That file contains simply the email address of the person attempting to sell what’s said to be the stolen Oracle Cloud data. We’ve asked Oracle for further clarification or an explanation. It’s claimed that information was exfiltrated from the EM2 as well as US2 login server. Samples of allegedly stolen info were also shared by the would-be thief. Looking through the Wayback Machine, we can see that the US2 server was as recently as February 2025 running some form of Oracle Fusion Middleware 11G. Infosec outfit CloudSEK reckons that server may not have been patched to close CVE-2021-35587, a known critical vulnerability in Fusion Middleware’s Oracle Access Manager, specifically its OpenSSO Agent. Exploiting that bug – which can be done over HTTP with no authentication – would potentially give an intruder access to the very kind of information put up for sale this week. Public exploit code for the flaw exists. On Thursday, what was claimed to be six million records of Oracle Cloud customers’ Java KeyStore files, which contain security certificates and keys; encrypted Oracle Cloud SSO passwords; encrypted LDAP passwords; Enterprise Manager JPS keys; and other information stolen from the cloud provider went up for sale on BreachForums by a previously unknown netizen going by the name rose87168. The potentially affected customers is said to number in the thousands. … Regards
HELLFIRE https://www.theregister.com/2025/03/25/oracle_breach_update/ – There are perhaps 10,000 reasons to doubt Oracle Cloud’s security breach denial Oracle Cloud’s denial of a digital break-in is now in clear dispute. A infosec researcher working on validating claims that the cloud provider’s login servers were compromised earlier this year says some customers have confirmed data allegedly stolen and leaked from the database giant is genuine. Since Oracle rubbished reports of a security breach, rose87168, the individual who claimed responsibility for the alleged intrusion and theft of approximately six million records – customer security keys, encrypted credentials, LDAP entries, and other data – sent a 10,000-line sample of the collection to Alon Gal, co-founder and CTO at security shop Hudson Rock. Gal said he took the sample and reached out to multiple Hudson Rock customers who appeared to be affected. Three customers have since confirmed the data handed to Gal by rose87168 from Oracle Cloud’s internal systems is genuine, according to the CTO. … Infosec outfit CloudSEK speculated rose87168 appeared to have exploited CVE-2021-35587, a critical vulnerability in Oracle Access Manager that would have given the miscreant access to the kinds of credentials and other data said to have been siphoned. That would mean Oracle failed to patch a hole in its own software on its own infrastructure. … Regards