A Missed Patch Exposed FBI Staff, Plus 3 Stories
A missed patch is rarely just a missed patch. Sometimes it becomes a data breach. Sometimes it exposes medical records. And sometimes, apparently, it exposes the home addresses of people doing human-intelligence work for the FBI.
A Known Patch, a Contractor, and an FBI Breach
The FBI removed an Accenture contractor Monday after determining that a security update hadn’t been applied to a third-party-managed platform, according to a Reuters investigation. Two sources identified the platform as Oracle PeopleSoft and the outside organization as Accenture. Accenture told Reuters it remains proud to support the FBI, but didn’t answer the publication’s questions about the contractor or the failed patch.
The exposed information reportedly includes detailed descriptions of named employees’ counterintelligence work, street addresses of human-intelligence operatives, and medical and psychiatric records. That’s more than the usual identity-theft mess. Home addresses and job descriptions can put employees, sources, and families at risk. The FBI says it has removed the contractor and taken steps to protect its workforce, but it’s still working out the full consequences.
Here’s where the technical detail matters. Google warned in June that ShinyHunters was exploiting a PeopleSoft weakness, and Oracle issued security fixes the same day. The broader campaign has been associated with CVE-2026-35273 in PeopleSoft Environment Management Hub, where unsafe Java object deserialization can let an attacker run code remotely. In plain English, the server can be tricked into rebuilding attacker-controlled data as a live Java object and executing behavior it never should have trusted.
Reuters hasn’t publicly established that CVE-2026-35273 was the exact FBI entry point, so I’m not going to pretend the remaining forensic question has already been answered. What the FBI’s cyber chief did confirm is the operational failure: a contractor didn’t apply a patch explicitly issued to secure the platform.
This is why “we sent the patch notice to the vendor” isn’t a control. Somebody needs to own the update, somebody needs to verify that it actually landed, and somebody needs to investigate if an internet-facing system stayed vulnerable while attackers were already using the flaw. A closed ticket isn’t proof of a patched server. It is, at best, proof that a ticket got closed.
If your business outsources an application, ask who tracks vendor security alerts, how quickly urgent patches must be tested and deployed, and what evidence you receive afterward. Then make sure the contract’s responsibility chart matches reality. “The contractor handles it” is not especially comforting after your data leaves with the attacker.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
Google’s Spirit Data Deal Clears a Privacy Hurdle
Google’s $10 million bid for data left behind by the defunct Spirit Airlines has received a recommendation from the bankruptcy case’s court-appointed consumer privacy ombudsman, Business Insider reports. Google wants the material for AI development. Spirit shut down in May, but decades of records don’t disappear simply because the planes stopped flying.
The revised deal would exclude passenger databases, use Tonic.ai to de-identify potentially sensitive information, and add protections meant to reduce the risk to roughly 97 million consumers. Those are meaningful changes. They also don’t make the privacy problem vanish. De-identification is a process, not holy water; large collections of email and operational data can contain names, unusual combinations of facts, free-form text, and details that are difficult to sanitize perfectly.
There’s another gap. The ombudsman’s consumer review didn’t cover employees. Unions representing Spirit pilots and flight attendants, along with the Allied Pilots Association, have objected over employee privacy and safety. Earlier filings described concerns about payroll records, tax documents, schedules, travel information, and a collection containing around 100 million emails. Google says the data it receives won’t contain personally identifiable information, but the sale still needs court approval at a hearing scheduled for October 14.
The broader lesson isn’t that useful data can never be sold. It’s that data collected for one relationship can become an asset in an entirely different one. Customers and employees gave information to an airline, not to an AI laboratory. If a business wants data to outlive the original purpose, its retention rules, contracts, bankruptcy planning, and privacy promises need to anticipate that. Otherwise, “we kept it because storage was cheap” eventually becomes “we found somebody who wants to buy it.”
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
Citrix Has Another Exploited NetScaler Fix
Administrators who patched last week’s Citrix NetScaler flaws have another update to check. CVE-2026-88779 is a memory-overflow vulnerability affecting customer-managed NetScaler ADC and Gateway systems configured as a SAML service provider or identity provider. It can be exploited remotely without authentication to crash the affected service or appliance. Citrix rates it 8.7 under CVSS 4.0, and CISA added it to the Known Exploited Vulnerabilities catalog on October 4.
This needs one careful distinction. The new flaw is a denial-of-service vulnerability, not another confirmed remote-code-execution flaw. Beazley Security’s incident-response update says attackers have tried to use the reboot condition alongside the earlier CVE-2026-88771 attack chain, but it has found no evidence that CVE-2026-88779 produces code execution on systems already patched for that earlier flaw.
That doesn’t make it harmless. Repeatedly crashing an authentication gateway is a perfectly respectable way to ruin somebody’s day. It does mean we shouldn’t turn “exploited” into “attackers can own every patched Citrix box” when the evidence doesn’t support that.
Affected organizations should move to NetScaler 14.1-73.41 or 13.1-64.28, with Citrix’s corresponding fixed FIPS and NDcPP builds where applicable. Citrix-managed cloud services have already been updated. If you run the appliance yourself, check for the SAML configuration preconditions and apply the new build even if you finished last week’s emergency patching. The previous job being done doesn’t make this one optional. Our September 28 Brief has the separate RCE details and compromise-checking guidance.
Business IT goes well beyond the website
Your business also depends on workstations, cloud accounts, browsers, Wi-Fi, remote access, collaboration tools, and all the other technology that quietly becomes infrastructure. Raymond Tec works across that whole stack, whether the problem lives on a server, on a desk, or somewhere in between.
AI Is Changing Work. DNB Is Cutting 400 Jobs.
Norway’s largest bank, DNB, says it will eliminate about 400 positions in its Technology & Services unit as it invests more heavily in AI agents and digital services. CEO Kjerstin Braathen said AI is changing both how the bank works and how it serves customers, calling the shift a “new reality,” according to Reuters.
It’s tempting to reduce that to a neat headline: AI replaced 400 workers. DNB’s public explanation doesn’t establish that. A technology reorganization can combine automation, eliminated projects, consolidation, changed skills, and ordinary cost cutting. Invoking AI doesn’t tell us which tasks disappeared, which services will change, or whether customers will get faster help or a more elaborate route to a human being.
Still, this is more concrete than a CEO predicting that AI might someday transform work. Hundreds of people are losing jobs now, and the bank is explicitly tying the organizational change to AI agents and digital investment. That deserves more honesty than either “the robots took the jobs” or “AI merely assists people.” Both can be true in different parts of the same company.
For a smaller business, the useful question isn’t how many people a vendor says an agent can replace. Start with the work: what can be automated reliably, what still needs judgment, who catches the weird case, and what happens when the system is wrong? Measure the result, include the people who understand the process, and decide what you’ll do with the time you save. Buying an AI tool and immediately turning the savings target into a headcount number is not a transformation plan. It’s a spreadsheet with ambitions.
That distinction also belongs in the larger AI infrastructure argument. The industry is spending trillions because it expects software agents to change real work. DNB is one early example of that expectation reaching an organizational chart. Whether it produces better banking, cheaper banking, or merely fewer bankers remains an open question.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Reuters: Accenture contractor removed from FBI following damaging data breach
- Reuters: ShinyHunters expanded attacks on Oracle PeopleSoft
- Business Insider: Google’s Spirit Airlines data bid receives privacy recommendation
- Reuters: U.S. closes airline privacy review without penalties
- Citrix: NetScaler advisory for CVE-2026-88779
- Canadian Centre for Cyber Security: Citrix advisory AV26-996
- Beazley Security: NetScaler exploitation and remediation updates
- Reuters: DNB to cut around 400 jobs amid AI-driven changes
Photo by Christina Morillo on Pexels.
