Archive for Oracle

What the Oracle vulnerability says about today’s patching problem

Posted in Commentary with tags , on July 17, 2026 by itnerd

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite (EBS) financial application. The directive to repeat states that as mandated by Binding Operational Directive (BOD) 26-04, this needs to be patched by tomorrow. AKA Saturday.

Ted Miracco, Approov (https://www.linkedin.com/in/tedmiracco)

“Organizations continue to struggle to patch critical vulnerabilities quickly because enterprise resource planning (ERP) platforms like Oracle and SAP are highly customized and deeply interwoven with other business applications. Patching them isn’t like updating a web browser; a single database update can break custom API integrations, halting payroll, shipping, or manufacturing.

“The window for ‘safe testing’ no longer exists for edge-facing systems. In the past, organizations had 30 to 90 days to test and deploy patches before exploits were widely weaponized. Today, threat actors reverse-engineer patches and deploy exploits within days or even hours.

“To better prioritize and respond to these types of threats, security teams must implement strict Web Application Firewall (WAF) rules, sever internet exposure, or place vulnerable assets behind a Zero Trust Network Access (ZTNA) gateway until patches can be safely tested. When patches can be deployed to a staging environment, tested automatically, and instantly rolled back if they fail, emergency deployments become a low-risk routine rather than a weekend crisis.”

Damon Small, Board Member, Xcape, Inc. (https://www.linkedin.com/in/damon-small-7400501)

“Deploying a patch on a single computer may seem like a trivial task, but doing it across an enterprise that may have hundreds, or even thousands, of servers is daunting.  That said, we have seen incidents where a patched vulnerability is exploited months after it was resolved.  As an industry, we must strike a balance between operational readiness and patching fatigue.

The first open source vulnerability scanner was released in 1995.  Since then, vulnerability management has remained the least sexy, yet the most important, directive in cyber security.  Frankly, as an industry, we struggle to update software quickly, and this fact will become more problematic as the time between vulnerabilities being discovered and them being actively exploited continues to shrink.

Security leaders should first and foremost ensure that their organizations have accurate software and hardware inventories. You cannot defend what you can’t see. Additionally, as ‘silent’ or no-reboot patching becomes an industry standard, automatic updates may follow.”

Donald McFarlane, Advisory Board Member, Xcape, Inc. (https://www.linkedin.com/in/dmcfarlane)

“Organizations rarely fail to patch because they lack another alert: they struggle when they lack reliable asset inventories, clear ownership, tested maintenance paths, or the authority to interrupt business-critical systems and processes. In today’s machine-scale, machine-speed adversarial environment, IT organizations must deploy critical security patches far more quickly.  When immediate patching is not possible, leaders must prioritize vulnerabilities based on active exploitation, internet exposure, mission impact and potential blast radius, not severity scores alone.  They should know in advance who owns each critical system, how it can be isolated, and how emergency changes can be made safely.  

“Patching is not the finish line: organizations must determine whether an adversary arrived before the fix was applied. Find material exposure before an adversary does, fix it, and prove the risk actually went down.”

Kevin Surace, CEO, Token (https://www.linkedin.com/in/ksurace)

“Patching is rarely as simple as installing an update. Critical enterprise applications are often deeply connected to financial systems, databases, customized workflows, and third-party software, so teams fear that an untested patch could interrupt essential operations. 

“The deeper problem is that many organizations do not have an accurate, continuously updated inventory of their systems. They may not know which servers are exposed to the internet, which versions are running, who owns them, or whether a patch was successfully applied.

“In this case, Oracle released the patch in May, exploitation was observed by late June, and more than 1,000 Oracle E Business Suite systems were still exposed to the internet in July. That is not primarily a technology failure. It is a failure of ownership, visibility, testing capacity, and executive accountability.

“Urgent federal patching orders and extremely short remediation deadlines are becoming more visible, but this particular action was not technically a standalone Emergency Directive. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog under Binding Operational Directive 26 04 and required remediation within three days.

“The significance is the deadline. CISA is effectively telling agencies that once exploitation is confirmed, the traditional patching cycle is no longer acceptable. Attackers are weaponizing vulnerabilities faster, while many organizations are still operating through monthly maintenance windows, lengthy approval processes, and manual asset reviews.

“These directives also reveal an uncomfortable truth: too many organizations still need an external government deadline to force action on vulnerabilities that vendors have already patched.

“Security leaders should prioritize vulnerabilities based on actual exploitation, internet exposure, business importance, and the potential impact of compromise, not simply on the severity score. A vulnerability that is being actively exploited against an exposed financial system should move immediately ahead of a higher scoring flaw on an isolated test machine.

“Every critical system needs a named business owner, a technical owner, a tested emergency patching procedure, and a clearly defined authority capable of accepting the operational risk of patching or the security risk of delaying it. When exploitation is confirmed, teams should be able to patch, isolate, restrict network access, or temporarily remove a system from service without waiting through days of meetings.

“Organizations should also assume that patching may come too late. Organizations must review logs for evidence of earlier exploitation, rotate potentially exposed credentials, inspect connected systems, and protect privileged access with hardware based biometric assured identity.

“Biometric assured identity would not prevent an unauthenticated Oracle software exploit such as this one. It can, however, stop attackers from turning stolen administrator credentials into broader access after the initial compromise. Patching closes the software vulnerability. Biometric assured identity helps contain what attackers can do next.”

Steven Swift, Managing Director, Suzu Labs (https://www.linkedin.com/in/steven-swift-5238956a)

“Patching is a big thankless task, and it rarely gets the resourcing it would require to actually patch all the things quickly. In order to have any chance at keeping up with patching, organizations need to implement solutions to automate both patching and vulnerability scanning.

“A lot of organizations are hesitant to patch immediately, because there have been enough issues with bad patches being released over the years, that the risk of patching slowly is preferred over the risk of patching fast and breaking things.

“Patching automation is great for those systems which are consistently deployed across the organization. However, the applications that are only on a few systems are those least likely to have automated patching. This would be fine, except for that there tends to be a lot of applications that fall into this category. Practically, that means staff can patch the vast majority of things consistently and in a timely manner, and still always have a long tail of vulnerabilities that are more challenging to fix.

“This is compounded when ownership is split between different teams. Especially so when organizational priorities are split. If teams are under pressure to hit tight deadlines, the last thing they want to do is spend time fixing/patching things that don’t directly assist in that goal. This results in a lot of vulnerability management teams spending much of their time providing reports on what needs patching, to teams that will get to it when they get to it.

“As for what leadership can do to better prioritize and respond to new vulnerabilities? A big part of is keeping metrics so that the work being done isn’t invisible anymore. If the team is consistently patching 90% of all published CVEs in a timely manner, and yet all that leadership sees are reports showing the remaining 10%, it can look like the team just isn’t doing much patching when the opposite is true.

“Track stale vulnerabilities in the organization, and prioritize those. Stale can be older than 30, 90, or 365 days for example. Depending on how mature existing processes are. Once all of the stale vulnerabilities are remediated, build automation to handle as much repeatable work as is possible. Provide developers with vulnerability feedback as early in the process as you can, as it costs much less time and money to fix code early on, than it does after release.”

While it is beyond time to patch all the things, organizations need rethink how they go about keeping their environments safe. Because patching is clearly not enough.

Attackers exploit critical Oracle E-Business vulnerabilitie

Posted in Commentary with tags on June 29, 2026 by itnerd

Threat intel company Defused has reported that attackers are exploiting a critical vulnerability which is named CVE-2026-46817 in the Oracle E-Business Suite (EBS) financial application.

The vulnerability in the File Transmission component of EBS’s Oracle Payments product lets unauthenticated malicious actors with HTTP network access to take over vulnerable systems through low-complexity attacks.

Oracle released security updates to address the vulnerability in the May 2026 Critical Security Patch Update and urged that customers patch immediately. The vulnerability has no known previous exploitation or POC, according to Defused.

Sunil Gottumukkala, CEO of Averlon had this comment:

“This is an unauthenticated, low-complexity takeover of Oracle E-Business Suite, which runs many companies’ financials and payments, so the value to an attacker is obvious. EBS is already a known extortion target.

“Oracle shipped the patch in May, there is still no public proof-of-concept, yet attackers are already exploiting it, most likely by reverse-engineering the patch itself. A released fix can become the attacker’s roadmap, which is why the exposure window, the gap between when a patch ships and when it’s actually deployed, is where the real risk lives. Every day a critical vulnerability sits unpatched is another day inside that window.

“Organizations running EBS Payments on affected versions have no time to spare. Patch now, take the File Transmission component off the open internet, and hunt for compromise.”

Denis Calderone, CTO, Suzu Labs had this to say:

“The Cl0p campaign that exploited CVE-2025-61882 across more than a hundred Oracle EBS environments proved two things. First, that Oracle EBS is a target-rich environment full of financial, HR, and procurement data worth serious extortion money. And second, that a lot of organizations are running internet-exposed EBS instances and not patching fast enough. CVE-2026-46817 looks like what follows when that kind of spotlight gets put on a platform. Different actors, different component, but the same exposed attack surface. And this time, the target is Oracle Payments’ File Transmission module, the component that formats and transmits payment instructions, ACH batches, wire transfers, and EFT files directly to financial institutions.

“Some months back we all witnessed Cl0p’s Oracle EBS campaign hit over a hundred organizations using a sophisticated five-step exploit chain through BI Publisher that required SSRF, CRLF injection, path traversal, and malicious XSLT template processing just to get to code execution. That was a fairly sophisticated chained attack. CVE-2026-46817 looks far less complex, more like the front door was just left wide open. There is no authentication on the HTTP endpoint, and no complex exploit chain required. A crafted HTTP request gets you from zero access to full control of the system that formats and transmits ACH batches, wire transfers, and EFT files to financial institutions. Oracle EBS has a definite spotlight on its back. Now we have different actors picking different components, and we’d argue this is potentially much worse.

“The way the File Transmission component handles file operations can be exploited to execute arbitrary code on the server, and the attacker lands with enough privilege to take over Oracle Payments entirely. Oracle scored it a 9.8. File Transmission is the component that opens connections with banks and payment systems to send formatted payment instruction files. Full takeover of that system means potential access to read, modify, or redirect financial transactions.

“What’s got our attention is the exploitation timeline. There is no public proof-of-concept code for this vulnerability. Defused observed active exploitation on their Oracle EBS honeypots over the weekend. This probably means that someone reverse-engineered Oracle’s May patch, built a working exploit, and deployed it operationally in under six weeks. That tells you something about the caliber of actor going after this and how much value they see in owning a payment processing system.

“Oracle EBS is self-hosted, so the attack surface is entirely in your hands. If your Oracle Payments File Transmission endpoints are reachable over HTTP from untrusted network segments, restrict that access immediately to trusted internal sources only. Apply the May 2026 Critical Patch Update. The affected version range is 12.2.3 through 12.2.15, nearly identical to the Cl0p campaign’s target set. And given the six-week window between patch availability and confirmed exploitation, assume compromise and hunt for indicators of unauthorized access to your payment processing infrastructure going back to late May. If you’re running these versions, treat this as an emergency, not a quarterly maintenance item.”

Since organizations are in control, it is up to organizations to patch all the things. And I recommend that organizations do so before there is an attack that comes of this.

Harvard Has Apparently Been Pwned Via The Oracle Vulnerability

Posted in Commentary with tags , on October 14, 2025 by itnerd

Remember this Oracle vulnerability that is far from trivial? It now has its first confirmed victim outside of Oracle. And unfortunately for Oracle, it’s Harvard. Yes. That Harvard.

The cybercrime group Cl0p is now seemingly reaping the harvest after it successfully exploited a critical zero-day bug in Oracle’s E-Business Suite (EBS). Hundreds of companies and organizations – all Oracle clients – were allegedly compromised.

One of them is apparently Harvard University, which uses EBS for various administrative functions. Now, Cl0P, essentially a digital organized crime ring, has claimed it had stolen data from the prestigious school.

And:

According to Cybernews researchers, Cl0p has shared 1.4TB of data on its leak site. This data originates from Harvard’s servers hosted by Oracle.

The published data includes logs and reports from Harvard’s internal payment system as well as source code for various internal tools. Cybernews research team has analyzed the data and says it includes references that strongly suggest that it was indeed taken from OBS systems.

Anders Askasen, VP of Product Marketing, Radiant Logic had this to say:

     “The Harvard breach tied to the Oracle EBS exploitation highlights a recurring truth: complexity is the adversary of security. When identity and data silos persist, visibility evaporates, and the ability to trace who has access to what becomes guesswork. Systems like Oracle EBS sit at the heart of enterprise operations — rich in sensitive HR and financial data, yet notoriously hard to govern across hybrid infrastructures. Resilience begins with a unified identity data foundation and continuous observability that enable organizations to detect exposures in real time, contain and act with precision, and restore confidence through verifiable facts rather than assumptions”


Will Baxter, Field CISO, Team Cymru follows with this comment:

“This threat highlights the importance of egress filtering and monitoring where files are downloaded from. This operation appears to have exploited the vulnerability weeks ahead of patch release, indicating early access or a brokered exploit. Detecting these campaigns early depends on correlating outbound anomalies, C2 beaconing, and shared infrastructure across sectors. The only scalable defense is collective intelligence — connecting enterprise telemetry with trusted partners before the stolen data surfaces publicly.”

Gunter Ollmann, CTO, Cobalt adds this comment:

“This campaign underscores the growing sophistication of financially motivated groups exploiting enterprise software supply chains. The attackers didn’t rely on a single exploit—they combined zero-day vulnerabilities with custom malware to maximize access before detection. It’s another reminder that penetration testing can’t stop at application edges; enterprises must stress-test complex ERP systems as part of their attack surface. Increasingly, the focus must shift toward offensive security services that continuously test not just applications, but also the effectiveness of defense-in-depth systems and SOC teams. Regular, adversarial testing provides the real-world validation organizations need to ensure their layered defenses perform as intended when it matters most.”

Sucks to be Harvard. And it sucks even more to be Oracle who’s senior management have to be reconsidering their life choices at this point. Because they know that there will be more fallout, and the lawsuits that follow that fallout.

Oracle Pretty Much Confirms That They Got Pwned By Cl0p

Posted in Commentary with tags , on October 7, 2025 by itnerd

Oracle has warned of a critical zero-day vulnerability, with a CVSS base score of 9.8, in its E-Business Suite (CVE-2025-61882) that is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution. Chances are that this is how the Cl0p ransomware gang was able to launch their latest campaign.

Ensar Seker, CISO at SOCRadar, commented:

“The exploitation of CVE-2025-61882 by the Clop ransomware group reinforces a hard truth security leaders continue to wrestle with: legacy enterprise software with sprawling configurations like Oracle E-Business Suite (EBS) remains a ripe target for modern ransomware operators. This vulnerability, rated 9.8 CVSS, allows unauthenticated remote code execution and is being actively exploited in the wild, making it one of the most dangerous types of flaws we see in enterprise environments. What makes this case particularly alarming is that the attack chain appears to span multiple vulnerabilities across different patch cycles, including one disclosed only days ago. Clop is clearly operating with a highly proactive exploitation model, monitoring Oracle patches and working quickly to reverse-engineer the flaws for immediate weaponization.

“The fact that proof-of-concept (PoC) code was circulating on Telegram and used in real-world data exfiltration attacks just weeks after patch release underscores how rapidly threat actors are moving to capitalize on enterprise inertia. This incident also highlights a serious procedural gap in many organizations: the critical patches for Oracle EBS can only be applied if the previous quarterly update (in this case, October 2023) is already in place. That creates an unintended but dangerous bottleneck where even security-conscious teams can find themselves exposed simply because they’re one patch cycle behind.

“Clop’s focus on Oracle EBS is no accident. These systems often house sensitive financial, HR, and operational data, and because they’re deeply integrated into business workflows, they’re notoriously difficult to update without risking downtime. That’s exactly the kind of environment threat actors love: high-value, low-change.

“Security teams should act immediately to verify patch levels and apply the latest fixes, but this needs to go beyond a break-fix mindset. Organizations must rethink their patch readiness processes for ERP-class systems, including pre-staging test environments, reducing configuration drift, and tightening external access to legacy interfaces like BI Publisher and Concurrent Processing.

“In parallel, defenders should hunt for indicators of compromise shared by Oracle and Mandiant and conduct forensic reviews of EBS systems for unusual BI Publisher activity, unauthorized concurrent jobs, or unexplained external network connections.

This is another case where visibility and segmentation matter. Oracle EBS should never be directly internet-exposed, and authentication should be enforced at all layers, even where Oracle’s native security falls short.

“Ultimately, the Clop campaign against Oracle EBS is a wake-up call that ransomware actors are not just opportunistic. They are increasingly strategic, surgical, and tuned into vendor ecosystems. Defenders must be equally proactive in hardening the software foundations that underpin their critical operations.”

SOCRadar posted a really good analysis of this here and it is totally worth your time to read. In the meantime, this is not a good look for Oracle. I wonder what they have to say about it?

UPDATE:  Adrian Culley, Senior Sales Engineer at SafeBreach adds this insight:

“The Cl0p extortion gang is combined under ‘The Com,’ which is a loose collective of hackers that includes individuals from Lapsus$ and Scattered Spider. The Com—short for ‘The Community’—is a fluid, international collective of mostly young, English-speaking individuals. Crucially, they’re not motivated by politics or ideology—their drivers appear to be purely money and ego. They thrive on notoriety, loudly bragging about their exploits on platforms like Telegram, which pushes members toward more brazen, high-profile attacks. While they are clearly very skilled, their precociousness leaves them highly vulnerable to nation state infiltration and manipulation.

The group’s roots begin with LAPSUS$ in 2021 and 2022, when they demonstrated just how devastating social engineering could be against giants like Microsoft, Nvidia, and Okta. But their work was somewhat erratic, and they often focused on chaos and notoriety.

Scattered Spider took that playbook and professionalized it, moving from chaotic data theft to financially devastating ransomware campaigns. They have been able to master the initial access problem with their native English skills and mastery of social engineering.

The Com, which has evolved out of these two groups, relies heavily on voice phishing as their most effective TTP to get past multi-factor authentication. The group uses highly ephemeral IOCs. The phishing domains they use are often active for less than seven days. This means that organizations relying on a purely reactive security posture—for example, blocklisting known IPs or domains—are often behind the curve.

The latest threat that has come to light with the Oracle e-business suite is a critical, 9.8-rated CVE. Organizations should patch immediately and then begin to shift from testing code to testing policy and procedure. BAS and AEV tools can help organizations focus on validating the Human Firewall.

BAS can simulate the reconnaissance phase, testing whether employees overshare PII online that an attacker could use to build a convincing persona. It can also continuously push bomb an organization’s MFA solution to measure the Mean Time to Detect and block the attack before a frustrated user approves the request.

An AEV platform can help confirm that an organization’s help desk is uncompromisable. Are they enforcing policies like a vocal password or two-employee approval for privileged account resets, even when the supposed caller provides all the PII they should know? Finally, AEV must continuously test an organization’s IAM posture, ensuring they can detect and immediately flag actions like a compromised admin creating malicious cloud instances or forging SAML tokens for persistence.”

Oracle Apparently Has Been Pwned And Extortion Emails Have Gone Out To Execs Of Companies Using E-Business Suite

Posted in Commentary with tags , on October 3, 2025 by itnerd

There’s a newly reported extortion campaign, where hackers claim to have stolen sensitive data through Oracle’s E-Business Suite and are now targeting executives directly:

According to Google Threat Intelligence Group (GTIG) and Mandiant, the malicious activity allegedly targeting Oracle EBS appears to have started on or around September 29. The attackers have sent extortion emails to executives at “numerous” companies, claiming to be affiliated with the notorious Cl0p cybercrime group.

GTIG and Mandiant researchers have described the attacks as a high-volume email campaign leveraging hundreds of compromised accounts, including ones previously linked to a profit-driven threat group named FIN11. This long-running cybercrime gang is known to engage in ransomware deployment and extortion.

The researchers also found some evidence indicating a connection to Cl0p. Specifically, the contact information provided by the attackers in the emails sent to targeted organizations matches contact addresses listed on the Cl0p leak website.

Mandiant and GTIG said they are in the early stages of their investigations and could not confirm whether the hackers’ claims are substantiated. 

Dr. Chris Pierson, a former DHS cybersecurity official and CEO/founder of BlackCloak, a digital executive protection firm had this to say:

     “Extortion attempts like this highlight the reality that executives are increasingly being singled out as the soft underbelly of the corporation for cybercriminals. Cybercriminals recognize that targeting the C-suite creates urgency, exposes them to high risk, and instills fear that can lead to other issues. The challenge for organizations is twofold: hardening the systems that store the most sensitive corporate data, and ensuring executives are prepared with the right playbook when extortion attempts land in their inbox. Third-party vendor risks will continue to be a favorite target of cybercriminals, and we’ve seen a marked increase in these systems being targeted because they yield information on not one company, but hundreds or thousands of companies.  The companies that come out ahead are those that treat digital executive protection as part of their overall cybersecurity posture rather than an afterthought.”

Oracle said via a blog post that they believe the threat actors exploited vulnerabilities patched in the July 2025 security updates. But they have said no more than that. Which likely means that this is going to be very, very bad. Oracle looks like it has some explaining to do.

CISA Warns of Credential Risks From Oracle Cloud Leak

Posted in Commentary with tags , on April 17, 2025 by itnerd

You might recall the recent Oracle cloud breach. If not, this and this will act as a refresher.

Related to that, the CISA has warned of potential unauthorized access to legacy Oracle cloud environments related to exposed credentials reused across separate, unaffiliated systems, or embedded (i.e., hardcoded into scripts, applications, infrastructure templates, or automation tools).

Details can be found here: https://www.cisa.gov/news-events/alerts/2025/04/16/cisa-releases-guidance-credential-risks-associated-potential-legacy-oracle-cloud-compromise  

Jim Routh, Chief Trust Officer at Saviynt, provided the following comments:

“Software engineers often embed authentication credentials or scripts for convenience when applications are being tested before production. However, engineers often neglect to remove the embedded credentials once the code is put into production. This creates a vulnerability that threat actors actively exploit, giving them access to the application where they may escalate privileges, obtaining access to more sensitive information. There are now tools available that identify credentials in software code, but these tools are not widely used. The root cause of this problem for enterprises is to improve processes for credential management using more advanced privileged access management capabilities and seeking alternatives to credentials through passwordless authentication options.”

You can expect more warnings like this in the near future as this Oracle breach really has the potential to be THE breach of the year.

SOCRadar’s CISO Comments On The Oracle Cloud Data Breach

Posted in Commentary with tags on March 29, 2025 by itnerd

A threat actor using the alias “rose87168” claimed responsibility for breaching Oracle Cloud systems, allegedly stealing 6 million user records containing encrypted passwords, authentication keys, and directory credentials. Oracle has denied any breach occurred, stating no customer data was compromised.

To investigate these claims, SOCRadar contacted the threat actor, who provided the below 10,000-record sample. This dataset appears consistent with real Oracle Cloud user information, including structured fields like user IDs, encrypted credentials, and company-specific domains. While SOCRadar cannot confirm the full 6 million record claim, the sample’s format and content seem legitimate and not easily fabricated.

According to Ensar Seker, CISO at SOCRadar:

“Several other security researchers and vendors have also analyzed the sample. At least three Oracle Cloud customers reportedly confirmed their information was present in the leaked data, further supporting its authenticity. These confirmations, along with observed Indicators of Attack (IOAs) such as irregular logins and suspicious file activity, suggest that the breach may indeed be real.

The hacker continues to provide screenshots and additional data fragments to prove the claim. The screen shot illustrates structured user data likely sourced from an identity management system. The actor also claims to have exploited a known vulnerability (potentially CVE-2021-35587), though this has not been confirmed.


Despite the mounting evidence, Oracle maintains its stance that no breach occurred. The company has provided no technical explanation or alternative theory for the leaked data’s origin. This leaves many Oracle Cloud customers in a difficult position—unable to fully assess their exposure without further guidance.

In cybersecurity, even unconfirmed incidents should be treated with seriousness when multiple independent sources identify potential compromise. We recommend organizations remain vigilant, monitor their environments closely, and follow trusted updates from Oracle and the security community.

We urge all Oracle Cloud users to take precautionary steps, including:

  • Reviewing security logs from mid-February onward for unusual login attempts or access patterns.
  • Auditing user accounts, especially those with administrative privileges.
  • Rotating sensitive credentials such as SSO and LDAP passwords or keys.
  • Ensuring multi-factor authentication (MFA) is enabled across all accounts.”

Much as I said in this post, this might be the breach that we’re all talking about in 2025. So far, my hunch on this is proving correct.

A Deal Involving Oracle And Microsoft To Buy TikTok Is Allegedly On The Table

Posted in Commentary with tags , , on January 26, 2025 by itnerd

TikTok’s corporate masters Byte Dance have been consistently saying that TikTok isn’t for sale. But according to this story, a deal may be in the works:

The Trump administration is working on a plan to save TikTok that involves tapping software company Oracle and a group of outside investors to effectively take control of the app’s global operations, according to two people with direct knowledge of the talks.

Under the deal now being negotiated by the White House, TikTok’s China-based owner ByteDance would retain a minority stake in the company, but the app’s algorithm, data collection and software updates will be overseen by Oracle, which already provides the foundation of TikTok’s web infrastructure. 

That would effectively mean American investors would own a majority stake in TikTok, but the terms of the deal could change and are still being hammered out.

“The goal is for Oracle to effectively monitor and provide oversight with what is going on with TikTok,” said the person directly involved in the talks, who was not authorized to speak publicly about the deliberations. “ByteDance wouldn’t completely go away, but it would minimize Chinese ownership.”

NPR has agreed not to name the sources, who are not authorized to speak publicly about the confidential talks.

Other potential investors who are engaged in the talks include Microsoft.

If any of this sounds familiar, it should. The last time Donald Trump was president, he tried to engineer a deal involving Oracle and WalMart among others. But the deal fell apart. Microsoft was also said to be interested in buying TikTok. But that deal went nowhere at least twice. So, will it happen this time? I have no clue. But we have less than 75 days to see what happens as that’s how long the TikTok executive lasts.


Oracle Gets Served With A Class Action Lawsuit Of Epic Proportions

Posted in Commentary with tags on August 23, 2022 by itnerd

Lawyers for software giant Oracle are going to be busy as they’re now going to be dealing with a class-action lawsuit.

The class-action has three class representatives, including Dr. Johnny Ryan, Senior Fellow of the Irish Council for Civil Liberties (ICCL), and was filed against Oracle in the U.S. District Court for the Northern District of California. It alleges Oracle has violated the Federal Electronic Communications Privacy Act, the Constitution of the State of California, the California Invasion of Privacy Act, competition law, and the common law. How did they do that? The lawsuit claims that Oracle created a network containing personal data of hundreds of millions of people and sold said data to third parties. Which is why the class includes every Internet user on the planet. Which makes this lawsuit in a word, epic.

Here’s the kicker. The plaintiff’s claim is backed up by a video on the ICCL website of Oracle CEO Larry Ellison describing how the company’s real-time machine learning system collects this information and states that 5 billion profiles are stored in the “Oracle Data Cloud.” Which I am guessing that the ICCL thinks is the digital smoking gun that they need to win this lawsuit.

As far as I can tell, Oracle hasn’t commented on this. But Chris Olson, CEO, The Media Trust has:

     “In 2016, the rules for data targeting were still up in the air – since then, emerging data privacy legislation has drawn a hard line around microtargeting, collecting and selling user’s data without express permission. However the ICLL’s lawsuit pans out, the fact that it’s happening is a major development for businesses around the world, especially since it is happening in the U.S, and alleges a violation of California law.

While not all businesses directly harvest data from their users in a way that violates data privacy legislation in Europe or America, most partner with digital vendors who do, whether through their websites or mobile platforms. Now more than ever, businesses must commit to digital trust and safety protections – otherwise, it is only a matter of time before they will suffer from breaches, lawsuits and expensive fines.”

It’s going to be interesting to see how Oracle responds to this. Because if they lose, it’s going to be expensive.

Oracle Kills Sun Microsystems At Last

Posted in Commentary with tags on September 5, 2017 by itnerd

The news is out is that Oracle laid off the core talent of the Solaris and SPARC teams on Friday. The timing sucks as they did this just before Labour Day which has really craptastic optics. Unofficial tallies on the TheLayoff.com and elsewhere put total of jobs cut at around 2,500, affecting the company’s Santa Clara and San Diego, Calif. offices, as well as people in Austin, Texas, Broomfield, Colo., Burlington, Mass., and India.

Oracle itself hasn’t commented on this, which is typical for them, but it does basically bring to an end one of the more famous names in the IT industry. Oracle became the owner of Solaris as it was one of the properties that were part of its 2010 acquisition of the company. Other well-known assets were Java, MySQL and OpenOffice, with Oracle making no secret about the fact that it was buying Sun only because of Java and its business prospects. With Oracle shifting its focus to cloud services and software platforms, this day was coming. I’m kind of surprised that it took this long to happen.

RIP Sun Microsystems.