The ITAM Roundup: 3/23/25

roundup Mar 23, 2025

📰 News

The Flexera 2025 State of the Cloud Report highlights key cloud computing trends, including the rise of dedicated FinOps teams to manage growing cloud costs, the ongoing competition between AWS and Azure for market dominance, and the increasing reliance on Managed Service Providers (MSPs) to handle cloud complexity. With 83% of respondents already using or experimenting with AI, new cost challenges are emerging, leading to the rise of “FinOps for AI.” The report underscores the continued expansion of cloud workloads, the need for cost optimization, and the growing role of MSPs in streamlining cloud management.

The latest cloud computing trends: Flexera 2025 State of the Cloud Report
Flexera’s 2025 State of the Cloud Report—the de facto standard for cloud computing trends—started as a little more than a snapshot capturing responses to 15 or so questions on the adoption and use of…

Inside the Google-Wiz acquisition and the deal’s biggest winners

Google is acquiring cloud security startup Wiz for $32 billion after a series of negotiations, making it one of the largest deals in the sector. Sequoia and Israeli VC firm Cyberstarts are among the biggest winners, with Cyberstarts securing the largest percentage gain. The TechCrunch Equity podcast covers this deal, Nvidia’s GTC highlights, the Klarna IPO, HR tech drama, and Waymo’s new airport mapping project.

Inside the Google-Wiz acquisition and the deal’s biggest winners
It was on, then off, and welp, now it’s on again — and this time for a lot more money. Yep, the Equity podcast dug into Google’s $32 billion acquisition of cloud security startup Wiz. There was a lot to unpack: the why, the how, what it means. And of course, there was the “who […]

SoftBank to acquire semiconductor designer Ampere in $6.5B all-cash deal

SoftBank is acquiring semiconductor designer Ampere Computing for $6.5 billion in an all-cash deal, positioning it as a wholly owned subsidiary to strengthen its AI infrastructure investments. Ampere, backed by Carlyle and Oracle, develops ARM-based server chips used by major cloud providers like Google Cloud, Microsoft Azure, and Alibaba. SoftBank sees this acquisition as a key step in advancing AI computing power, aligning with its broader AI initiatives, including partnerships with OpenAI and the AI infrastructure project Stargate.

SoftBank to acquire semiconductor designer Ampere in $6.5B all-cash deal | TechCrunch
SoftBank Group announced on Wednesday that it will acquire Ampere Computing, a chip designer founded by former Intel executive Renee James, through a $6.5

SAM Tools Market Research

The Software Asset Management (SAM) tools market is growing rapidly due to increasing software costs, compliance requirements, and the shift to cloud and SaaS environments, with Gartner estimating that up to 30% of software spending is wasted on unused licenses. Market projections indicate strong double-digit growth, with estimates ranging from $7.3 billion by 2029 (16% CAGR) to $16.5 billion by 2034, driven by cost optimization, vendor audits, and rising IT spending. While some conservative forecasts suggest slower growth (7–8% CAGR), most experts agree that SAM adoption will continue expanding as organizations seek to streamline software management and governance.

SAM Tools Market Research – Licenseware

In 2025, IT decision-makers face rising cloud costs, increased AI adoption, and pressure to modernize legacy systems. Many organizations are reconsidering cloud-first strategies in favor of hybrid models while integrating AI into business processes to improve efficiency and competitiveness. Meanwhile, CIOs must demonstrate the value of IT investments amid budget constraints, driving a focus on financial management and cross-functional collaboration to optimize technology strategies.

Trends driving IT decision-makers in 2025
AI, rising cloud costs, legacy systems

📖 Tips

Oracle Java subscription: How to easily gain visibility into your license agreements

Managing Oracle Java licenses has become increasingly complex due to frequent contract changes, including the shift to the Employee Universal metric, which can significantly impact costs. Organizations must gain full visibility into their Java environment, track license usage accurately, and consider alternatives like OpenJDK or Azul to optimize costs. SHI’s Oracle Discovery Application (SODA) provides an automated solution to scan, analyze, and optimize Java licensing, ensuring compliance and cost efficiency while preparing organizations for potential audits.

Oracle Java subscription: How to easily gain visibility into your license agreements
Learn how to gain visibility into your Oracle Java license agreements. Discover strategies for managing Java environments and optimizing your Oracle contracts with SHI’s Oracle Discovery Application (SODA).

Hardware Asset Management Software: 10 Tools For 2025

The list includes solutions such as InvGate Asset Management, Freshservice, Device42, FlexeraOne, and AssetPanda, among others, each offering unique features to cater to various organizational needs. The article also emphasizes the importance of selecting the right HAM software to enhance IT visibility, reduce costs, and ensure compliance with corporate policies and industry regulations.

Hardware Asset Management Software: 10 Tools For 2025
Looking for the best Hardware Asset Management software? Check out 10 top tools to streamline HAM, and improve IT visibility.

What is Cloud License Management?

Cloud License Management (CLM) helps companies gain visibility into their cloud software spend, optimize usage, and reduce compliance risks by tracking underutilization, preventing uncontrolled spending, and ensuring proper license management. Flexera’s CLM tool provides granular insights into software costs across multi-cloud environments, enabling businesses to cut waste, forecast expenses, and make informed budgeting decisions. By leveraging CLM, organizations can improve efficiency, avoid compliance penalties, and strategically manage their cloud software investments.

What is Cloud License Management?
ITAM has always been an integral part of most company’s strategic planning and decision making because of two incredibly powerful objectives – managing cost and managing risk and doing so has never…

How Companies Get Phase 0 Wrong—And Set Themselves Up for Disaster

Companies frequently fail large-scale IT transformation projects due to poor decision-making in the pre-implementation "Phase 0," rather than technology issues. These failures often stem from misaligned priorities, lack of independent governance, and reliance on system integrators (SIs) that prioritize their own interests over the company's success. To avoid disaster, businesses must take a business-driven approach to Phase 0, maintain decision-making control, and ensure competitive selection of implementation partners rather than defaulting to their Phase 0 advisors.

How Companies Get Phase 0 Wrong
Learn how companies get Phase 0 wrong to avoid costly mistakes and set your IT initiatives up for success with the right strategy.

Why you almost certainly have a shadow AI problem

Shadow AI, the unauthorized use of AI tools in organizations, poses significant risks, including data leakage and misinformation, yet many companies lack governance measures to address it. The rapid growth of AI capabilities far outpaces AI governance, making it difficult for businesses to control and mitigate risks effectively. To combat shadow AI, organizations should implement technical solutions like Retrieval-Augmented Generation (RAG), enforce security controls, and foster cultural awareness through AI literacy training, similar to cybersecurity education.

Why you almost certainly have a shadow AI problem
Battling the rising Shadow AI epidemic

🐛Bugs & Exploits

Veeam Fixes Critical Vulnerability in Backup & Replication Software

Veeam has released a security update to fix a critical remote code execution vulnerability (CVE-2025-23120) in its Backup & Replication software, which has a CVSS score of 9.9 and could allow unauthorized access to sensitive data. The issue affects version 12.3.0.310 and earlier builds, and users are urged to upgrade to version 12.3.1. Lansweeper has introduced a new report to help organizations identify at-risk Veeam installations and mitigate potential threats.

Veeam Fixes Critical Vulnerability in Backup & Replication Software - Lansweeper
Veeam released a security update for its Backup & Replication software addressing a critical RCE vulnerability. Update vulnerable devices now.

Oracle denies breach after hacker claims theft of 6 million data records

Oracle has denied claims of a data breach after a hacker, "rose87168," alleged they stole 6 million records from Oracle Cloud's federated SSO login servers and attempted to sell the data. The hacker provided a sample database and claimed access via a vulnerability, demanding 100,000 XMR for breach details, but Oracle maintains that no customer data was compromised. BleepingComputer is investigating the validity of the alleged stolen data and has contacted affected companies for confirmation.

Oracle denies breach after hacker claims theft of 6 million data records
Oracle denies it was breached after a threat actor claimed to be selling 6 million data records allegedly stolen from the company’s Oracle Cloud federated SSO login servers

VSCode extensions found downloading early-stage ransomware

Two malicious VSCode extensions, "ahban.shiba" and "ahban.cychelloworld," were found deploying in-development ransomware, highlighting flaws in Microsoft's review process. Despite being reported in November 2024, Microsoft allowed the extensions to remain for months, only removing them after security researchers flagged them again. This incident raises concerns about Microsoft's ability to detect threats promptly, especially as their review process has inconsistencies—sometimes removing non-malicious extensions too quickly while allowing actual threats to persist.

VSCode extensions found downloading early-stage ransomware
Two malicious VSCode Marketplace extensions were found deploying in-development ransomware from a remote server, exposing critical gaps in Microsoft’s review process.

Tags