There you have it! The FBI just removed an Accenture contractor after a security patch for Oracle…
October 6, 2026 · 0 likes · 0 comments
AI Defense Cybersecurity
There you have it! The FBI just removed an Accenture contractor after a security patch for Oracle PeopleSoft never got installed, and the hacking group ShinyHunters used that gap to steal personal, medical and psychiatric records on thousands of FBI employees.
Oracle and Google both warned PeopleSoft customers back in June to install every critical patch without delay. The FBI's own cyber division assistant director, Brett Leatherman, said the incident happened "after a contractor failed to implement a security patch explicitly issued to secure the platform." Reuters' sources named Accenture as the contractor, and Google's Mandiant traced the break-in to CVE-2026-35273, where the attackers double-encoded a request to slip past a web application firewall that was supposed to block exactly that. A firewall rule was standing in for a patch that nobody applied, and Cybernews reported the stolen data included descriptions of named employees' counterintelligence assignments and street addresses of intelligence operatives, which former FBI officials called a major blow to the bureau's operational security.
While the FBI does not follow it, this is exactly the supply chain failure CMMC was built for. For the Department of War, Level 2 is NIST 800-171, which requires you to find and fix flaws in a timely way, and the whole idea is that the contractor has to prove it before the breach, instead of the government finding out after thousands of people's home addresses are on a leak site.
Most of the defense industrial base is made of small and mid-size companies that hold sensitive data for the Pentagon and don't have a team watching every patch. If you're one of them, CloudFit Software, one of our amazing sponsors for UBH, offers easyCMMC to help you get your CMMC requirements in order. I'd rather see you do that now than explain a missed update to a customer later.
Full breakdown on UnbiasedHeadlines.com, an unbiased news site built entirely by AI agents. No spin, just the facts: https://lnkd.in/eKBMqdam
If someone audited your patching today, would you pass but more importantly, are you secure?
Oracle and Google both warned PeopleSoft customers back in June to install every critical patch without delay. The FBI's own cyber division assistant director, Brett Leatherman, said the incident happened "after a contractor failed to implement a security patch explicitly issued to secure the platform." Reuters' sources named Accenture as the contractor, and Google's Mandiant traced the break-in to CVE-2026-35273, where the attackers double-encoded a request to slip past a web application firewall that was supposed to block exactly that. A firewall rule was standing in for a patch that nobody applied, and Cybernews reported the stolen data included descriptions of named employees' counterintelligence assignments and street addresses of intelligence operatives, which former FBI officials called a major blow to the bureau's operational security.
While the FBI does not follow it, this is exactly the supply chain failure CMMC was built for. For the Department of War, Level 2 is NIST 800-171, which requires you to find and fix flaws in a timely way, and the whole idea is that the contractor has to prove it before the breach, instead of the government finding out after thousands of people's home addresses are on a leak site.
Most of the defense industrial base is made of small and mid-size companies that hold sensitive data for the Pentagon and don't have a team watching every patch. If you're one of them, CloudFit Software, one of our amazing sponsors for UBH, offers easyCMMC to help you get your CMMC requirements in order. I'd rather see you do that now than explain a missed update to a customer later.
Full breakdown on UnbiasedHeadlines.com, an unbiased news site built entirely by AI agents. No spin, just the facts: https://lnkd.in/eKBMqdam
If someone audited your patching today, would you pass but more importantly, are you secure?