FBI Data Breach Linked to Unpatched Oracle PeopleSoft Vulnerability (CVE-2026-35273) Exploited by ShinyHunters
The FBI has removed an Accenture contractor following a significant data breach attributed to the ShinyHunters threat group, which exposed personal details of thousands of FBI employees and applicants. The incident was caused by the contractor's failure to apply a critical security patch for Oracle PeopleSoft (CVE-2026-35273). ShinyHunters exploited this unpatched vulnerability using a URL-encoding technique to bypass web application firewall (WAF) protections and gain unauthorized access to the FBI's job portal.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.