CISA has issued urgent guidance following reports of leaked credentials from legacy Oracle cloud servers. Here’s what happened, what’s at risk, and the steps organizations must take to secure their environments.
Cisa
- A critical Windows vulnerability (CVE-2025-24054) is under active exploitation, allowing attackers to leak NTLM hashes and compromise credentials via phishing and malicious .library-ms files. Immediate patching is strongly recommended.
- President Trump's revocation of SentinelOne executives' security clearances over the hiring of former CISA chief Chris Krebs has sent shockwaves through the cybersecurity industry, with major vendors remaining silent amid fears of political retaliation.