
Grab your beverage of choice , because there's a LOT to recap from the last 24 hours. Check it out here
https://opalsec.io/daily-news-update-friday-april-4-2025-australia-melbourne/
There's a lot to digest, so if you're running between meetings or scoffing down a quick lunch before the next - here's the TL;DR on the key points:
Urgent Ivanti Patch Alert: A critical RCE zero-day is being actively exploited by suspected China-nexus group UNC5221, who are deploying new malware (TRAILBLAZE, BRUSHFIRE).
Fast Flux is Back in the Spotlight: Five Eyes agencies dropped a joint advisory on the increased use of this evasion technique by sophisticated actors (ransomware gangs, state-sponsored groups). It makes tracking C2s & phishing sites a real headache by rapidly changing IPs/nameservers.
GitHub Supply Chain Attack Deep Dive: Remember that complex attack targeting Coinbase via GitHub Actions? Unit 42 traced its origin back to a single leaked SpotBugs Personal Access Token from late 2024! A huge reminder about token hygiene, the risks of mutable tags, and those cascading dependency threats. Rotate secrets if you use SpotBugs, Reviewdog, or tj-actions!
Oracle's Cloud Breach Saga Continues...: Oracle reportedly admitted a breach to customers, framing it as a "legacy" (pre-2017) environment issue, yet, the actor leaked data allegedly from late 2024/2025. The focus on "Oracle Cloud Classic" vs. OCI feels like damage control over transparency. As I put it in the blog, their handling doesn't exactly inspire confidence – trust is earned, folks.
Rethinking Disaster Recovery in the Ransomware Era: DR is way more than just backups now. With hybrid environments sprawling and ransomware the top threat, recovery is Incident Response (detect, isolate, wipe, reinstall, restore). Homogeneity might simplify recovery, but beware of single points of failure (hello, CrowdStrike outage!).
Mass Scanning Alert: Seeing increased probes against Juniper devices (looking for default 't128' creds - change 'em!) and Palo Alto GlobalProtect portals. Motives are unclear – could be recon, botnet building, or sniffing for vulnerabilities. Keep those edge devices patched and hardened!
New Malware 'Wrecksteel' Hits Ukraine: CERT-UA warns of a new espionage malware targeting state agencies and critical infrastructure via phishing. Deployed by UAC-0219, Wrecksteel exfiltrates documents and takes screenshots.
INC Ransomware Claims State Bar of Texas: The second-largest US bar association confirmed a data breach after INC ransomware listed them on their leak site.
Stay informed, stay vigilant, and let me know your thoughts in the comments! What's catching your eye this week?
Oracle Tells Clients of Second Recent Hack, Log-In Data Stolen - An anonymous reader shares a report: Oracle has told customers that a hacker broke... - https://developers.slashdot.org/story/25/04/03/198224/oracle-tells-clients-of-second-recent-hack-log-in-data-stolen?utm_source=rss1.0mainlinkanon&utm_medium=feed #oracle
Oracle privately confirms Cloud breach to customers https://www.bleepingcomputer.com/news/security/oracle-privately-confirms-cloud-breach-to-customers/
Oracle confirmed data breaches for Oracle Classic (cloud) and Oracle Health (formerly Cerner).
https://www.bleepingcomputer.com/news/security/oracle-privately-confirms-cloud-breach-to-customers/
- - -
Oracle ont confirmé des brèches de données pour Oracle Classic (infonuagique) et Oracle Health (anciennement Cerner).
// Article en anglais //
Oracle is in bed with the US regime and is bidding for TikTok, which means it's on the good side of DT. It seems to be under the impression it can get away with this deceitful behavior because it's the Wild West again - and it's not alone. Apple, Meta and other tech companies are hiding behind DT to try and escape the consequences of their wrongdoing.
The Register: Oracle faces Texas-sized lawsuit over alleged cloud snafu and radio silence https://www.theregister.com/2025/04/02/oracle_breach_class_action/ @theregister #Oracle #cybersecurity #Infosec #databreach
This is going to come back and bite Oracle in the behind.
"Wayback Machine archive has been scrubbed."
"rose87168 left a text file on the Oracle Access Manager frontend as proof they were there."
"Oracle appears to have had that URL removed from the Wayback Machine on request."
Oracle continues to deny breach, tries to hide evidence https://www.computing.co.uk/news/2025/security/oracle-continues-to-deny-breach-hides-evidence #Oracle #cybersecurity #Infosec #databreach
Oracle faces Texas-sized lawsuit over alleged cloud snafu and radio silence – Source: go.theregister.com https://ciso2ciso.com/oracle-faces-texas-sized-lawsuit-over-alleged-cloud-snafu-and-radio-silence-source-go-theregister-com/ #rssfeedpostgeneratorecho #TheRegisterSecurity #CyberSecurityNews #TheRegister #Oracle
Ready for a fresh day of Cyber horrors? Me neither!
Oh well, here you go: https://opalsec.ghost.io/daily-news-update-wednesday-april-2-2025-australia-melbourne/
Here's a few of the key items to be aware of:
Palo Alto GlobalProtect Scans: Observed a significant spike in scans targeting Palo Alto Network GlobalProtect login portals, possibly prior to new exploit releases. Time to audit those logs!
China as Top Cyber Threat: Gen. Paul Nakasone (former NSA/Cyber Command Head) highlights China's unprecedented cyber activities, including malicious code in critical infrastructure and rapid exploitation of vulnerabilities. It's time to rethink our defense strategies!
North Korean IT Worker Expansion: North Korean "IT warriors" are infiltrating European companies, using fake identities to secure remote work and fund their regime. Stay vigilant and double-check those remote hires!
Identity Flaws in Breaches: A new report indicates 60% of incidents involved an identity attack, with compromised valid accounts being a top initial access vector. Focus on robust MFA, least privilege, and AD security!
Read the full post for all the details and more actionable insights, and if you want all this straight to your inbox, you're in luck! https://opalsec.ghost.io/daily-news-update-wednesday-april-2-2025-australia-melbourne/#/portal/signup
Oracle Hit with Lawsuit Over Alleged Cloud Breach Affecting Millions https://hackread.com/oracle-lawsuit-over-cloud-breach-affecting-millions/ #Laws&Legalities #Cybersecurity #CyberAttack #OracleCloud #databreach #Security #lawsuit #Oracle
Oracle Hit with Lawsuit Over Alleged Cloud Breach Affecting Millions – Source:hackread.com https://ciso2ciso.com/oracle-hit-with-lawsuit-over-alleged-cloud-breach-affecting-millions-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #Laws&Legalities #cybersecurity #CyberAttack #OracleCloud #DataBreach #Hackread #security #lawsuit #Oracle
Data leak at Oracle: Up to 2000 German victims? What is known and what is not
Data from the "Oracle Classic" cloud is for sale on the darknet. Analysts agree: the data is genuine. But some pieces of the puzzle are still missing.
#Oracle under fire for its handling of separate security incidents
https://techcrunch.com/2025/03/31/oracle-under-fire-for-its-handling-of-separate-security-incidents/
NEW: #Oracle sued over massive cloud data breach. Hacker claims 6 million+ users' data stolen. Plaintiff alleges negligence and failure to notify victims.
Read: https://hackread.com/oracle-lawsuit-over-cloud-breach-affecting-millions/
Datenleck bei Oracle: Bis zu 2000 deutsche Opfer? Was bekannt ist und was nicht
Daten aus der "Oracle Classic"-Cloud stehen im Darknet zum Verkauf. Analysten sind sich einig: Die Daten sind echt. Einige Puzzlesteine fehlen aber noch.
Disappointing (if not surprising) behavior from #Oracle, who are apparently trying to downplay what sounds like a serious security incident: https://doublepulsar.com/oracle-attempt-to-hide-serious-cybersecurity-incident-from-customers-in-oracle-saas-service-9231c8daff4a
Oracle Cloud security SNAFU latest: IT giant accused of pedantry as evidence scrubbed – Source: go.theregister.com https://ciso2ciso.com/oracle-cloud-security-snafu-latest-it-giant-accused-of-pedantry-as-evidence-scrubbed-source-go-theregister-com/ #rssfeedpostgeneratorecho #TheRegisterSecurity #CyberSecurityNews #TheRegister #Oracle
#Oracle Cloud is hacked. Another reason why I do not use the #cloud :)
https://techcrunch.com/2025/03/31/oracle-under-fire-for-its-handling-of-separate-security-incidents/