@christopherkunz I still run firmware fingerprint scanning across the internet and regularly find US federal agencies that are over a year behind with updated on CISA KEV
Conversation
Notices
-
Embed this notice
Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 06-Oct-2026 20:53:19 JST
Kevin Beaumont
-
Embed this notice
Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Tuesday, 06-Oct-2026 20:53:20 JST
Dr. Christopher Kunz
Accenture, acting as a contractor for the FBI, allegedly failed to install updates for Oracle Peoplesoft after CVE-2026-35273 was published.
This was a "Missing Authentication for Critical Function" vulnerability and scored 9.8. If this didn't raise any flags, the CISA KEV listing should have. It was an n-day at release.
But no, interestingly enough the FBI is exempt from BOD 26-04 and wasn't even obliged to update?!
Man, if not even federal agencies fix their vulns, this is all pointless.
-
Embed this notice