Just goes to show that the wall of IT bureaucracy does nothing. I'm sure they had an ATO, a several-hundred-page SBOM, compliance audits, etc.
There was a time, 25-ish years ago, where exploits were thrown about like candy at a parade. The procedures you mention, along with other things, have made zero-days like these more valuable than gold.
Yeah, it's called regulatory capture.
Treating security as an accounting exercise has never stopped a 0-day. Better software tools and practices have.
If they did have it set up, then somebody wasn't doing their job. If they didn't have it set up, they didn't comply (which is also not doing their job). I see this all the time. The security analysts send tickets to people when they see major issues and nobody is held accountable for inaction. Management asleep at the wheel (which is also their cover, can't be blamed for what you made sure you never knew about).
They trusted Oracle. I'm not sure I believe you.
Still skeptical, but the FBI's vendors are just as vulnerable to 0-days as Hertz's vendors.
Now, I made that totally up, but this is how things go. They'll watch one area like a hawk only to leave another glaringly wide door open.
What is even worse is there are a lot of horrifically inefficient apps out there calling way too much data for no reason and suddenly a hack of an entire database gets lost as noise in relation to all the traffic on the servers and networks.