甲骨文云服务遭供应链攻击泄露600万数据记录,影响大约14万租户 泄露内容主要是通过SSO和LDAP获取的用户数据,还包括了JKS文件、密码、密钥文件(推测应该是Oracle登陆系统的关键文件和数据)。根据时间线推测是利用了 CVE-2021-35587: Oracle Access Manager 中的漏洞。 https://www.cloudsek.com/blog/the-biggest-supply-chain-hack-of-2025-6m-records-for-sale-exfiltrated…
彭博社:甲骨文集团近期告知客户其系统被黑客入侵,客户账户的登录凭据被窃取,包括用户名、通行密钥和加密后的密码
https://www.msn.com/en-us/money/other/oracle-tells-clients-of-second-recent-hack-log-in-data-stolen/ar-AA1Cb2DG
MSN
Oracle Tells Clients of Second Recent Hack, Log-In Data StolenOracle Corp. has told customers that a hacker broke into a computer system and stole old client log-in credentials, according to two people familiar with the matter. It’s the second cybersecurity breach that the software company has acknowledged to clients…