https://www.reddit.com/r/sysadmin/comments/d1ttzp/oracle_is_...
I remember it as Sun. But looking it up, Sun acquired it from something called Innotek GmbH.
I don't get the impression that Oracle is putting a lot of serious engineering effort on the old Sun products, aside from maintenance. Anyone keeping the lights on is probably unlikely to get offended by the thing from 2 layers of acquisition being called "crap".
Virtualbox represents exactly as much threat to your business as an OpenIndiana or FreeBSD server. Are you sure that a sysadmin is not using (CDDL licensed) ZFS?
Watch your licenses. Oracle Java JRE/JDK switched to a proprietary commmercial license (it's time to switch to openjre/openjdk including on the desktop. You're either out of date on patches or running oracle non-cddl code (prepare to bend over)
openjdk jre link: https://adoptopenjdk.net/installation.html?variant=openjdk11...
Affero GPL/AGPL is commercially toxic as well. Java iTextPdf is probably the most common thing.
(It is not especially clear to me what exact mitigations TFA describes; it seems to be glossy ad copy rather than technical documentation.)
I'm not sure I'd want "!!!" log lines going to the primary business log when only the suspicion of an attack exists.