Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
Cookie Policy Privacy Policy {title}
Skip to content

CloudTech is part of the TechForge Publications series

  • View All
  • AI News
  • The Block
  • Developer
  • Edge Computing News
  • IoT News
  • Marketing Tech
  • TechHQ
  • Tech Wire Asia
  • Sustainability News
  • Telecoms
  • View All
  • AI News
  • The Block
  • Developer
  • Edge Computing News
  • IoT News
  • Marketing Tech
  • TechHQ
  • Tech Wire Asia
  • Sustainability News
  • Telecoms

TechForge

  • Search
  • News
  • Categories
    • Applications
      • Blockchain
      • Containers
      • Data Centres
      • Infrastructure as a Service
      • Platform as a Service
      • Software as a Service
      • Virtualisation
    • Companies
      • Alibaba Cloud
      • AWS
      • Google Cloud
      • Microsoft
    • Data & Analytics
    • Enterprise
      • Cloud Migration
      • Collaboration
      • Digital Transformation
      • Future Work
      • Hybrid Cloud
      • Private Cloud
      • Public Cloud
    • Industries
      • Banking & Finance
      • Healthcare
      • Public Sector
      • Retail & Consumer
      • Telecoms
    • Infrastructure
    • Interviews
    • IoT
    • Platforms
    • Privacy
    • Regulation & Government
    • Security
    • Sponsored Content
  • Events
  • Resources
    • All Resources
    • On-demand Webinars
    • Exclusive Videos
  • More
    • Advertise
    • Contact Us
    • About Us
  • Search
  • News
  • Categories
    • Applications
      • Blockchain
      • Containers
      • Data Centres
      • Infrastructure as a Service
      • Platform as a Service
      • Software as a Service
      • Virtualisation
    • Companies
      • Alibaba Cloud
      • AWS
      • Google Cloud
      • Microsoft
    • Data & Analytics
    • Enterprise
      • Cloud Migration
      • Collaboration
      • Digital Transformation
      • Future Work
      • Hybrid Cloud
      • Private Cloud
      • Public Cloud
    • Industries
      • Banking & Finance
      • Healthcare
      • Public Sector
      • Retail & Consumer
      • Telecoms
    • Infrastructure
    • Interviews
    • IoT
    • Platforms
    • Privacy
    • Regulation & Government
    • Security
    • Sponsored Content
  • Events
  • Resources
    • All Resources
    • On-demand Webinars
    • Exclusive Videos
  • More
    • Advertise
    • Contact Us
    • About Us
Subscribe
Subscribe
  • Search
  • News
  • Categories
    • Applications
      • Blockchain
      • Containers
      • Data Centres
      • Infrastructure as a Service
      • Platform as a Service
      • Software as a Service
      • Virtualisation
    • Companies
      • Alibaba Cloud
      • AWS
      • Google Cloud
      • Microsoft
    • Data & Analytics
    • Enterprise
      • Cloud Migration
      • Collaboration
      • Digital Transformation
      • Future Work
      • Hybrid Cloud
      • Private Cloud
      • Public Cloud
    • Industries
      • Banking & Finance
      • Healthcare
      • Public Sector
      • Retail & Consumer
      • Telecoms
    • Infrastructure
    • Interviews
    • IoT
    • Platforms
    • Privacy
    • Regulation & Government
    • Security
    • Sponsored Content
  • Events
  • Resources
    • All Resources
    • On-demand Webinars
    • Exclusive Videos
  • More
    • Advertise
    • Contact Us
    • About Us

Cloud Computing

CISA issues guidance amid unconfirmed Oracle Cloud breach

Muhammad Zulhusni

21st April 2025

CISA issues guidance amid unconfirmed Oracle Cloud breach

Share this story:

Tags:

cloud
cybersecurity
ORacle
Security

Categories::

Cloud Computing
Security

The US Cybersecurity and Infrastructure Security Agency (CISA) is urging organisations and individuals to take precautions amid concerns about a potential compromise involving a legacy Oracle cloud environment.

In an alert issued Wednesday, CISA acknowledged ongoing reports of suspicious activity targeting Oracle customers. While the full scope of the threat remains unclear, the agency flagged several risks, particularly around exposed or reused credentials.

CISA’s guidance highlights the danger of credential material—such as usernames, passwords, authentication tokens, and encryption keys—being embedded in scripts, automation tools, or infrastructure templates. If compromised, credentials can grant long-term access to attackers and are often difficult to detect.

The agency is advising organisations to take several steps:

  • Reset passwords for users who may have been affected, especially where credentials aren’t managed through centralised identity systems.
  • Review and update any scripts, code, or configuration files that may contain hardcoded credentials, replacing them with secure authentication methods.
  • Monitor authentication logs for any unusual activity, with extra attention on accounts with administrative or elevated privileges.
  • Enforce phishing-resistant multifactor authentication for both user and admin accounts wherever possible.

The advisory follows claims made in recent weeks about a large-scale breach involving up to six million records and as many as 140,000 Oracle tenants. Researchers at CloudSek pointed to a vulnerability in Oracle Cloud’s login system, while TrustWave SpiderLabs said its analysis of a dataset supports the breach claims.

Oracle has publicly denied any compromise of Oracle Cloud Infrastructure (OCI) and maintains customer data has not been affected. Despite the denials, the company hasn’t issued formal guidance or a public advisory to customers. Security professionals say Oracle has communicated with some customers privately but has stayed largely silent in the public domain.

An Oracle spokesperson stated, “There has been no breach of Oracle Cloud (OCI),” to Cybersecurity Dive earlier this month. It said the circulated credentials are unrelated to OCI.

Two lawsuits have already been filed—one against Oracle Health in Missouri, and the other against Oracle Corporation in Texas.

Industry groups are calling for more openness from Oracle. Errol Weiss, chief security officer at the Health-Information Sharing and Analysis Center, said Oracle had yet to respond to an invitation to engage with the group’s members. “We’re disappointed with the lack of transparency from Oracle,” he said.

Jonathan Braley, director of threat intelligence at IT-ISAC, said the CISA advisory offers some direction while stakeholders continue to wait for more detailed information. “The advisory is helpful in that we have a credible report we can share, though it appears CISA has taken a proactive stance of mitigating ”potential unauthorised access” as we all await details from Oracle,” he said.

For now, security experts continue to monitor the situation, repeating calls to Oracle to provide further clarity to its customers and the broader cybersecurity community.

(Photo by Unsplash)

See also: Oracle Cloud denies breach as hacker offers 6 million records for sale

Want to learn more about cybersecurity and the cloud from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London.

Explore other upcoming enterprise technology events and webinars powered by TechForge here.

About the Author

Muhammad Zulhusni

Journalist

As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

Related

Trade tensions prompt European firms to rethink cloud strategies

21st April 2025

$100M IFC investment in sub-Saharan Africa data centres

11th April 2025

Dr Mary Aiken, University of East London: The Intersection of technology and human behaviour in cybersecurity

11th April 2025

Google Cloud Next 25: AI, cloud, and WAN

10th April 2025

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Click here

Popular

Cloud Computing

Oracle Cloud denies breach as hacker offers 6 million records for sale

4303 view(s)

Applications

Netflix countersues Broadcom over VMware patents

3086 view(s)

Cloud Computing

5 of the best: cloud technology training platforms

3057 view(s)

Infrastructure

Microsoft’s palm-sized chip brings practical quantum computing within reach

2467 view(s)
See all

Latest

View All Latest

Interviews

11th April 2025

Dr Mary Aiken, University of East London: The Intersection of technology and human behaviour in cybersecurity

Google unveils Cloud WAN and Gemini Tools to simplify app development Google Cloud Next 2025

Applications

10th April 2025

Google Cloud Next 25: AI, cloud, and WAN

Deutsche Telekom extends Google Cloud partnership through 2030

Cloud Computing

10th April 2025

Deutsche Telekom extends Google Cloud partnership through 2030

Subscribe

All our premium content and latest tech news delivered straight to your inbox

Subscribe

Explore

  • About Us
  • Contact Us
  • Newsletter
  • Privacy Policy
  • Cookie Policy
  • About Us
  • Contact Us
  • Newsletter
  • Privacy Policy
  • Cookie Policy

Reach Our Audience

  • Advertise
  • Post a Press Release
  • Contact Us
  • Advertise
  • Post a Press Release
  • Contact Us

Categories

  • Applications
  • Companies
  • Data & Analytics
  • Enterprise
  • Industries
  • IoT
  • Infrastructure
  • Platforms
  • Sponsored Content
  • Applications
  • Companies
  • Data & Analytics
  • Enterprise
  • Industries
  • IoT
  • Infrastructure
  • Platforms
  • Sponsored Content

Other Publications

  • Explore All
  • AI News
  • Developer
  • IoT News
  • Edge Computing News
  • Marketing Tech
  • TechHQ
  • Tech Wire Asia
  • Telecoms
  • The Block
  • Sustainability News
  • Explore All
  • AI News
  • Developer
  • IoT News
  • Edge Computing News
  • Marketing Tech
  • TechHQ
  • Tech Wire Asia
  • Telecoms
  • The Block
  • Sustainability News

CloudTech News is part of TechForge 

Subscribe

All our premium content and latest tech news delivered straight to your inbox

Permissions(Required)
This field is for validation purposes and should be left unchanged.

Notifications