Thursday, April 17, 2025

Saudi defense minister meets Iran’s Khamenei

Saudi defense minister hands letter from king to Khamenei during Tehran  visit | The Times of Israel

“We believe that relations between the Islamic Republic of Iran and Saudi Arabia will be beneficial for both countries, and the two countries can complement each other,” Khamenei was quoted as saying by Iran’s official IRNA news agency.

Saudi defense minister meets Iran’s Khamenei, delivers letter from King Salman

The meeting marked the first time Khamenei has received a Saudi official since 2006, when then-Foreign Minister Prince Saud al-Faisal visited Tehran

Iran’s Supreme Leader Ali Khamenei meets Saudi Defense Minister Prince Khalid bin Salman in Tehran on April 17, 2025. (Via Reuters)

Iran’s Supreme Leader Ali Khamenei meets Saudi Defense Minister Prince Khalid bin Salman in Tehran on April 17, 2025. (Via Reuters)

Yaghoub Fazeli - Al Arabiya English
Published: Updated:

Saudi Arabia’s Defense Minister Prince Khalid bin Salman met with Iran’s Supreme Leader Ayatollah Ali Khamenei in Tehran on Thursday, delivering a letter from King Salman, according to Iranian state media.

During the meeting, Khamenei expressed support for closer ties between the two countries.

Kuwait Times | Saudi Defense Minister Prince Khalid bin Salman delivered a  letter from Saudi King Salman bin Abdulaziz to Iran's Supreme Leader  Ayatollah... | Instagram

“It is much better for brothers in the region to cooperate and help each other than to rely on others,” he added.

Iran’s President Masoud Pezeshkian meets with Saudi Arabia’s Defense Minister Prince Khalid bin Salman in Tehran on April 17, 2025. (Via AFP)
Iran’s President Masoud Pezeshkian meets with Saudi Arabia’s Defense Minister Prince Khalid bin Salman in Tehran on April 17, 2025. (Via AFP)

The meeting marked the first time Khamenei has received a Saudi official since 2006, when then-Foreign Minister Prince Saud al-Faisal visited Tehran.

During his trip, Prince Khalid also met with Iranian President Masoud Pezeshkian, Supreme National Security Council secretary Ali Akbar Ahmadian, and chief of staff of the armed forces Mohammad Bagheri.

“Iran and Saudi Arabia can resolve many of the region’s problems by relying on their joint capacities and without the need for foreign intervention,” Pezeshkian said during his meeting with the Saudi defense chief, according to IRNA.

Saudi defense minister meets with Iranian leadership during official visit|  Arab News

Top stories

CISA warns of increased breach risks following Oracle Cloud leak...+ More articles from Bleeping Computer

BleepingComputer ​​​​​has separately confirmed with multiple Oracle customers that leaked data samples (including associated LDAP display names, email addresses, given names, and other identifying information) received from the threat actor were valid.
  • In late March, cybersecurity firm CybelAngel also revealed that Oracle told customers that an attacker deployed a web shell and additional malware on some of its Gen 1 (also known as Oracle Cloud Classic) servers as early as January 2025.
  • Until the breach was detected in late February, the attacker allegedly stole data from the Oracle Identity Manager (IDM) database, which included hashed passwords, usernames, and user emails.

CISA warns of increased breach risks following Oracle Cloud leak

By Sergiu Gatlan
April 17, 2025
07:23 AM

Oracle

On Wednesday, CISA warned of heightened breach risks after the compromise of legacy Oracle Cloud servers earlier this year and highlighted the significant threat to enterprise networks.

 "the nature of the reported activity presents potential risk to organizations and individuals, particularly where credential material may be exposed, reused across separate, unaffiliated systems, or embedded (i.e., hardcoded into scripts, applications, infrastructure templates, or automation tools),"

CISA Warns of Credential Risks Tied to Oracle Cloud Breach

The U.S. cybersecurity agency also released guidance to mitigate the risks linked to the resulting credential leak, urging network defenders to reset affected users' passwords, replace hardcoded or embedded credentials with secure authentication methods, enforce phishing-resistant multi-factor authentication (MFA) wherever possible, and monitor authentication logs for suspicious activity.

This warning comes after Oracle confirmed in email notifications sent to customers that a threat actor leaked credentials stolen from what the company described as "two obsolete servers."

However, Oracle added that its Oracle Cloud servers were not compromised, and the incident didn't impact its cloud services or customer data.

Oracle email statement (BleepingComputer)
Oracle email statement (BleepingComputer)
  1. ​Oracle also privately acknowledged in calls with some of its clients that attackers stole old client credentials after breaching a "legacy environment" last used in 2017. 
  2. However, the hacker behind the breach posted newer records from 2025 on BreachForums and shared data with BleepingComputer from the end of 2024.

Last month, BleepingComputer first reported that Oracle also issued private customer notifications regarding another January breach at Oracle Health (a SaaS company previously known as Cerner) that impacted patient data at multiple U.S. healthcare organizations and hospitals.

Related Articles:

Oracle privately confirms Cloud breach to customers

CISA tags SonicWall VPN flaw as actively exploited in attacks

Oracle says "obsolete servers" hacked, denies cloud breach

Oracle customers confirm data stolen in alleged cloud breach is valid

Oracle denies breach after hacker claims theft of 6 million data records

=== 
  • Get this open-box Microsoft Surface SE laptop for just $189.99 in this deal

    If you're in the market for a simple, reliable laptop for schoolwork, browsing, or everyday tasks, this deal might be right up your alley. Right now, you can grab an open-box Microsoft Surface SE laptop for just $189.99—marked down from its original price of $378.99.

    • BleepingComputer Deals
    • April 17, 2025
    • 07:05 AM
    • Comment Count 0
  • New Windows Server emergency updates fix container launch issue

    Microsoft has released emergency Windows Server updates to address a known issue preventing Windows containers from launching.

  • CISA tags SonicWall VPN flaw as actively exploited in attacks

    On Wednesday, CISA warned federal agencies to secure their SonicWall Secure Mobile Access (SMA) 100 series appliances against attacks exploiting a high-severity remote code execution vulnerability.

  • Over 16,000 Fortinet devices compromised with symlink backdoor

    Over 16,000 internet-exposed Fortinet devices have been detected as compromised with a new symlink backdoor that allows read-only access to sensitive files on previously compromised devices.

  • Google blocked over 5 billion ads in 2024 amid rise in AI-powered scams

    Google blocked 5.1 billion ads and suspended more than 39.2 million advertiser accounts in 2024, according to its 2024 Ads Safety Report released this week.

  • Eliminate PDFs frustrations with this PDF software deal

    Rather than pay recurring fees for a PDF management suite, you could pay a one-time fee for UPDF and gain access to every tool you need to edit, convert, organize, and secure your PDFs. Grab lifetime access for only $47.97 (reg. $149) through April 27.

    • BleepingComputer Deals
    • April 16, 2025
    • 02:07 PM
    • Comment Count 0
  • Apple fixes two zero-days exploited in targeted iPhone attacks

    Apple released emergency security updates to patch two zero-day vulnerabilities that were used in an "extremely sophisticated attack" against specific targets' iPhones.

  • Google begins unifying search country domains to Google.com

    Google has announced that it's retiring separate country code top-level domain names like google.co.uk or google.com.br and redirecting users to Google.com.

  • Jira Down: Atlassian users experiencing degraded performance

    Atlassian users are experiencing degraded performance amid an 'active incident' affecting multiple Jira products since morning hours today. Jira, Jira Service Management, Jira Work Management and Jira Product Discovery are among the impacted products.

  • 41% of Attacks Bypass Defenses: Adversarial Exposure Validation Fixes That

    Your dashboards say you're secure—but 41% of threats still get through. Picus Security's Adversarial Exposure Validation uncovers what your stack is missing with continuous attack simulations and automated pentesting.

  • CISA extends funding to ensure 'no lapse in critical CVE services'

    CISA says the U.S. government has extended MITRE's funding to ensure no continuity issues with the critical Common Vulnerabilities and Exposures (CVE) program.

  • Microsoft warns of blue screen crashes caused by April updates

    Microsoft warned customers this week that their systems might crash with a blue screen error caused by a secure kernel fatal error after installing Windows updates released since March.

  • Cyber Security News

    Maybe Dollar Can Squeeze Shorts a Little: 3-Minute MLIV

     

    May be an image of 1 person and text that says 'Josh Rincone @joshrinconn JUST IN: The Value of U.S. Dollar has TANKED in 2025 Value of the U.S. dollar this year +2% -6 -8 -10 Jan. 2025 Feb. -8.2% I March Note: ICE U.S. Dollar Index York Times April Source: FactSet By The New'