{"id":1456,"date":"2025-07-15T15:26:31","date_gmt":"2025-07-15T09:56:31","guid":{"rendered":"https:\/\/nocturnalknight.co\/?p=1456"},"modified":"2025-07-15T15:26:31","modified_gmt":"2025-07-15T09:56:31","slug":"oracle-cloud-breach-is-a-transitive-trust-timebomb-heres-how-to-defuse-it","status":"publish","type":"post","link":"http:\/\/3.10.118.248\/?p=1456","title":{"rendered":"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\u2019s How to Defuse It"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em>&#8220;One mispatched server in the cloud can ignite a wildfire of trust collapse across 140,000 tenants.&#8221;<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. The Context: Why This Matters<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In March 2025, a breach at Oracle Cloud shook the enterprise SaaS world. A few hours after Rahul from CloudSEK first flagged signs of a possible compromise, I published an initial analysis titled <a href=\"http:\/\/3.10.118.248\/is-oracle-cloud-safe-data-breach-allegations-and-what-you-need-to-do-now\/\" target=\"_blank\" rel=\"noopener\" title=\"\"><em>Is Oracle Cloud Safe? Data Breach Allegations and What You Need to Do Now<\/em><\/a>. That piece was an urgent response to a fast-moving situation, but this article is the reflective follow-up. Here, I break down not just the facts of what happened, but the deeper problem it reveals: the fragility of transitive trust in modern cloud ecosystems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threat actor <strong>rose87168<\/strong> leaked nearly <strong>6 million records<\/strong> tied to Oracle\u2019s login infrastructure, affecting <strong>over 140,000 tenants<\/strong>. The source? A misconfigured legacy server still running an unpatched version of <strong>Oracle Access Manager (OAM)<\/strong> vulnerable to <strong>CVE\u20112021\u201135587<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Initially dismissed by Oracle as isolated and obsolete, the breach was later confirmed via datasets and a tampered page on the login domain itself, captured in archived snapshots. This breach was not just an Oracle problem. It was a <strong>supply chain problem<\/strong>. The moment authentication breaks upstream, every SaaS product, platform, and identity provider depending on it inherits the risk, <em>often unknowingly<\/em>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Welcome to the age of <strong>transitive trust<\/strong>. shook the enterprise SaaS world. Threat actor <strong>rose87168<\/strong> leaked nearly <strong>6 million records<\/strong> tied to Oracle\u2019s login infrastructure, affecting <strong>over 140,000 tenants<\/strong>. The source? A misconfigured legacy server still running an unpatched version of <strong>Oracle Access Manager (OAM)<\/strong> vulnerable to <strong>CVE\u20112021\u201135587<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Initially dismissed by Oracle as isolated and obsolete, the breach was later confirmed via datasets and a tampered page on the login domain itself, captured in archived snapshots. This breach was not just an Oracle problem. It was a <strong>supply chain problem<\/strong>. The moment authentication breaks upstream, every SaaS product, platform, and identity provider depending on it inherits the risk, <em>often unknowingly<\/em>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Welcome to the age of <strong>transitive trust<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Anatomy of the Attack<\/h3>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"http:\/\/3.10.118.248\/wp-content\/uploads\/2025\/07\/Oracle-Cloud-Anatomy-of-Attack-branded-Compressed-1024x683.png\" alt=\"\" class=\"wp-image-1457\" srcset=\"http:\/\/3.10.118.248\/wp-content\/uploads\/2025\/07\/Oracle-Cloud-Anatomy-of-Attack-branded-Compressed-1024x683.png 1024w, http:\/\/3.10.118.248\/wp-content\/uploads\/2025\/07\/Oracle-Cloud-Anatomy-of-Attack-branded-Compressed-300x200.png 300w, http:\/\/3.10.118.248\/wp-content\/uploads\/2025\/07\/Oracle-Cloud-Anatomy-of-Attack-branded-Compressed-768x512.png 768w, http:\/\/3.10.118.248\/wp-content\/uploads\/2025\/07\/Oracle-Cloud-Anatomy-of-Attack-branded-Compressed.png 1080w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">Attack Vector<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Exploited: <strong>CVE-2021-35587<\/strong>, a critical RCE in Oracle Access Manager.<\/li>\n\n\n\n<li>Payload: Malformed XML allowed <strong>unauthenticated remote code execution<\/strong>.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">Exploited Asset<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Legacy <strong>Oracle Cloud Gen1<\/strong> login endpoints still active (e.g., <code>login.us2.oraclecloud.com<\/code>).<\/li>\n\n\n\n<li>These endpoints were supposedly decommissioned but remained <strong>publicly accessible<\/strong>.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">Proof &amp; Exfiltration<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Uploaded artefact visible in Wayback Machine snapshots.<\/li>\n\n\n\n<li>Datasets included:\n<ul class=\"wp-block-list\">\n<li><strong>JKS files<\/strong>, <strong>encrypted SSO credentials<\/strong>, <strong>LDAP passwords<\/strong><\/li>\n\n\n\n<li><strong>Tenant metadata<\/strong>, <strong>PII<\/strong>, <strong>hashes<\/strong> of admin credentials<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Validated by researchers from CloudSEK, ZenoX, and GoSecure.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. How Was This Possible?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Infrastructure drift<\/strong>: Legacy systems like Gen1 login were never fully decommissioned.<\/li>\n\n\n\n<li><strong>Patch blindness<\/strong>: CVE\u20112021\u201135587 was disclosed in 2021 but remained exploitable.<\/li>\n\n\n\n<li><strong>Trust misplacement<\/strong>: Downstream services assumed the upstream IDP layer was hardened.<\/li>\n\n\n\n<li><strong>Lack of dependency mapping<\/strong>: Tenants had no visibility into Oracle\u2019s internal infra state.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>4. How This Could Have Been Prevented<\/strong><\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td colspan=\"2\"><strong>Oracle\u2019s Prevention Gaps<\/strong><\/td><\/tr><tr><td><strong>Vector<\/strong><\/td><td><strong>Preventive Control<\/strong><\/td><\/tr><tr><td>Legacy exposure<\/td><td>Enforce infra retirement workflows. Remove public DNS entries for deprecated endpoints.<\/td><\/tr><tr><td>Patch gaps<\/td><td>Automate CVE patch enforcement across cloud services with SLA tracking.<\/td><\/tr><tr><td>IDP isolation<\/td><td>Decouple prod identity from test\/staging legacy infra. Enforce strict perimeter controls.<\/td><\/tr><tr><td colspan=\"2\"><strong>What Clients Could Have Done<\/strong><\/td><\/tr><tr><td><strong>Risk Inherited<\/strong><\/td><td><strong>Mitigation Strategy<\/strong><\/td><\/tr><tr><td>Blind transitive trust<\/td><td>Maintain a real-time trust graph between IDPs, SaaS apps, and their dependencies.<\/td><\/tr><tr><td>Credential overreach<\/td><td>Use scoped tokens, auto-expire shared secrets, enforce rotation.<\/td><\/tr><tr><td>Detection lag<\/td><td>Monitor downstream for leaked credentials or unusual login flows tied to upstream IDPs.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">5. Your Response Plan for Upstream IDP Risk<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Domain<\/td><td>Best Practices<\/td><\/tr><tr><td>Identity &amp; Access<\/td><td>Enforce federated MFA, short-lived sessions, conditional access rules<\/td><\/tr><tr><td>Secrets Management<\/td><td>Store all secrets in a vault, rotate frequently, avoid static tokens<\/td><\/tr><tr><td>Vulnerability Hygiene<\/td><td>Integrate CVE scanners into CI\/CD pipelines and runtime checks<\/td><\/tr><tr><td>Visibility &amp; Auditing<\/td><td>Maintain structured logs of identity provider access and token usage<\/td><\/tr><tr><td>Trust Graph Mapping<\/td><td>Actively map third-party IDP integrations, revalidate quarterly<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">6. Tools That Help You Defuse Transitive Trust Risks<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Tool<\/td><td>Mitigates<\/td><td>Use Case<\/td><\/tr><tr><td>CloudSEK XVigil<\/td><td>Credential leaks<\/td><td>Monitor for exposure of tokens, admin hashes, or internal credentials in open channels<\/td><\/tr><tr><td>Cortex Xpanse \/ Censys<\/td><td>Legacy infra exposure<\/td><td>Surface forgotten login domains and misconfigured IDP endpoints<\/td><\/tr><tr><td>OPA \/ OSQuery \/ Falco<\/td><td>Policy enforcement<\/td><td>Detect violations of login logic, elevated access, or fallback misroutes<\/td><\/tr><tr><td>Orca \/ Wiz<\/td><td>Runtime posture<\/td><td>Spot residual access paths and configuration drifts post-incident<\/td><\/tr><tr><td>Sigstore \/ Cosign<\/td><td>Supply chain integrity<\/td><td>Protect CI\/CD artefacts but limited in identity-layer breach contexts<\/td><\/tr><tr><td>Vault (HashiCorp)<\/td><td>Secrets lifecycle<\/td><td>Automate token expiration, key rotation, and zero plaintext exposure<\/td><\/tr><tr><td><a target=\"_blank\" href=\"http:\/\/zerberus.ai\/\" rel=\"noreferrer noopener\">Zerberus.ai<\/a> Trace-AI<\/td><td>Transitive trust, IDP visibility<\/td><td>Discover hidden dependencies in SaaS trust chains and enforce control validation<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">7. Lessons Learned<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When I sat down to write this, these statements felt too obvious to be called lessons. Of course authentication is production infrastructure, any practitioner would agree. But then why do so few treat it that way? Why don\u2019t we build failovers for our SSO? Why is trust still assumed, rather than validated?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These aren&#8217;t revelations. They&#8217;re reminders; hard-earned ones.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Transitive trust is NOT NEUTRAL, it\u2019s a silent threat multiplier.<\/strong> It embeds risk invisibly into every integration.<\/li>\n\n\n\n<li><strong>Legacy infrastructure never retires itself.<\/strong> If it\u2019s still reachable, it\u2019s exploitable.<\/li>\n\n\n\n<li><strong>Authentication systems deserve production-level fault tolerance.<\/strong> Build them like you\u2019d build your API or Payment Gateway.<\/li>\n\n\n\n<li><strong>Trust is not a diagram to revisit once a year; it must be observable, enforced, and continuously verified.<\/strong><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">8. Making the Invisible Visible: Why We Built Zerberus<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Transitive trust is invisible until it fails. Most teams don&#8217;t realise how many of their security guarantees hinge on external identity providers, third-party SaaS integrations, and cloud-native IAM misconfigurations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At <strong><a href=\"http:\/\/zerberus.ai\" target=\"_blank\" rel=\"noopener\" title=\"\">Zerberus<\/a><\/strong>, we set out to answer a hard question: <em>What if you could see the trust relationships before they became a risk?<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>We map your <strong>entire trust graph<\/strong>, from identity providers and cloud resources to downstream tools and cross-SaaS entitlements.<\/li>\n\n\n\n<li>We continuously verify the health and configuration of your identity and access layers, including:\n<ul class=\"wp-block-list\">\n<li>MFA enforcement<\/li>\n\n\n\n<li>Secret expiration windows<\/li>\n\n\n\n<li>IDP endpoint exposure<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>We bridge compliance and security by treating <strong>auth controls and access posture as observable artefacts<\/strong>, not static assumptions.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Your biggest security risk may not be inside your codebase, but <strong>outside your control plane<\/strong>. Zerberus is your lens into that blind spot.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Further Reading &amp; References<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>NocturnalKnight \u2013 Is Oracle Cloud Safe? Data Breach Allegations and What You Need to Do Now: <a href=\"http:\/\/3.10.118.248\/is-oracle-cloud-safe-data-breach-allegations-and-what-you-need-to-do-now\" target=\"_blank\" rel=\"noopener\" title=\"\">http:\/\/3.10.118.248\/is-oracle-cloud-safe-data-breach-allegations-and-what-you-need-to-do-now<\/a><\/li>\n\n\n\n<li>CloudSEK Blog \u2013 Oracle Cloud Breach Analysis (2025): <a href=\"https:\/\/cloudsek.com\/blog\/the-biggest-supply-chain-hack-of-2025-6m-records-for-sale-exfiltrated-from-oracle-cloud-affecting-over-140k-tenants\" target=\"_blank\" rel=\"noopener\" title=\"\">https:\/\/cloudsek.com\/blog\/the-biggest-supply-chain-hack-of-2025-6m-records-for-sale-exfiltrated-from-oracle-cloud-affecting-over-140k-tenants<\/a><\/li>\n\n\n\n<li>ZenoX Security \u2013 Oracle Leak Sample Validation: <a href=\"https:\/\/zenox.ai\/en\/new-data-from-the-oracle-incident-analysis-and-validation-of-the-10k-line-sample-from-the-reported-leak\" target=\"_blank\" rel=\"noopener\" title=\"\">https:\/\/zenox.ai\/en\/new-data-from-the-oracle-incident-analysis-and-validation-of-the-10k-line-sample-from-the-reported-leak<\/a> <\/li>\n\n\n\n<li>GoSecure \u2013 Strategic IDP Exposure Risks: <a href=\"https:\/\/gosecure.ai\/blog\/2025\/03\/24\/oracle-cloud-breach-a-strategic-response-to-an-identity-layer-threat\" target=\"_blank\" rel=\"noopener\" title=\"\">https:\/\/gosecure.ai\/blog\/2025\/03\/24\/oracle-cloud-breach-a-strategic-response-to-an-identity-layer-threat<\/a><\/li>\n\n\n\n<li>Trustwave SpiderLabs \u2013 Threat Review: Oracle Access Exploits: <a href=\"https:\/\/www.trustwave.com\/en-us\/resources\/blogs\/spiderlabs-blog\/trustwave-spiderlabs-threat-review-alleged-oracle-compromise\" target=\"_blank\" rel=\"noopener\" title=\"\">https:\/\/www.trustwave.com\/en-us\/resources\/blogs\/spiderlabs-blog\/trustwave-spiderlabs-threat-review-alleged-oracle-compromise<\/a><\/li>\n\n\n\n<li>Dark Reading \u2013 Oracle Denial and Disclosure Timeline: <a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/oracle-breach-2-obsolete-servers\" target=\"_blank\" rel=\"noopener\" title=\"\">https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/oracle-breach-2-obsolete-servers<\/a><\/li>\n\n\n\n<li>Orca Security \u2013 CVE-2021-35587 and Cloud Drift: <a href=\"https:\/\/orca.security\/resources\/blog\/oracle-cloud-breach-exploiting-cve-2021-35587\" target=\"_blank\" rel=\"noopener\" title=\"\">https:\/\/orca.security\/resources\/blog\/oracle-cloud-breach-exploiting-cve-2021-35587<\/a><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Want to Know Who You\u2019re Really Trusting?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Start your <strong>free Zerberus trial<\/strong> and discover the trust graph behind your SaaS stack\u2014before someone else does.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Oracle Cloud breach didn\u2019t just expose 140,000 tenants, it revealed the silent danger of transitive trust across SaaS ecosystems. This post analyses the breach, outlines what could\u2019ve been done, and offers a practical response guide for engineering and security teams. Featuring tools, trust graphs, and lessons for the road ahead.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[40,41,163],"tags":[265,413,457,469,490,512],"class_list":["post-1456","post","type-post","status-publish","format-standard","hentry","category-cyber-resilience","category-cyber-security","category-supply-chain-vulnerabilities","tag-cve202135587","tag-oraclecloud","tag-saassecurity","tag-securitybreach","tag-sso","tag-transitivetrust"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"The Oracle Cloud breach didn\u2019t just expose 140,000 tenants, it revealed the silent danger of transitive trust across SaaS ecosystems. This post analyses the breach, outlines what could\u2019ve been done, and offers a practical response guide for engineering and security teams. Featuring tools, trust graphs, and lessons for the road ahead.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Ramkumar Sundarakalatharan\"\/>\n\t<link rel=\"canonical\" href=\"http:\/\/3.10.118.248\/?p=1456\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_GB\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Nocturnalknight&#039;s Lair - Observations of a Random Wanderer!\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\u2019s How to Defuse It - Nocturnalknight&#039;s Lair\" \/>\n\t\t<meta property=\"og:description\" content=\"The Oracle Cloud breach didn\u2019t just expose 140,000 tenants, it revealed the silent danger of transitive trust across SaaS ecosystems. This post analyses the breach, outlines what could\u2019ve been done, and offers a practical response guide for engineering and security teams. Featuring tools, trust graphs, and lessons for the road ahead.\" \/>\n\t\t<meta property=\"og:url\" content=\"http:\/\/3.10.118.248\/?p=1456\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-07-15T09:56:31+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-07-15T09:56:31+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@nocturnalknight\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\u2019s How to Defuse It - Nocturnalknight&#039;s Lair\" \/>\n\t\t<meta name=\"twitter:description\" content=\"The Oracle Cloud breach didn\u2019t just expose 140,000 tenants, it revealed the silent danger of transitive trust across SaaS ecosystems. This post analyses the breach, outlines what could\u2019ve been done, and offers a practical response guide for engineering and security teams. Featuring tools, trust graphs, and lessons for the road ahead.\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@nocturnalknight\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1456#blogposting\",\"name\":\"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\\u2019s How to Defuse It - Nocturnalknight's Lair\",\"headline\":\"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\\u2019s How to Defuse It\",\"author\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?author=2#author\"},\"publisher\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"http:\\\/\\\/3.10.118.248\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/Oracle-Cloud-Anatomy-of-Attack-branded-Compressed.png\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1456\\\/#articleImage\",\"width\":1080,\"height\":720},\"datePublished\":\"2025-07-15T15:26:31+01:00\",\"dateModified\":\"2025-07-15T15:26:31+01:00\",\"inLanguage\":\"en-GB\",\"mainEntityOfPage\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1456#webpage\"},\"isPartOf\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1456#webpage\"},\"articleSection\":\"Cyber Resilience, Cyber Security, Supply Chain Vulnerabilities, CVE202135587, OracleCloud, SaaSSecurity, SecurityBreach, sso, TransitiveTrust\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1456#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\\\/\\\/3.10.118.248\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?cat=34#listItem\",\"name\":\"Computing &amp; AI\"}},{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?cat=34#listItem\",\"position\":2,\"name\":\"Computing &amp; AI\",\"item\":\"http:\\\/\\\/3.10.118.248\\\/?cat=34\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?cat=41#listItem\",\"name\":\"Cyber Security\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?cat=41#listItem\",\"position\":3,\"name\":\"Cyber Security\",\"item\":\"http:\\\/\\\/3.10.118.248\\\/?cat=41\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1456#listItem\",\"name\":\"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\\u2019s How to Defuse It\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?cat=34#listItem\",\"name\":\"Computing &amp; AI\"}},{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1456#listItem\",\"position\":4,\"name\":\"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\\u2019s How to Defuse It\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?cat=41#listItem\",\"name\":\"Cyber Security\"}}]},{\"@type\":\"Organization\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/#organization\",\"name\":\"Nocturnalknight's Lair\",\"description\":\"Observations of a Random Wanderer!\",\"url\":\"http:\\\/\\\/3.10.118.248\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"http:\\\/\\\/3.10.118.248\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/cropped-Ram-Profile.avif\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1456\\\/#organizationLogo\"},\"image\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1456\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/nocturnalknight\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/nocturnalknight\\\/\"]},{\"@type\":\"Person\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?author=2#author\",\"url\":\"http:\\\/\\\/3.10.118.248\\\/?author=2\",\"name\":\"Ramkumar Sundarakalatharan\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1456#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/818bc4a4d5681de6957f83aca2601d598459bf37a0a8b17d5abb1a889e2b9298?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Ramkumar Sundarakalatharan\"}},{\"@type\":\"WebPage\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1456#webpage\",\"url\":\"http:\\\/\\\/3.10.118.248\\\/?p=1456\",\"name\":\"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\\u2019s How to Defuse It - Nocturnalknight's Lair\",\"description\":\"The Oracle Cloud breach didn\\u2019t just expose 140,000 tenants, it revealed the silent danger of transitive trust across SaaS ecosystems. This post analyses the breach, outlines what could\\u2019ve been done, and offers a practical response guide for engineering and security teams. Featuring tools, trust graphs, and lessons for the road ahead.\",\"inLanguage\":\"en-GB\",\"isPartOf\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/#website\"},\"breadcrumb\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?p=1456#breadcrumblist\"},\"author\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?author=2#author\"},\"creator\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/?author=2#author\"},\"datePublished\":\"2025-07-15T15:26:31+01:00\",\"dateModified\":\"2025-07-15T15:26:31+01:00\"},{\"@type\":\"WebSite\",\"@id\":\"http:\\\/\\\/3.10.118.248\\\/#website\",\"url\":\"http:\\\/\\\/3.10.118.248\\\/\",\"name\":\"Nocturnalknight's Lair\",\"description\":\"Observations of a Random Wanderer!\",\"inLanguage\":\"en-GB\",\"publisher\":{\"@id\":\"http:\\\/\\\/3.10.118.248\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\u2019s How to Defuse It - Nocturnalknight's Lair","description":"The Oracle Cloud breach didn\u2019t just expose 140,000 tenants, it revealed the silent danger of transitive trust across SaaS ecosystems. This post analyses the breach, outlines what could\u2019ve been done, and offers a practical response guide for engineering and security teams. Featuring tools, trust graphs, and lessons for the road ahead.","canonical_url":"http:\/\/3.10.118.248\/?p=1456","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"http:\/\/3.10.118.248\/?p=1456#blogposting","name":"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\u2019s How to Defuse It - Nocturnalknight's Lair","headline":"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\u2019s How to Defuse It","author":{"@id":"http:\/\/3.10.118.248\/?author=2#author"},"publisher":{"@id":"http:\/\/3.10.118.248\/#organization"},"image":{"@type":"ImageObject","url":"http:\/\/3.10.118.248\/wp-content\/uploads\/2025\/07\/Oracle-Cloud-Anatomy-of-Attack-branded-Compressed.png","@id":"http:\/\/3.10.118.248\/?p=1456\/#articleImage","width":1080,"height":720},"datePublished":"2025-07-15T15:26:31+01:00","dateModified":"2025-07-15T15:26:31+01:00","inLanguage":"en-GB","mainEntityOfPage":{"@id":"http:\/\/3.10.118.248\/?p=1456#webpage"},"isPartOf":{"@id":"http:\/\/3.10.118.248\/?p=1456#webpage"},"articleSection":"Cyber Resilience, Cyber Security, Supply Chain Vulnerabilities, CVE202135587, OracleCloud, SaaSSecurity, SecurityBreach, sso, TransitiveTrust"},{"@type":"BreadcrumbList","@id":"http:\/\/3.10.118.248\/?p=1456#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"http:\/\/3.10.118.248#listItem","position":1,"name":"Home","item":"http:\/\/3.10.118.248","nextItem":{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?cat=34#listItem","name":"Computing &amp; AI"}},{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?cat=34#listItem","position":2,"name":"Computing &amp; AI","item":"http:\/\/3.10.118.248\/?cat=34","nextItem":{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?cat=41#listItem","name":"Cyber Security"},"previousItem":{"@type":"ListItem","@id":"http:\/\/3.10.118.248#listItem","name":"Home"}},{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?cat=41#listItem","position":3,"name":"Cyber Security","item":"http:\/\/3.10.118.248\/?cat=41","nextItem":{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?p=1456#listItem","name":"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\u2019s How to Defuse It"},"previousItem":{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?cat=34#listItem","name":"Computing &amp; AI"}},{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?p=1456#listItem","position":4,"name":"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\u2019s How to Defuse It","previousItem":{"@type":"ListItem","@id":"http:\/\/3.10.118.248\/?cat=41#listItem","name":"Cyber Security"}}]},{"@type":"Organization","@id":"http:\/\/3.10.118.248\/#organization","name":"Nocturnalknight's Lair","description":"Observations of a Random Wanderer!","url":"http:\/\/3.10.118.248\/","logo":{"@type":"ImageObject","url":"http:\/\/3.10.118.248\/wp-content\/uploads\/2026\/08\/cropped-Ram-Profile.avif","@id":"http:\/\/3.10.118.248\/?p=1456\/#organizationLogo"},"image":{"@id":"http:\/\/3.10.118.248\/?p=1456\/#organizationLogo"},"sameAs":["https:\/\/x.com\/nocturnalknight","https:\/\/www.linkedin.com\/in\/nocturnalknight\/"]},{"@type":"Person","@id":"http:\/\/3.10.118.248\/?author=2#author","url":"http:\/\/3.10.118.248\/?author=2","name":"Ramkumar Sundarakalatharan","image":{"@type":"ImageObject","@id":"http:\/\/3.10.118.248\/?p=1456#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/818bc4a4d5681de6957f83aca2601d598459bf37a0a8b17d5abb1a889e2b9298?s=96&d=mm&r=g","width":96,"height":96,"caption":"Ramkumar Sundarakalatharan"}},{"@type":"WebPage","@id":"http:\/\/3.10.118.248\/?p=1456#webpage","url":"http:\/\/3.10.118.248\/?p=1456","name":"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\u2019s How to Defuse It - Nocturnalknight's Lair","description":"The Oracle Cloud breach didn\u2019t just expose 140,000 tenants, it revealed the silent danger of transitive trust across SaaS ecosystems. This post analyses the breach, outlines what could\u2019ve been done, and offers a practical response guide for engineering and security teams. Featuring tools, trust graphs, and lessons for the road ahead.","inLanguage":"en-GB","isPartOf":{"@id":"http:\/\/3.10.118.248\/#website"},"breadcrumb":{"@id":"http:\/\/3.10.118.248\/?p=1456#breadcrumblist"},"author":{"@id":"http:\/\/3.10.118.248\/?author=2#author"},"creator":{"@id":"http:\/\/3.10.118.248\/?author=2#author"},"datePublished":"2025-07-15T15:26:31+01:00","dateModified":"2025-07-15T15:26:31+01:00"},{"@type":"WebSite","@id":"http:\/\/3.10.118.248\/#website","url":"http:\/\/3.10.118.248\/","name":"Nocturnalknight's Lair","description":"Observations of a Random Wanderer!","inLanguage":"en-GB","publisher":{"@id":"http:\/\/3.10.118.248\/#organization"}}]},"og:locale":"en_GB","og:site_name":"Nocturnalknight's Lair - Observations of a Random Wanderer!","og:type":"article","og:title":"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\u2019s How to Defuse It - Nocturnalknight's Lair","og:description":"The Oracle Cloud breach didn\u2019t just expose 140,000 tenants, it revealed the silent danger of transitive trust across SaaS ecosystems. This post analyses the breach, outlines what could\u2019ve been done, and offers a practical response guide for engineering and security teams. Featuring tools, trust graphs, and lessons for the road ahead.","og:url":"http:\/\/3.10.118.248\/?p=1456","article:published_time":"2025-07-15T09:56:31+00:00","article:modified_time":"2025-07-15T09:56:31+00:00","twitter:card":"summary_large_image","twitter:site":"@nocturnalknight","twitter:title":"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\u2019s How to Defuse It - Nocturnalknight's Lair","twitter:description":"The Oracle Cloud breach didn\u2019t just expose 140,000 tenants, it revealed the silent danger of transitive trust across SaaS ecosystems. This post analyses the breach, outlines what could\u2019ve been done, and offers a practical response guide for engineering and security teams. Featuring tools, trust graphs, and lessons for the road ahead.","twitter:creator":"@nocturnalknight"},"aioseo_meta_data":{"post_id":"1456","title":null,"description":null,"keywords":null,"keyphrases":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":null,"twitter_description":null,"schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":null,"created":"2026-08-19 12:14:14","updated":"2026-08-19 12:14:14"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"http:\/\/3.10.118.248\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"http:\/\/3.10.118.248\/?cat=34\" title=\"Computing &amp; AI\">Computing &amp; AI<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"http:\/\/3.10.118.248\/?cat=41\" title=\"Cyber Security\">Cyber Security<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tOracle Cloud Breach Is a Transitive Trust Timebomb : Here\u2019s How to Defuse It\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"http:\/\/3.10.118.248"},{"label":"Computing &amp; AI","link":"http:\/\/3.10.118.248\/?cat=34"},{"label":"Cyber Security","link":"http:\/\/3.10.118.248\/?cat=41"},{"label":"Oracle Cloud Breach Is a Transitive Trust Timebomb : Here\u2019s How to Defuse It","link":"http:\/\/3.10.118.248\/?p=1456"}],"amp_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"http:\/\/3.10.118.248\/index.php?rest_route=\/wp\/v2\/posts\/1456","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/3.10.118.248\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/3.10.118.248\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/3.10.118.248\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/3.10.118.248\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1456"}],"version-history":[{"count":0,"href":"http:\/\/3.10.118.248\/index.php?rest_route=\/wp\/v2\/posts\/1456\/revisions"}],"wp:attachment":[{"href":"http:\/\/3.10.118.248\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1456"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/3.10.118.248\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1456"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/3.10.118.248\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1456"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}