Oracle – Gaming Master https://gaming.vmondeika.com Get daily gaming updates with us Thu, 11 Jun 2026 21:26:58 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 ShinyHunters breached 100+ companies through an unpatched Oracle PeopleSoft zero-day https://gaming.vmondeika.com/shinyhunters-breached-100-companies-through-an-unpatched-oracle-peoplesoft-zero-day/ https://gaming.vmondeika.com/shinyhunters-breached-100-companies-through-an-unpatched-oracle-peoplesoft-zero-day/#respond Thu, 11 Jun 2026 21:26:58 +0000 https://gaming.vmondeika.com/shinyhunters-breached-100-companies-through-an-unpatched-oracle-peoplesoft-zero-day/ [ad_1]

TL;DR

ShinyHunters exploited an unpatched Oracle PeopleSoft zero-day (CVE-2026-35273, CVSS 9.8) to breach 100+ organisations. Two-thirds are universities. No patch yet.

Oracle warned customers on Thursday of a critical vulnerability in its PeopleSoft software that hackers have already exploited to breach more than 100 organisations. The flaw, CVE-2026-35273, carries a CVSS score of 9.8 and can be exploited over the internet without any authentication. Oracle has not released a patch.

The advisory came a day after the cybercrime group ShinyHunters claimed responsibility for the mass-hacking campaign. Google’s Mandiant confirmed that the bug Oracle disclosed is the same one ShinyHunters is exploiting. Mandiant said it notified more than 100 global organisations, most of them in the United States.

About two-thirds of the victims are universities and colleges. A ShinyHunters member told TechCrunch the group stole “hundreds of thousands of student records containing full name, home address, phone, email, date of birth, gender, ethnicity, enrollment status, GPA, major, and student ID.” The University of Nottingham was named among the breached institutions.

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!

While several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, resulting in stolen data being published on the ShinyHunters Data Leak Website,” Mandiant wrote. Oracle did not respond to TechCrunch’s request for comment.

PeopleSoft is used by large companies and universities to manage payroll, human resources, and student records. The vulnerability affects PeopleTools versions 8.61 and 8.62. ShinyHunters exploited a chain of old and zero-day vulnerabilities to target both cloud and on-premises instances, compromising approximately 300 servers across the 100+ organisations.

The attack follows a pattern. ShinyHunters has spent the past year targeting organisations that share the same vulnerable enterprise software. Previous campaigns hit companies using Salesforce, Gainsight, and education platform Instructure. The group identifies the flaw, finds every company running the software, steals data, and demands a ransom.

Instructure paid the hackers earlier this year after being breached twice. ShinyHunters also defaced the login pages of schools using Instructure’s Canvas portal. The PeopleSoft campaign is the largest yet, and it is ongoing. Oracle recommended mitigations but has not said when a patch will be available.

For any organisation running PeopleSoft, the immediate action is to apply Oracle’s mitigations and restrict internet-facing access to PeopleSoft servers. The broader lesson is one the enterprise software industry keeps relearning: when a critical zero-day hits software used by hundreds of large organisations, the attacker only needs to find it once. AI is making vulnerability discovery cheaper. The defenders patching those flaws are not getting faster. And groups like ShinyHunters are industrialising the exploitation of every window between disclosure and fix.

[ad_2]

Source link

]]>
https://gaming.vmondeika.com/shinyhunters-breached-100-companies-through-an-unpatched-oracle-peoplesoft-zero-day/feed/ 0
Oracle warns of security bug that hackers abused to breach 100+ companies https://gaming.vmondeika.com/oracle-warns-of-security-bug-that-hackers-abused-to-breach-100-companies/ https://gaming.vmondeika.com/oracle-warns-of-security-bug-that-hackers-abused-to-breach-100-companies/#respond Thu, 11 Jun 2026 21:20:33 +0000 https://gaming.vmondeika.com/oracle-warns-of-security-bug-that-hackers-abused-to-breach-100-companies/ [ad_1]

Oracle warned its corporate customers that there is a critical-rated vulnerability in its PeopleSoft software, which is used by large companies to manage payroll and human resources, a day after a cybercrime group took credit for abusing the flaw as part of a mass-hacking campaign.

The company published the security advisory on Thursday after the hacking group ShinyHunters claimed to have breached more than 100 organizations that use PeopleSoft servers.

Mandiant, the Google-owned security unit that investigates cyberattacks, warned in a blog post that the new Oracle flaw is the same bug that the ShinyHunters group is abusing in its hacking campaign targeting PeopleSoft customers. 

Oracle, which has not released a patch for the vulnerability at the time of writing, said in the advisory that the bug can be exploited over the internet without needing any authentication, such as a password. 

The tech giant recommended that customers who use PeopleSoft software apply its mitigations to prevent exploitation.

On Wednesday, a ShinyHunters member told TechCrunch that the gang compromised the companies by abusing an unpatched flaw in PeopleSoft servers. The bug is known as a zero-day because the company affected, in this case Oracle, had no time to fix it before it was discovered and exploited.

Mandiant confirmed that it has also notified more than “100 global organizations,” most of them in the United States, in an effort to restrict access to their potentially vulnerable systems. The cybersecurity group said that about two-thirds of these organizations are in higher education, which aligns with what ShinyHunters previously claimed.

“While several organizations successfully blocked the activity or remediated the vulnerabilities, others experienced compromise, resulting in stolen data being published on the ShinyHunters [Data Leak Website],” Mandiant wrote. 

Oracle did not respond to TechCrunch’s request for comment. 

Contact Us

Do you have more information about this hacking campaign? Or other data breaches? We’d love to hear from you. From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.

The ShinyHunters member told TechCrunch this week that some of the hacked organizations are universities and colleges.

The hacker shared a message they said was sent to one of the victim schools, in which the hackers claimed to have stolen “hundreds of thousands of student records containing full name, home address, phone, email, date of birth, gender, ethnicity, enrollment status, GPA, major, and student ID across all campuses,” among other data. 

PeopleSoft, and its customers, are the latest victims in a long series of hacking campaigns where the ShinyHunters gang targeted organizations that all share the same vulnerable software. 

In the last year, the group targeted several companies that use Salesforce and Gainsight, as well as software provided by education giant Instructure, and among others. 

Once the hackers identify vulnerable software and companies that use it, they try to steal corporate or customer data and then threaten to release it unless the victims pay a ransom. 

Earlier this year, education tech company Instructure said it paid the hackers after they breached the company’s systems twice. As part of the hacking campaign, ShinyHunters defaced the login pages of several schools that use Instructure’s popular school information portal Canvas.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

[ad_2]

Source link

]]>
https://gaming.vmondeika.com/oracle-warns-of-security-bug-that-hackers-abused-to-breach-100-companies/feed/ 0
ByteDance and Oracle are using Arm’s in-house AGI CPU, completing the hyperscaler-x86 exit https://gaming.vmondeika.com/bytedance-and-oracle-are-using-arms-in-house-agi-cpu-completing-the-hyperscaler-x86-exit/ https://gaming.vmondeika.com/bytedance-and-oracle-are-using-arms-in-house-agi-cpu-completing-the-hyperscaler-x86-exit/#respond Tue, 02 Jun 2026 09:39:40 +0000 https://gaming.vmondeika.com/bytedance-and-oracle-are-using-arms-in-house-agi-cpu-completing-the-hyperscaler-x86-exit/ [ad_1]

Arm CEO René Haas confirmed at Computex that ByteDance and Oracle have joined Meta as customers for Arm’s own data-centre CPU, validating the company’s shift from licensor to silicon vendor.

Arm chief executive René Haas confirmed at Computex on Monday that ByteDance and Oracle are among the customers using AGI, Arm’s first in-house data-centre CPU, joining Meta as the third and fourth named adopters of a chip that the Cambridge-based company is positioning as the structural alternative to Intel’s Xeon and AMD’s EPYC server lines.

The strategic shift the customer announcement validates is the harder of the two parts of the story. Arm spent the past three decades licensing CPU IP to chipmakers who then designed and sold their own silicon, AWS’s Graviton, Microsoft’s Cobalt, Google’s Axion, Nvidia’s Grace and now Vera.

AGI represents the company’s decision to design and sell finished silicon directly. The customers Arm is now announcing for that finished chip are not its existing licensees; they are the same hyperscaler and enterprise-cloud buyers its licensees would themselves have hoped to sell to.

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!

The Arm-AGI launch is therefore as much a vertical-integration play against its own customer base as it is a horizontal-integration play against Intel and AMD.

The customer roster tells the story. Meta was the first publicly named AGI customer, announced at the AGI launch event in San Francisco in March. ByteDance is the largest Chinese AI workload customer, which is significant given the company’s parallel custom-CPU programme on Arm and RISC-V tracks reported last week.

Oracle is the enterprise-cloud workhorse that pairs Arm-based servers with its database product line for customer deployments. The composition is meaningful: one US frontier-AI lab, one Chinese hyperscaler, one US enterprise-cloud provider. Arm has, on three named customers, demonstrated that AGI is being adopted across the three most strategically distinct categories of data-centre buyer.

The financial-projection backdrop matters. Haas said at the AGI launch that sales of the chip alone would bring in $15bn to Arm by 2031. The chip is co-designed with Meta and built on a chiplet design using TSMC’s 3nm N3P process, the same node Nvidia uses for Rubin.

The $15bn projection is, on the most aggressive read, a doubling of Arm’s current annual revenue base if achieved. The Monday customer announcement is the most concrete validation yet that the projection is supportable.

The structural read on the broader CPU market is the editorial point worth surfacing. Nvidia’s Vera CPU launched yesterday with OpenAI, Anthropic and SpaceX as named customers.

Snowflake’s $6bn AWS Graviton commitment last week added a major enterprise-data-platform customer to the Arm-server-side ledger. ByteDance is building its own custom Arm-and-RISC-V CPUs in parallel. Arm itself is now selling AGI to Meta, ByteDance and Oracle.

Every named major AI-data-centre customer on the public record is now committed to Arm-based silicon in at least one tier of their compute stack, either as a direct purchase, a hyperscaler-built custom design, or a co-developed product. The x86 incumbents have, on the available evidence, lost the hyperscaler-CPU war in the four weeks since Computex 2026 began.

The implication for Intel and AMD is severe. Both companies have historically derived the majority of their server-CPU revenue from hyperscaler purchases, and the hyperscaler portion of the data-centre CPU market is structurally the highest-margin tier. The current public commitments to Arm silicon, in aggregate, materially compress that segment of the x86 incumbents’ addressable market.

The compression is not yet visible in Intel’s and AMD’s reported revenue because hyperscaler purchasing happens on multi-year cycles, but the trajectory through 2028 is now clear.

The harder question for Arm is whether selling finished silicon to its existing licensees’ customers will compress its core IP-licensing revenue line.

The hyperscalers that previously paid Arm royalties through their own custom CPUs (Graviton, Cobalt, Axion) may now have less reason to maintain those programmes if Arm’s in-house AGI design covers the same workloads at comparable price-performance. The vertical-integration play, in other words, is its own competitive risk.

Arm shares were modestly higher in pre-market trading on the announcement. The AGI chip is shipping now to all three named customers.

[ad_2]

Source link

]]>
https://gaming.vmondeika.com/bytedance-and-oracle-are-using-arms-in-house-agi-cpu-completing-the-hyperscaler-x86-exit/feed/ 0