Dark mode: ON

Infosec Decoded Season 5 #24: Oracle Breach

With Doug Spindler and sambowne@infosec.exchange

Recorded Fri, Mar 28, 2025

Politics

Trump administration at ‘war’ with mRNA technology: scientists alarmed vaccine skeptics could kill research

Scientists are sounding the alarm over a recent move by the National Institutes of Health to collect information about funding for research into mRNA technology. "Colleagues have also been advised not to apply for mRNA vaccine grants. This is all through the grapevine. There has not been an official statement about it."

The foundations of America’s prosperity are being dismantled

Federal scientists warn that Americans could feel the effects of the new administration's devastating cuts for decades to come. Every major technological transformation in the US, from electric cars to Google to the iPhone, can trace its roots back to basic science research once funded by the federal government.

Even Elon Musk Is Trying to Correct Joe Rogan’s Anti-Vax Nonsense

Joe Rogan hosted Dr. Suzanne Humphries, a nephrologist who co-wrote the self-published 2013 book "Dissolving Illusions: Disease, Vaccines, and the Forgotten History," which falsely claims that vaccines do not account for the decline of infectious diseases including smallpox and polio.

Flight bookings between Canada and US down 70% amid Trump tariff war

Law firms are scared to speak out amid Trump’s attacks on their livelihood

After a series of White House executive orders threatening their business and hiring practices, several powerful Washington law firms face a defining choice: push back publicly in defense of their industry or quietly hope to avoid President Donald Trump’s wrath.

Infosec

OpenAI’s new AI image generator is potent and bound to provoke

4o IG represents a shift to "native multimodal image generation," where the large language model processes and outputs image data directly as tokens. Even if it's slow (for now), the ability to generate images using a purely autoregressive approach is arguably a major leap for OpenAI due to its flexibility. But it's also very compute-intensive, since the model generates the image token by token, building it sequentially. This contrasts with diffusion-based methods like DALL-E 3, which start with random noise and gradually refine an entire image over many iterative steps.

We asked 5 AI helpers to write tough emails. Claude was a clear winner.

A panel of communications experts helped us test how well artificial intelligence tools ChatGPT, Claude, Copilot, DeepSeek and Gemini write emails.

After 50 million miles, Waymos crash a lot less than human drivers

Using human crash data, Waymo estimated that human drivers on the same roads would get into 78 crashes serious enough to trigger an airbag. By comparison, Waymo’s driverless vehicles only got into 13 airbag crashes. That represents an 83 percent reduction in airbag crashes relative to typical human drivers.

Quantum computing milestone: 56-qubit computer provides truly random number generation

They have for the first time experimentally demonstrated certified randomness, a way of generating random numbers from a quantum computer and then using a classical supercomputer to prove they are truly random and freshly generated.

China built hundreds of AI data centers to catch the AI boom. Now many stand unused.

Renting out GPUs to companies that need them for training AI models—the main business model for the new wave of data centers—was once seen as a sure bet. But with the rise of DeepSeek and a sudden change in the economics around AI, the industry is faltering.

Reasoning models like DeepSeek’s R1 need data centers near major tech hubs to minimize transmission delays and ensure access to highly skilled operations and maintenance staff. Data centers built in central, western, and rural China—where electricity and land are cheaper--are losing their allure to AI companies.

I don’t need Windows anymore. One final tool broke my reliance on Microsoft

Photoshop was the last holdout--Photopea replaces it.

Jamf 100 Course

Complete the course and take the Jamf Pro Associate exam.

Gemini hackers can deliver more potent attacks with a helping hand from… Gemini

For the first time, computer-generated prompt injections against Gemini have much higher success rates than manually crafted ones. The new method abuses fine-tuning, a feature Gemini offers free of charge. After 60 hours of compute time, it finds nonsense characters to add to a prompt injection that make it far more effective.

Oracle customers confirm data stolen in alleged cloud breach is valid

Despite Oracle denying a breach of its Oracle Cloud federated SSO login servers and the theft of account data for 6 million people, BleepingComputer has confirmed with multiple companies that associated data samples shared by the threat actor are valid.

Massive Oracle Cloud Breach: 6M Records Exposed, 140k+ Tenants Risked

A sophisticated supply chain hack targeting Oracle Cloud has exfiltrated a staggering 6 million records. The attacker got in by exploiting a server last updated in 2014 running Oracle Access Manager, using a well-known vulnerability — CVE-2021-35587.

At least three SF shops received ‘returned’ packages filled with drugs

Small businesses in San Francisco are finding unexpected packages of amphetamines and other drugs — complete with fake invoices using their branding.