Application security, Third-party code, Threat Intelligence

FBI contractor removed after data breach due to unapplied security patch

The FBI seal is seen on its headquarters at the J. Edgar Hoover FBI building in Washington.

The FBI confirmed a security failure on a platform managed by a third party led to a data breach affecting thousands of employees, according to a recent report by Information Week.

The incident occurred because a contractor failed to implement a critical security patch for Oracle's PeopleSoft ERP software. This vulnerability, identified as CVE-2026-35273, was exploited by threat actors like ShinyHunters, who modified their attacks to bypass existing security measures. The FBI's experience highlights a growing challenge for organizations: ensuring timely patching when responsibility is distributed across multiple external entities. Verizon's 2026 Data Breach Investigations Report indicates that vulnerability exploitation is now the leading initial access vector for breaches, with AI accelerating the timeline from vulnerability disclosure to exploitation. The FBI breach underscores the complexity of modern IT environments, where a single vulnerability can have far-reaching consequences due to the interconnectedness of vendors, managed service providers, and contractors. This fragmentation of control makes it difficult for any single entity to guarantee system security, as demonstrated by the 60% rise in breaches involving third parties.

Source: Information Week

You can skip this ad in 5 seconds