AI Weekly Malaysia

Back to items Summaries

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

ID
32195
Status
summarized
Published
06 Oct 2026, 2:56 PM
Fetched
06 Oct 2026, 5:23 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/fbi-removes-accenture-contractor-after.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
06 Oct 2026, 5:24 PM
Tags
Audience
developerssaas_founders

What happened

The FBI removed an Accenture contractor after a security failure on a third-party platform — reported by Reuters to be Oracle PeopleSoft — allowed ShinyHunters to steal personal details of thousands of FBI employees, according to assistant director Brett Leatherman. Mandiant assesses ShinyHunters bypassed a web application firewall rule protecting the vulnerable PSEMHUB endpoint for CVE-2026-35273 using a URL-encoding trick. Two ShinyHunters members have been arrested and the FBI says more are likely.

Why it matters

The concrete lesson is that the compensating control here was a WAF rule blocking a specific endpoint, and an attacker defeated it with URL encoding rather than a novel exploit — so if you rely on WAF path/endpoint rules instead of patching, treat those rules as temporary. The second detail worth acting on is contractual: the failure was attributed to a third-party-managed platform and a contractor who did not apply an explicitly issued patch, so patch SLAs and named accountability in vendor contracts are the thing to re-check, not your own stack. There is no Malaysian or Southeast Asian element in this text.

Discussion angle

Should a WAF rule ever be accepted as the fix for a known CVE, or only as a stopgap with an expiry date — and how would you write that into a managed-platform contract?

Top