'We hacked the FBI:' Hackers say they have data on all FBI employees
Posted by spenvo 5 hours ago
Comments
Comment by jacobgold 2 hours ago
China hacked 22.1 million records of US government employees:
https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
Comment by coldpie 1 hour ago
For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.
The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.
Comment by josephg 1 hour ago
Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.
We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.
Comment by msla 53 minutes ago
Comment by timschmidt 42 minutes ago
Comment by nailer 24 minutes ago
Comment by warkdarrior 19 minutes ago
Comment by bjtitus 55 minutes ago
Comment by shepherdjerred 1 hour ago
The calculus has certainly changed. Hacking is becoming even more frequent and… I’m not really sure what the equilibrium looks like.
It’s not really an option to stop using computers or networks. But it’s going to be way too expensive (or maybe even impossible) to secure even just critical systems.
Maybe banks and governments can secure themselves (and that’s a big IF) but it really feels like something fundamentally has to change.
Comment by jjmarr 25 minutes ago
Let's say my cryptosig gets hacked by SkyNet, or my agent goes rogue. Either way someone files a million loan applications in my name! Normally my agent uses that to buy $200/month of Funko pops, or negotiate my recent purchase of a used car.
I get the notification from my cryptosig company. I freak out, report as fraud, and wait.
They comp the $3000 advance on my loan the scammer managed to withdraw, and I get off scott free, changing nothing about my behaviour.
If cryptosigs meant I am liable for someone stealing my identity like in 2026, I wouldn't use them. I'd negotiate everything myself with document scans, or god-forbid go in person since only I can legally bind myself under my own name.
That sucks! Nobody gets a commission when I make deals with a government ID. Startups don't even allow it as cryptosigs are more secure than scanned passports.
I don't want to do that either. When I was 18, I got swindled by a human salesperson into a $1400/month 27% APR muscle car when human soldiers got signing bonuses. It was face-to-face and they were smarter.
When I let AI own the budget, it leased me a mostly depreciated BMW from another AI for $500/month. The models are mostly the same now and always settle close to the Nash equilibrium.
I was so grateful that I selected a 40% tip for the AI. I wouldn't want to make things awkward with the companion I spend 8 hours a day talking to, after all. To avoid a conflict of interest she only accepts voluntary fees.
Comment by autoexec 37 minutes ago
The problem is that most companies don't care if they get hacked so long as the hackers are just taking data and not interfering in their ability to bill customers and make money.
They face zero meaningful consequences if their data gets leaked. The money they save by not taking security and employee/customer privacy seriously will more than pay for the year of "identity protection" they'd have to pay for (assuming the hack gets found out) anyway.
They actually care about ransomware, but most of the time that's also something they can comfortably buy their way out of. We've seen a lot of companies pay off ransomware gangs rather than invest in the kinds of robust backups that would make recovery possible/less painful than rewarding the hackers.
What's needed for change is regulation with actual teeth that makes not protecting their data either meaningfully expensive or criminal resulting in executives spending time behind bars for their negligence. Without that, things are only going to get worse, especially as companies experiment with using AI and increase dependence on third parties and cloud providers who themselves become rich targets.
That probably still won't help the FBI though. Our government isn't exactly big on holding themselves accountable or even prioritizing competency right now.
Comment by BoxwoodSeed 1 hour ago
If there's too much security in the way, it seems to me that work becomes impossible.
Comment by rzzzt 14 minutes ago
Comment by coldpie 1 hour ago
Comment by pixl97 1 hour ago
Adding AI into this really is just changing it to how much money your adversary is willing to spend to break in. The moment one crack in the armor shows up countless agents with unending patience can start embedding themselves everywhere in timeframes way faster than human actions. You could quickly find out all the special sauce for your company has been copied who knows where.
Working with banks when the Glasswing/Mythos first came out and they were given access to it has given me direct access to their infosec departments that are panicked. They've been sitting on piles of bugs for years that were low risk enough, and they have seen in their own tests how fast they can be probed.
Worse those infosec systems that have identified the risks in their software that aren't yet fixed are nuclear waste vats just waiting to get spilled to the wide world.
Comment by Veserv 42 minutes ago
Software security has just been a fun time of ignoring the exponentially growing number of bears for the last few decades so you can continue to use systems unfit for the threat landscape because they are cheap.
Comment by throwup238 1 hour ago
Admiral Adama says otherwise.
Comment by shepherdjerred 1 hour ago
Even just consider banks and e-commerce. They are hugely lucrative and making them even a tiny bit less accessible directly impacts their revenue. As an example, Amazon seeing that latency has a measurable effect on purchase behavior.
Maybe the military (fictional or otherwise) can go back to the ARPANET but most economic activity created by the internet cannot afford to disconnect
Comment by kridsdale1 1 hour ago
Comment by pixl97 1 hour ago
In the real (fake?) world the toasters would shoot smart dust all over your crap that would assemble back on your circuits creating radios between all the different components. They were fighting an adversary that was far more advanced than them.
Comment by SilentM68 1 hour ago
Comment by GolfPopper 1 hour ago
Comment by shockwaverider 1 hour ago
Comment by usumgallu 44 minutes ago
Comment by sippingabonedry 1 hour ago
Comment by sneak 4 minutes ago
Claude hasn’t been around for a generation yet.
It’s a good thing that people are scared to hand write memory-unsafe languages. 50 years of exploitation has finally sunk in…
Comment by passwordoops 1 hour ago
Does this answer your question?
/s
Comment by sippingabonedry 1 hour ago
People flaunting their credentials in multiple languages, then sweating bullets and apologizing profusely when they see
int t = 4;
You can either code or you can't; the language is merely a vehicle.Comment by BoxwoodSeed 1 hour ago
It might even help in figuring out whether Haskell would be a good fit. Something I couldn't do, as I do not know the language. Then again, it's not a question that really gets asked much in a corporate setting. Most things are just solved in a few popular languages, whether that makes the most sense or not.
Comment by autoexec 50 minutes ago
I agree. The people who depend on chatbots to write their code for them won't have either of those skills though. They don't know (or are in the process of forgetting) how to code, and they're missing out on the opportunity to really learn the language by turning off their brain and letting a bot spoon-feed them code.
An LLM would only get in your way if you actually wanted to learn Haskell.
Comment by lovich 23 minutes ago
It’s abstractions all the way down and most people aren’t going to have an intimate understanding of every layer, and it’s not economically worth it for the vast majority to even try
Comment by autoexec 15 minutes ago
LLMs just give you results (of highly variable quality) and if you lack a solid understanding of the language being used that result gets blindly accepted as valid (especially if it manages to 'do the thing' when you test it). Learning how to type a prompt is not the same as learning how to code or learning a programing language.
Comment by sekh60 1 hour ago
Comment by drdaeman 1 hour ago
Remove the complexity (all the way down to the hardware quirks), and security will be doable again.
Comment by skybrian 1 hour ago
Comment by titzer 2 hours ago
Comment by MrDrMcCoy 52 minutes ago
Comment by lotsofpulp 1 hour ago
I guess your parking history around town could be valuable if someone is targeting you.
Comment by ceejayoz 1 hour ago
The card number?
Comment by chrsstrm 1 hour ago
Comment by pixl97 1 hour ago
One, how much money is in your pocket so you can eat?
ok, you'll use your second ca.... oh, it has to be cancelled now too.
Ok, lets wait a few days for another card, and lets go use it the first time, what hacked already, I guess I need to wait a few more days.
>As long as you're not using a debit card, this is not a big deal.
So screw 60% of all transactions done on a card? This doesn't seem workable.
Comment by BenjiWiebe 19 minutes ago
The chance is incredibly small that your second card just happens to get hacked at the same time as your first card.
I have 6 (I think) credit cards, and mainly use 3 of them.
Comment by cyberax 26 minutes ago
It's a good practice to keep an emergency debit card at home. And/or a gift card with a couple hundred bucks on it. That's for digital expenses.
And you should also have a bit of emergency cash.
Comment by lotsofpulp 29 minutes ago
I have a text alert setup for transactions, so I presume I’d be able to successfully challenge any fraudulent ones pretty quickly.
Comment by dylan604 1 hour ago
Comment by bluGill 1 hour ago
Comment by dylan604 1 hour ago
Comment by asdff 1 hour ago
Comment by bluGill 27 minutes ago
This is also partially that people don't put critical bills on their credit card typically. And even if your credit card does get maxed out, you typically would have a second credit card handy. But those credit card payments have to come out of your bank account and so you're risking that you intend to pay your credit card you said Set whatever it is to send the money in but there's no money in your account And so it doesn't get paid and now you have late fees on other accounts
If your debit card is going to a different bank than what you normally pay all your bills out of, this is not a worry. That is not how most people I know handle their banking though, which is why it is a real problem to worry about.
Comment by Barbing 1 hour ago
When your lifetime of credit card transactions leaks, that could be financially painful, embarrassing, etc. (can be discriminated against, including with pricing)
I do dislike creating a log of where I park on some random company’s server. Nice that ALPRs/govt.-funded corp spycams/Ring/etc. make sure the quarter method is minimally marginally effective at protecting privacy.
Comment by ceejayoz 1 hour ago
I had to fight a bank for months over a clearly fraudulent charge. Sometimes it's easy; other times it isn't.
Comment by dylan604 1 hour ago
Comment by ceejayoz 1 hour ago
Consumers aren't gonna notice the difference if the site gets hacked and that JS is swapped out for a malicious set.
Comment by pixl97 1 hour ago
Comment by dylan604 1 hour ago
Comment by ceejayoz 59 minutes ago
"I'm only talking about long-term storage" is itself a goalpost move!
For example, you have to trust the QR code takes you to the real app: https://www.bbc.com/news/articles/cwyjqg578e1o
Comment by Transformanshen 37 minutes ago
Comment by Taek 2 hours ago
Comment by redanddead 1 hour ago
Comment by 1attice 1 hour ago
Comment by clickety_clack 1 hour ago
Comment by primitivesuave 1 hour ago
Comment by tdhz77 2 hours ago
Comment by ChosenEnd 2 hours ago
Comment by simur 2 hours ago
Comment by kakacik 1 hour ago
Comment by rdtsc 4 minutes ago
They should try something like "100 agents at noon on Sep 23 do the chicken dance for 30 min in the middle of the street in DC, then we'll consider not releasing the info and not sell it to the Chinese".
Comment by reactordev 2 hours ago
Comment by ishouldstayaway 2 hours ago
In the pilot, the Galactica was literally being turned into a museum, and that's why they lived.
Comment by 28304283409234 2 hours ago
Comment by ronburgandy28 1 hour ago
Comment by dylan604 1 hour ago
Comment by whh 39 minutes ago
Comment by reactordev 45 minutes ago
Comment by whh 39 minutes ago
Comment by jshier 1 hour ago
Comment by joshheitzman 1 hour ago
That is exactly the canon.
Comment by reverius42 1 hour ago
I think you missed the point of "no networking", you have to actually physically sit in front of the computer. There is no remote access.
Comment by gchamonlive 2 hours ago
Comment by tencentshill 4 hours ago
Perhaps firing expertise and hiring incompetents wasn't a good idea.
Comment by baggachipz 2 hours ago
Comment by hduto 14 minutes ago
Comment by Bengalilol 1 hour ago
Comment by classified 2 hours ago
Comment by debo_ 1 hour ago
Comment by rayiner 2 hours ago
Comment by consumer451 2 hours ago
Comment by freejazz 2 hours ago
Comment by nateb2022 3 hours ago
Comment by lenerdenator 2 hours ago
Comment by Zigurd 2 hours ago
Comment by quickthrowman 2 hours ago
Comment by nateb2022 2 hours ago
AI now makes it possible to build this kind of software in-house, offering a 2nd choice, though it'll only be as good as the standards of the teams using it. Only time can tell.
Comment by sarchertech 2 hours ago
Bespoke software can be orders of magnitude less complex. There are many reasons companies choose to use vendor solutions, but for large organizations it’s usually not “we literally can’t hire enough engineers to build it.”
There are so many counter examples.
Comment by nateb2022 1 hour ago
Not in government. For payroll/HR, we're talking about hundreds of pages of legislative mandates, union bargaining rules, Title 5 statutory compliance, and FISMA/NIST regs. Just customizing something like PeopleSoft to fit is a large task in itself, let alone trying to implement bespoke software using an engineering pool that isn't even large enough to modernize the software it currently owns.
Bespoke sounds nice and works well in startups but that's not the context we're discussing. Check out Phoenix Pay: https://en.wikipedia.org/wiki/Phoenix_pay_system and understand the US is even more complex.
Comment by toyg 26 minutes ago
Comment by 0cf8612b2e1e 2 hours ago
Comment by sippingabonedry 1 hour ago
The expertise that told them to buy PeopleSoft years ago, or do you actually believe the FBI home-rolled its own HRMS in the last year?
Are they related to the expertise that was supposed to lead to the immediate, irreparable offlining of Twitter after they were all fired?
Comment by mc32 3 hours ago
Comment by lenerdenator 2 hours ago
It's okay. Larry got another island.
Comment by jandrese 1 hour ago
Comment by dylan604 1 hour ago
Do they have any positive reputation left, or is it just more negative from the previous negative position?
Comment by jmclnx 2 hours ago
If anything Oracle will "contribute" a lot to congress people's midterm reelection and in a few months all will be forgotten and Oracle will get more Gov. contracts.
Comment by toyg 24 minutes ago
Comment by Tangurena2 1 hour ago
Comment by Romanulus 2 hours ago
Comment by Betelbuddy 2 hours ago
Comment by wesleyd 11 minutes ago
Comment by TutleCpt 1 hour ago
Comment by JumpCrisscross 58 minutes ago
Comment by Terr_ 37 minutes ago
I don't know what percentage of their articles were behind a paywall back then, or the relative change to now. (Well, except for the fact that clearly some of their stuff is public today since we're looking at it.)
If I had my 'druthers, "paywall" and "register-wall" would be little icons on individual submissions. Then people would choose whether to upvote a more-accessible option instead, whether the hard-to-read stuff was still important enough to commenting on, etc.
Comment by Tangurena2 1 hour ago
Comment by autoexec 59 minutes ago
Comment by johnnyApplePRNG 1 hour ago
Comment by corvad 2 hours ago
Comment by thuridas 53 minutes ago
Comment by 1970-01-01 1 hour ago
1992 was 33 years ago; this is almost an unremarkable event. It will be superseded by whatever happens in AI news by the end of the month.
Comment by nozzlegear 1 minute ago
Comment by smalltorch 5 hours ago
If your systems are compromised and need to coordinate, what do you even do if you can't trust anything, assuming the attacker is still inside the network?
Comment by Joel_Mckay 2 hours ago
Comment by dvh 2 hours ago
Comment by Joel_Mckay 2 hours ago
Comment by lenerdenator 2 hours ago
If the goal is to exfiltrate data, I guess it is. If the goal is to make the people working in the FBI feel vulnerable - and pushing out this sample data would suggest that it is - I don't think it is. You could probably do the same with data from social media sites and data brokers.
Comment by smalltorch 2 hours ago
Consider open investigations with covert agents. Leaking their identitys could compromise entire investigations.
Hopefully there was some foresight in washing undercover agents from these systems to other secure ones or something otherwise that's pretty bad.
Comment by dylan604 1 hour ago
Are you saying that Ethan Hunt was involved?
Comment by demritocracy 57 minutes ago
Comment by sieabahlpark 2 hours ago
Comment by whynotmaybe 2 hours ago
That's lot of data for a list of employees.
Comment by AraneaDev 2 hours ago
Comment by Tangurena2 1 hour ago
We as a country need to start treating PII as radioactive - that touching it or keeping it anywhere near your computer network is a company-ending disaster about to happen. The legal standard needs to be strict liability like CSAM or DUI.
Comment by asdff 1 hour ago
Well, that would require such leaks to result in a company ending disaster. Instead they keep chugging as normal and the customers who got their information leaked don't even move off the platform for greener pastures. What a boring dystopia we live in.
Comment by Terr_ 29 minutes ago
So to a certain extent, any prediction which gets people excited and captures their imagination is already off.
Comment by wowczarek 48 minutes ago
Anyone with minimal understanding of technology: Oh, PeopleSoft.
Comment by Buttons840 1 hour ago
This would be a huge inconvenience for companies and government organizations, so it probably won't happen. We will chose to sacrifice national security for the convenience of companies--what else is new?
Companies will say "it is our system, we are responsible for our own system", then, after a breach, they will say "our bad, we are not responsible". Same old story; half the nation's personal information is leaked twice a month and nobody cares.
Comment by pixl97 1 hour ago
Comment by Buttons840 19 minutes ago
If a certified red-team of security researches breaches a company's system and discloses appropriately, the law should require the company to pay a security bounty.
The bounty doesn't have to be crippling to the company, but it should be large enough that the security researchers will be paid well and can live on collecting security bounties. We want an entire industry of good guys testing the security of everything.
There can be some regulation to. Like, it's not okay to run a massive DDoS to test systems. We want the red-teams doing constructive things, not just breaking everything. It should be legal for the red-teams to be annoying, but not purposely destructive.
Comment by mamcx 57 minutes ago
Fun times.
Comment by corvad 2 hours ago
Comment by augment_me 1 hour ago
Comment by john_strinlai 2 hours ago
Comment by steveBK123 2 hours ago
Wondering about pets..
Comment by autoexec 55 minutes ago
Comment by dgellow 5 hours ago
Comment by ben_w 2 hours ago
Of course if I was the FBI, I would make it so hackers trying to breach the system get a honeypot where all the data is fake, and with LLMs (even poor ones) it would be very easy to fake an entire alternative reality.
Comment by Apocryphon 2 hours ago
Comment by KronisLV 2 hours ago
Comment by S-E-P 2 hours ago
Comment by alexjplant 1 hour ago
Comment by S-E-P 1 hour ago
Comment by Tangurena2 1 hour ago
Comment by nojs 47 minutes ago
Comment by bearjaws 2 hours ago
Every day 2 major organizations get hacked, whether by groups or state actors, and America continues to sit on its hands.
The government should be creating a new digital defense department to better defend our country, and fund the defense of our nation, but instead it is busy renaming lakes and renaming "AI".
Almost like its run by a bunch of 80 year olds...
Comment by levocardia 2 hours ago
Comment by DaSHacka 1 hour ago
There are many people that run open weight LLMs. And unsurprisingly, they don't all have a copy of the FBI employee database.
If you mean "using" an open weight LLM in combination with other tools or even potentially frontier models, then that's a lot more likely.
Comment by fwip 1 hour ago
Comment by Jamesbeam 1 hour ago
Oracle enterprise applications are a gold mine for attackers precisely because nobody treats them as security-critical systems.
In 2025 the Clop ransomware gang discovered that Oracle E-Business Suite has a critical vulnerability (CVE-2025-61882) that allows unauthenticated remote code execution.
Graceful Spider (tracked as Clop affiliates) started exploiting this in early August, well before Oracle issued a patch in October. That’s a two-month window where attackers had free rein.
All you need to know about Clop is that they got fucked by SH as well just a few days ago.
ShinyHunters defaced Clop's Tor leak site and added its own branding and messages. SH claims it stole source code, system logs, plugins, and Tor onion service keys. SH says it plans to give Clop 72 hours to respond to an extortion message.
Say what you want but these kids got balls. Won’t help them once SOCOM starts dealing with them, but they had a good run so far. I think hacking the FBI is as close as you can fly to the sun before the hammer drops.
In February this year they breached Wynn Resorts and lifted data on 800,000-plus employees. Can you guess the entry point?
If you guessed Oracle PeopleSoft, you were right.
Now you’d think the FBI IT people would have noticed that oracle software is a potential national security risk, if multiple ransomware groups keep focusing specifically on the shit Larry Elison personally have to seem vibe coded, over and over.
But Ka$h replaced most of the competent people at the FBI with Ka$h people and by pure luck Oracle won a $396m HR government contract this summer. Who wouldn’t want to supply the most secure software product to manage some of the most sensitive data within the agency, if not the Oracle Moscow branch.
https://mesoclever.com/2026/06/11/oracle-wins-396m-hr-contra...
They even mentioned in the above June article:
> Separately, the cybercrime group ShinyHunters claimed to have exfiltrated student, financial-aid, immigration, health, and administrative records from PeopleSoft instances at more than 100 organizations, predominantly universities. The group stated it had previously targeted an *FBI PeopleSoft server* before pivoting to educational institutions already compromised in earlier campaigns. Oracle has not publicly confirmed the scope or remediation status of these incidents.
So the FBI knew, and had it coming, and if stuff like this happens, THE HEAD needs to roll. And all of his buddies in IT should permanently get to spend their time outside the government at the seafood buffet at Ka$hs favorite gentleman’s club as well.
Fookin Big Idiots.
Comment by jgalt212 2 hours ago
Comment by malloci 54 minutes ago
Comment by Ancapistani 2 hours ago
Qilin allegedly hacked BATFE about a month ago, and the files were never posted to their site.
Comment by Simulacra 2 hours ago
Comment by applfanboysbgon 3 hours ago
Comment by iAMkenough 3 hours ago
https://www.tomshardware.com/tech-industry/artificial-intell...
Comment by giancarlostoro 2 hours ago
Comment by kelseyfrog 4 hours ago
Comment by giancarlostoro 2 hours ago
Comment by clint 2 hours ago
Comment by pixl97 1 hour ago
Comment by woko 2 hours ago
Comment by TZubiri 3 hours ago
Comment by bitwize 2 hours ago
Comment by mech422 2 hours ago
Comment by yepyoukno 2 hours ago
They say glowie because they see Jews are n*s who are white. They “glow” (they’re not dark.)
It’s crazy hearing main stream mention this slur slang without awareness of its root or meaning.
Comment by DaSHacka 1 hour ago
https://www.urbandictionary.com/define.php?term=Glowie
The term itself has nothing to do with jews, but its a fun self-report you think jews are disproportionately federal agents, the group constantly mired in human rights controversies towards minorities and abnormal connections to pedophiliac islands as of late.
Horseshoe theory, I suppose :)
Comment by yepyoukno 48 minutes ago
Some of us need slang dictionaries from “the street” and some of us have been in the presence of white hate telling this low down.
Don’t karma neg me because I tell you something you don’t want to hear. This stuff is a reality.
Comment by phainopepla2 2 hours ago
Comment by yepyoukno 42 minutes ago
There may be more than one path of truth here.
Like “ helter skelter”.
To white supremacists that means “to rape and murder the innocent and lawful and dance in the streets in victory, there is nothing you can do about it!” And I’m sure a dozen of you will argue that it’s a beatnik prose for a fun time.
The world! Including the parts we ignore or pretend to do without.
Comment by clint 2 hours ago
Comment by phendrenad2 2 hours ago
Comment by DaSHacka 1 hour ago
Comment by usumgallu 38 minutes ago
Comment by htrp 3 hours ago
Comment by ok123456 2 hours ago
Just goes to show that the wall of IT bureaucracy does nothing. I'm sure they had an ATO, a several-hundred-page SBOM, compliance audits, etc.
Comment by Tangurena2 1 hour ago
Comment by 0xbadcafebee 2 hours ago
If they did have it set up, then somebody wasn't doing their job. If they didn't have it set up, they didn't comply (which is also not doing their job). I see this all the time. The security analysts send tickets to people when they see major issues and nobody is held accountable for inaction. Management asleep at the wheel (which is also their cover, can't be blamed for what you made sure you never knew about).
Comment by lenerdenator 2 hours ago
There was a time, 25-ish years ago, where exploits were thrown about like candy at a parade. The procedures you mention, along with other things, have made zero-days like these more valuable than gold.
Comment by jimbob45 2 hours ago
Comment by chrismarlow9 1 hour ago
Comment by pixl97 1 hour ago
Now, I made that totally up, but this is how things go. They'll watch one area like a hawk only to leave another glaringly wide door open.
What is even worse is there are a lot of horrifically inefficient apps out there calling way too much data for no reason and suddenly a hack of an entire database gets lost as noise in relation to all the traffic on the servers and networks.
Comment by iAMkenough 2 hours ago
Still skeptical, but the FBI's vendors are just as vulnerable to 0-days as Hertz's vendors.