Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Oracle Hit by Zero-Day Hack of 100+ Companies and a Stock Crash on the Same Day

Since the Iran strikes and market volatility that have dominated this week's headlines, Oracle has delivered its own double-punch of bad news: a confirmed zero-day cyberattack hitting over 100 organizations, and an earnings-driven stock crash that erased roughly $72 billion from its market cap in a single session.
The PeopleSoft Zero-Day
Oracle published a security advisory on Thursday, June 11, warning customers of a critical-rated vulnerability in its PeopleSoft software — the platform large employers use to manage payroll and human resources. The warning came one day after the cybercrime group ShinyHunters claimed credit for exploiting it.
The flaw is a zero-day, meaning Oracle had no time to develop a fix before attackers were already using it. As of Thursday afternoon, according to TechCrunch, no patch exists. Oracle told customers to apply available mitigations instead.
What makes this worse: the bug requires ZERO authentication. No password, no credentials — just a network connection and the exploit code. Anyone with internet access could abuse it.
Mandiant, Google's cybersecurity unit, confirmed in a blog post that it has notified more than 100 global organizations about the vulnerability. The majority are in the United States. Mandiant said roughly two-thirds of the targeted organizations are in higher education — universities and colleges — which lines up with what ShinyHunters told TechCrunch directly.
A ShinyHunters member told TechCrunch that stolen data from at least one school includes "hundreds of thousands of student records" containing full names, home addresses, phone numbers, email addresses, dates of birth, gender, ethnicity, enrollment status, GPA, major, and student ID numbers. Mandiant noted that while several organizations blocked the intrusion or patched their systems, others were fully compromised and had their data published on ShinyHunters' data leak site.
Oracle did not respond to TechCrunch's request for comment.
The Stock Collapse
Separate from the security crisis, Oracle's fiscal fourth-quarter earnings — released Wednesday evening — triggered a sharp selloff Thursday. According to Livemint, shares fell as much as 13% to $175.30 on the New York Stock Exchange, a four-week low, and the stock is now down 21% month-to-date after erasing most of a 39% gain in May.
The numbers themselves were not the problem. Revenue for the quarter ended May 31 jumped 21% to $19.18 billion, beating the $19.1 billion analyst consensus tracked by LSEG, according to CNBC. Adjusted EPS of $2.03 topped the $1.96 estimate. Cloud infrastructure revenue surged 93% to $5.8 billion. The company's remaining performance obligation — a forward revenue indicator — hit $638 billion, up 363%, against a Street Account estimate of $595.67 billion.
What spooked investors was the spending. Capital expenditures for the full fiscal year hit $55.7 billion, 162% higher than a year ago and above Oracle's own $50 billion projection, according to Livemint. Free cash flow came in at negative $23.7 billion for the year, compared with a deficit of just $394 million in fiscal 2025.
New CFO Hilary Maxson told investors that net capital expenditure for fiscal 2027 will be approximately $70 billion, excluding $20 to $25 billion in customer prepayments. To fund it, Oracle plans to raise $40 billion through debt and equity, including a $20 billion stock sale previously announced — on top of the $43 billion in debt and $5 billion in equity already raised in fiscal 2026, according to CNBC.
The Bull Case Deserves a Fair Hearing
The concern among skeptics is real: Oracle is burning cash at an accelerating rate while competing against cloud giants — Amazon, Microsoft, Google — that generate far larger operating cash flows and can self-fund their AI buildouts. The fear is that Oracle is leveraging its balance sheet to chase a market it may not be able to win, and that dilution from equity issuances will cap shareholder returns.
This is a legitimate concern. Piper Sandler analysts, who recommend buying the stock, wrote in a report Wednesday that they remain "constructive on ORCL's AI-driven consumption growth." Oracle's backlog of $638 billion is not speculative; it represents signed contracts. The company's guidance of $90 billion in fiscal 2027 revenue, with adjusted EPS of $8.05, beat the Street's $8.01 and $88.9 billion estimates. Customers like Meta and OpenAI are already using Oracle's cloud infrastructure for high-end AI workloads. The company is not spending blindly. It is building to fulfill contracted demand.
Bank of America analysts also maintained a buy recommendation, according to CNBC.
Two Problems That Compound Each Other
The timing is bad for Oracle. A major unpatched security vulnerability in HR and payroll software used by large corporations and universities will make procurement officers nervous. The company's core enterprise business is already under competitive pressure from AI tools that Oracle's own cloud is supposed to support.
The unresolved question as of June 11 is when Oracle will release a patch for the PeopleSoft zero-day. Mandiant's notification of 100-plus organizations is a mitigation step, not a fix. Until Oracle ships a working patch, every PeopleSoft customer running internet-facing servers is operating with a known, actively exploited critical vulnerability. ShinyHunters has already demonstrated it knows how to use it at scale.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.