Security

June's breaches came in through doors you already own

A PeopleSoft zero-day, a ServiceNow exposure, a pharma extortion. None of it was exotic — and that is the uncomfortable part.

The most instructive thing about June's breach wave is how unremarkable the entry points were. Attackers did not out-innovate anyone. They walked in through the enterprise platforms you already run and a flaw you had not yet patched.

Look at the month

On June 11, attackers exploited a zero-day in Oracle PeopleSoft; Oracle later warned that more than 100 organizations had been compromised through it, Nissan among the named victims. Two days earlier, ServiceNow confirmed customer data had been exposed inside affected environments — the kind of instance that quietly stores employee records, support tickets, and asset inventories. Novo Nordisk had non-public clinical-trial patient data copied out, with Hunters International demanding $25 million. Different sectors, same shape: trusted platform, known category of weakness, sensitive data on the other side of it.

The unglamorous through-line

None of this rewards the security budget line most boards find exciting. There is no novel AI-powered threat to point at, no reason to buy another detection layer. The through-line is patch latency and third-party exposure — the two least photogenic problems in the discipline. The PeopleSoft victims were not undone by a lack of tooling. They were undone by the window between a patch existing and a patch applied, multiplied across a platform they did not fully control.

The lesson is not that these companies were careless. It is that the attack surface has quietly migrated into the SaaS and ERP platforms every enterprise depends on, where your patch cadence is partly someone else's and your visibility is thinner than you would like. That is precisely where the fundamentals — asset inventory, identity hygiene, third-party risk, time-to-patch — stop being hygiene and start being the whole defense.

Buy the boring things first. The breach that takes you down this year will almost certainly arrive through a platform you already trusted and a fix you already had.

What this reacts to

The daily brief

CIOReview, in your inbox before standup

The headlines technology leaders are reading, synthesized and source-linked. One email each morning. No filler.