US, UK Agencies Detail Iranian Malware Campaign Targeting Dissidents
A new joint advisory from multiple law enforcement agencies this week warned of an Iranian cyber campaign targeting dissidents and journalists in the U.S., UK, and elsewhere.
Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can't be legally bound to a contract you agreed to while drunk. What they discovered will make you look at your TV rather differently... Meanwhile, awful Android malware with the audacious name "Awesome" (in Indonesian) is doing the rounds, stealing your data, demanding a ransom, and then giving you a "jump scare"... Plus, in our featured interview, Andy Hornegold of Intruder explains why the mid-market is where cybercriminals are having the most fun right now - and how AI is helping attackers get from "first foot in the door" to "full ransomware disaster" in less than a working day. All this and more in episode 485 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Lianne Potter.
Identity at machine speed: Okta pushes governance beyond human users
Okta is adding new features to its identity platform to better govern AI agents.
Dark Reading General
AI Security Spending Jumps as Fear Outpaces Proof of Value
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
AWS Security Blog VulnArchitecting a secure landing zone in the AWS European Sovereign Cloud
The AWS European Sovereign Cloud is a new, independent cloud for Europe, physically and logically separate from existing AWS Regions and operated within the European Union (EU). It provides the same services, features, and APIs as AWS commercial Regions, but runs as a distinct AWS partition (aws-eusc), with its own control plane, AWS Identity and […]
Ars Technica GeneralNonprofit that tracks meteors taken down by "critical blow" from a cyberattack
Group plans to be largely out of commission for several weeks.
The Record Policy
Key lawmaker suggests action on AI safety legislation will wait until 2027
“It's really complicated, and I wouldn't want to do something in a lame duck session to do it quickly and not get it right,” said House Energy and Commerce Chairman Brett Guthrie about the FRONTIER Act.
CyberScoop GeneralCISA promotes a fresh way to deter cyberattackers: Lie to them
It’s the first guidance from the Cybersecurity and Infrastructure Security Agency on deploying decoys, like honeypots, to detect and distract adversaries. The post CISA promotes a fresh way to deter cyberattackers: Lie to them appeared first on CyberScoop.
Security Affairs MalwareBambooToken: The Malware That Speaks MQTT to Stay Under the Radar
Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines. Most malware connects directly to a command-and-control […]
Zero Day Initiative BreachThe Apple Security Update Review for September 2026
Welcome back to our monthly look at Apple security patches. This release shows Apple is not immune to the new normal of AI-assisted vulnerability discovery as they release patches for 273 total CVEs.For the September 2026 release, Apple released 273 unique CVEs across macOS 27 (Golden Gate), macOS Sequoia 15.8, macOS Tahoe 26.7, iOS / iPadOS 27, visionOS 27, watchOS 27, tvOS 27, iOS / iPadOS 26.7, Safari 27, and Xcode 27. This patch release actually happened a couple of days ago, but since Apple doesn’t provide CVSS scores or other severity information, it takes a couple of days to understand the full severity. Even with the additional time, there are many CVEs without a severity score. However, looking at the one that do have severity assigned by NVD or CISA-ADP, there are a few that truly stand out, including one under active exploit.CVE-2026-65400 — Screen Sharing Server (9.8 CRITICAL, ⚠ CISA KEV). This bug is confirmed by CISA to be actively exploited. A network attacker can authenticate to Screen Sharing without valid credentials, without user interaction. This component was first patched on August 6 and relisted in v27 as macOS 27/Tahoe 26.7 now carries the fix.CVE-2026-65414 — Bluetooth (9.8 CRITICAL). This is the highest-scored non-exploited bug in the release. It’s remote, network-vector arbitrary code execution with no privileges or interaction, and CISA tagged it "automatable: yes, technical impact: total." It spans all eight OS platforms, which is the broadest-reach critical vulnerability in the release and the most likely candidate to become a KEV entry.CVE-2026-65346 — ImageIO (8.8 HIGH). The bug sits at the top of the HIGH tier and is the most dangerous remote content bug: processing a malicious image leads to arbitrary code execution. ImageIO is the canonical zero-/one-click surface (images auto-rendered in Messages, previews), so it carries high real-world weaponization potential.Two honorable mentions that matter because of a data caveat: CVE-2026-84607 (AVEVideoEncoder) — a sandbox-to-kernel arbitrary-code-execution bug — and CVE-2026-43790 (Kernel) — remote kernel memory corruption — are arguably more severe by impact than #3, but NVD hasn't scored either yet (both TBD), so they don't rank on the current evidence. Also worth noting: CVE-2026-43692 (CUPS) remote code execution and CVE-2026-84568 (autofs) root RCE both sit at the top of the HIGH band.Here’s the full table of Apple patches and the products they affect: Apple Security Updates — September 14, 2026 (v27) 273Total CVEs 134Scored 139TBD 2CRITICAL 46HIGH 84MEDIUM 2LOW CVSS is the NVD primary score where available, otherwise CISA-ADP secondary; TBD = NVD has not scored it yet (most v27 CVEs are still under analysis). ⚠ KEV marks CVEs in CISA's Known Exploited Vulnerabilities catalog. Apple security release — September 14, 2026 (version 27), 273 CVEs. CVSS/Severity from NVD (National Vulnerability Database) as of Sept 16, 2026. CVE IDs link to NVD. "Yes/No" indicates whether each update is affected. CVE IDComponentImpactCVSSSeverity iOS / iPadOS 27 iOS / iPadOS 26.7 macOS 27 (Golden Gate) macOS Tahoe 26.7 macOS Sequoia 15.8 tvOS 27 watchOS 27 visionOS 27 Safari 27 Xcode 27 CVE-2026-65400 Screen Sharing Server An attacker on the network may be able to authenticate to Screen Sharing without valid credentials 9.8⚠ KEV CRITICAL NoNoYesYesNoNoNoNoNoNo CVE-2026-65414 Bluetooth A remote attacker may be able to cause unexpected app termination or arbitrary code execution 9.8CRITICAL YesYesYesYesYesYesYesYesNoNo CVE-2026-43692 CUPS A remote user may cause an unexpected app termination or arbitrary code execution 8.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-65346 ImageIO Processing an image may lead to arbitrary code execution 8.8HIGH NoNoNoNoYesYesYesYesNoNo CVE-2026-43686 Kernel Connecting to a malicious NFS server may lead to kernel memory corruption 8.8HIGH YesYesYesYesYesYesYesYesNoNo CVE-2026-65374 WebDAV Connecting to a malicious WebDAV server may result in code execution 8.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-43715 WebKit Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoYesNoNoNoNoNoNoNoNo CVE-2026-43794 WebKit Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoNoNoNoNoYesYesYesNoNo CVE-2026-65390 WebRTC Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoNoNoNoNoYesYesYesNoNo CVE-2026-65391 WebRTC Processing maliciously crafted web content may lead to memory corruption 8.8HIGH NoNoNoNoNoYesYesYesNoNo CVE-2026-43760 Screen Sharing Server An app may be able to access user-sensitive data 8.6HIGH NoNoNoYesNoNoNoNoNoNo CVE-2026-84581 HFS Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory 8.4HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84535 Automator An app may be able to break out of its sandbox 8.2HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84516 CUPS Processing a maliciously crafted file may result in unexpected app termination or disclosure of process memory 8.1HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-65415 Kernel A local user may be able to cause unexpected system termination or read kernel memory 8.1HIGH YesNoYesNoNoYesYesYesNoNo CVE-2026-84568 autofs An attacker with control of a network directory server may be able to execute arbitrary code with root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84607 AVEVideoEncoder A sandboxed app may be able to execute arbitrary code with kernel privileges 7.8HIGH YesYesYesYesYesYesYesYesNoNo CVE-2026-84631 Bluetooth An app may be able to gain root privileges 7.8HIGH NoNoYesNoNoNoNoNoNoNo CVE-2026-43786 CoreServices An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84575 CoreUI Processing a maliciously crafted file may lead to unexpected app termination 7.8HIGH YesNoYesYesYesYesYesYesNoNo CVE-2026-43691 CUPS An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-43698 CUPS An app may be able to gain root privileges 7.8HIGH NoNoYesYesNoNoNoNoNoNo CVE-2026-84505 Directory Utility An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-65362 Disk Images An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-64758 ImageIO Processing a maliciously crafted file may lead to unexpected app termination 7.8HIGH NoYesNoNoYesNoNoNoNoNo CVE-2026-43684 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory 7.8HIGH NoYesYesNoYesNoNoNoNoNo CVE-2026-43689 Kernel A malicious app may be able to gain root privileges 7.8HIGH YesYesYesNoNoNoNoYesNoNo CVE-2026-86917 Kernel An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-64712 odproxyd An app may be able to gain root privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84515 SMB Connecting to a malicious SMB server may lead to kernel memory corruption 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84506 udf An app may be able to execute arbitrary code with kernel privileges 7.8HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-64761 Accessibility An app may be able to identify what other apps a user has installed 7.5HIGH YesNoNoNoNoNoNoNoNoNo CVE-2026-86895 CloudKit A local app may be able to read a persistent account identifier 7.5HIGH YesNoNoNoNoYesYesYesNoNo CVE-2026-84563 CUPS An app may be able to cause unexpected system termination 7.5HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84606 iCloud An app may be able to identify a user across reinstalls 7.5HIGH YesNoYesNoNoNoNoYesNoNo CVE-2026-43661 ImageIO Processing a maliciously crafted image may corrupt process memory 7.5HIGH NoYesNoNoNoNoNoNoNoNo CVE-2026-28969 IOKit An app may be able to cause unexpected system termination 7.5HIGH YesNoYesYesYesYesYesYesNoNo CVE-2026-65343 Kernel A remote attacker may be able to cause unexpected system termination 7.5HIGH NoNoNoNoNoYesYesYesNoNo CVE-2026-65364 Kernel A remote attacker may be able to cause unexpected system termination 7.5HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-86894 libxpc An app may be able to break out of its sandbox 7.5HIGH NoNoYesNoNoNoNoNoNoNo CVE-2026-84543 SMB Connecting to a malicious SMB server may cause unexpected system termination or corrupt kernel memory 7.5HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-84553 smbx A remote attacker may be able to cause a denial-of-service 7.5HIGH NoNoYesYesYesNoNoNoNoNo CVE-2026-28930 Spotlight An app may be able to access protected user data 7.5HIGH NoNoNoNoYesNoNoNoNoNo CVE-2026-86904 Watch App An app may be able to track users across apps and websites without permission 7.5HIGH YesYesNoNoNoNoYesNoNoNo CVE-2026-64752 CoreMedia Processing a maliciously crafted image may lead to arbitrary code execution 7.3HIGH YesNoYesNoNoNoNoYesNoNo CVE-2026-84611 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption 7.3HIGH YesYesYesYesYesYesYesYesNoNo CVE-2026-84632 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption 7.3HIGH YesYesYesYesYesYesYesYesNoNo CVE-2026-64736 IOMobileFrameBuffer An app may be able to cause unexpected system termination or corrupt kernel memory 7.1HIGH NoNoNoNoYesYesYesYesNoNo CVE-2026-65349 Kernel An app may be able to cause unexpected system termination or read kernel memory 6.6MEDIUM NoNoNoNoYesYesYesYesNoNo CVE-2026-84537 SMB An app may be able to cause unexpected system termination or corrupt kernel memory 6.6MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-43788 Spotlight Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents 6.6MEDIUM NoNoYesNoNoNoNoNoNoNo CVE-2026-86882 Accelerate Framework Processing a maliciously crafted image may lead to unexpected process termination 6.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84519 AppleDouble Mounting a disk image with maliciously crafted files may lead to unexpected system termination 6.5MEDIUM YesYesYesYesYesNoNoNoNoNo CVE-2026-86879 Baseband A remote attacker may be able to cause a denial-of-service 6.5MEDIUM YesNoNoNoNoNoNoNoNoNo CVE-2026-86885 Baseband An attacker in radio range may be able to cause unexpected system termination 6.5MEDIUM YesNoNoNoNoNoNoNoNoNo CVE-2026-65412 CoreText Processing web content may lead to a denial-of-service 6.5MEDIUM YesYesYesYesYesNoYesYesNoNo CVE-2026-84596 CoreText Processing a maliciously crafted font may result in the disclosure of process memory 6.5MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2026-84597 FontParser Processing a maliciously crafted font may result in the disclosure of process memory 6.5MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2022-3437 Heimdal A user in a privileged network position may be able to leak sensitive user information 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-28934 HFS Mounting a malicious disk image may cause unexpected system termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-65347 ImageIO Processing an image may lead to a denial-of-service 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-65395 ImageIO Processing a maliciously crafted image may result in memory corruption 6.5MEDIUM YesYesYesYesYesYesNoYesNoNo CVE-2026-43687 Kernel Connecting to a malicious NFS server may disclose kernel memory 6.5MEDIUM YesYesYesYesNoYesYesYesNoNo CVE-2026-65330 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory 6.5MEDIUM NoNoNoNoYesYesYesYesNoNo CVE-2026-84538 Kernel A remote attacker may be able to cause a denial-of-service 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84588 Kernel Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory 6.5MEDIUM NoNoYesNoNoNoNoNoNoNo CVE-2026-84487 SceneKit Processing a maliciously crafted file may result in disclosure of process memory 6.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-43719 SMB Mounting a maliciously crafted SMB network share may lead to system termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-65365 SMB Connecting to a malicious SMB share may disclose kernel memory 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84536 SMB Connecting to a malicious SMB server may lead to unexpected system termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-43677 WebDAV Connecting to a malicious WebDAV server may lead to unexpected app termination 6.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-64715 WebKit Processing maliciously crafted web content may lead to an unexpected process crash 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-64753 WebKit Processing maliciously crafted web content may disclose sensitive user information 6.5MEDIUM YesNoYesNoNoYesYesYesYesNo CVE-2026-64787 WebKit Processing maliciously crafted web content may lead to an unexpected process termination 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-64778 WebKit History Visiting a maliciously crafted website may leak sensitive data 6.5MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-84560 Bluetooth An app may gain unauthorized access to Bluetooth 6.1MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2026-84619 Kernel An app may be able to cause unexpected system termination or write kernel memory 6.1MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84554 CUPS An attacker in a privileged network position may be able to cause a denial-of-service 5.9MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-43664 Accessibility An app may be able to access sensitive user data 5.5MEDIUM YesYesYesYesYesYesYesNoNoNo CVE-2026-65404 Accounts A malicious application may be able to bypass Privacy preferences 5.5MEDIUM YesNoYesNoNoNoNoNoNoNo CVE-2026-84523 APFS An app may be able to cause unexpected system termination or write kernel memory 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84586 Apple Account A malicious application may be able to leak sensitive user information 5.5MEDIUM NoNoYesNoNoNoYesNoNoNo CVE-2026-65407 AppleAVD An app may be able to cause unexpected system termination 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84593 AppleKeyStore An app may be able to cause unexpected system termination 5.5MEDIUM YesNoNoNoNoNoNoNoNoNo CVE-2026-43763 ATS An app may be able to read files outside of its sandbox 5.5MEDIUM NoNoNoYesYesNoNoNoNoNo CVE-2026-86905 Authentication Services An app may be able to delete credentials stored in Keychain 5.5MEDIUM YesNoYesNoNoNoNoYesNoNo CVE-2026-43737 CoreMotion An app may be able to access motion data from headphones without user consent 5.5MEDIUM YesYesYesYesYesYesYesNoNoNo CVE-2026-43738 CoreUI Processing a maliciously crafted asset catalog may result in disclosure of process memory 5.5MEDIUM YesNoYesNoNoNoNoNoNoNo CVE-2026-84489 CoreUI An app may be able to cause a denial of service 5.5MEDIUM YesNoYesNoNoNoNoNoNoNo CVE-2026-84534 file_cmds Extracting a maliciously crafted archive may allow an attacker to write arbitrary files 5.5MEDIUM YesYesYesYesYesNoNoYesNoNo CVE-2026-65409 Foundation An app may be able to cause a denial of service 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-64756 Image Capture An app may be able to access user-sensitive data 5.5MEDIUM YesNoYesYesYesNoNoNoNoNo CVE-2026-64760 IOSurfaceAccelerator An app may be able to leak sensitive kernel state 5.5MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2026-65401 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM NoNoYesYesNoNoNoNoNoNo CVE-2026-65402 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-65405 Kernel An app may be able to determine kernel memory layout 5.5MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84517 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84521 Kernel An app may be able to cause unexpected system termination 5.5MEDIUM YesYesYesYesYesNoNoYesNoNo CVE-2026-86903 Kernel An app may be able to disclose kernel memory 5.5MEDIUM YesNoYesNoNoYesYesYesNoNo CVE-2026-86883 Managed Configuration An app may be able to access sensitive user data 5.5MEDIUM YesNoNoNoNoNoNoYesNoNo CVE-2026-43741 Messages An app may be able to access protected user data 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84491 Photos Storage An app may be able to access sensitive user data 5.5MEDIUM YesYesYesNoNoYesYesYesNoNo CVE-2026-84576 QuartzCore An app may be able to access sensitive user data 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84555 Sandbox An app may be able to access sensitive user data 5.5MEDIUM NoNoYesNoYesNoNoNoNoNo CVE-2026-65413 SceneKit An app may be able to cause a denial of service 5.5MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-28937 Terminal An app may be able to access sensitive user data 5.5MEDIUM NoNoYesNoNoNoNoNoNoNo CVE-2026-64718 WebKit Canvas Processing maliciously crafted web content may lead to an unexpected Safari crash 5.5MEDIUM YesYesYesNoNoNoNoYesYesNo CVE-2026-65393 Xcode IDE An app may be able to access user-sensitive data 5.5MEDIUM NoNoYesNoNoNoNoNoNoYes CVE-2026-84617 XPC An app may be able to access sensitive user data 5.5MEDIUM YesYesYesYesYesYesNoNoNoNo CVE-2026-64788 IOGPUFamily Processing maliciously crafted web content may lead to memory corruption 5.4MEDIUM NoNoNoNoNoNoYesYesNoNo CVE-2026-65341 WebKit Processing maliciously crafted web content may lead to memory corruption 5.4MEDIUM NoNoNoNoNoYesYesYesNoNo CVE-2026-34979 CUPS An attacker in a privileged network position may be able to cause a denial-of-service 5.3MEDIUM NoNoYesNoNoNoNoNoNoNo CVE-2026-86876 CoreMedia A sandboxed process may be able to circumvent sandbox restrictions 5.2MEDIUM YesYesYesYesYesNoYesYesNoNo CVE-2026-86889 Security An attacker in a privileged network position may be able to intercept network traffic 4.8MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84492 Graphics An app may be able to cause unexpected system termination 4.7MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-84630 Kernel An app may be able to cause unexpected system termination 4.7MEDIUM YesYesYesYesYesYesYesYesNoNo CVE-2026-43690 SMB A local user may be able to read kernel memory 4.7MEDIUM NoNoYesYesYesNoNoNoNoNo CVE-2026-84518 Safari A malicious website may be able to determine what apps a user has installed 4.3MEDIUM YesNoYesNoNoNoNoNoYesNo CVE-2026-43795 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-64780 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-64781 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-64784 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65331 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65332 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65333 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65334 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65335 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65336 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65337 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65338 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65340 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-65351 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 4.3MEDIUM NoNoNoNoNoNoNoYesNoNo CVE-2026-64782 WebKit Processing maliciously crafted web content may lead to an unexpected Safari crash 3.1LOW NoNoNoNoNoNoNoYesNoNo CVE-2026-64779 WebKit Storage Processing maliciously crafted web content may lead to an unexpected Safari crash 3.1LOW NoNoNoNoNoNoNoYesNoNo CVE-2026-86910 APFS An application may be able to access restricted files TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-86888 App Store A local app may be able to read a persistent account identifier TBDTBD YesNoYesYesNoYesYesYesNoNo CVE-2026-84587 AppKit An app may be able to access protected user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-20683 Apple Account An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account TBDTBD YesNoYesYesYesNoNoYesNoNo CVE-2026-84601 Apple Intelligence An app may be able to bypass Apple Intelligence security prompts TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-65408 Apple Neural Engine An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-84520 AppleFDEKeyStore A local attacker may be able to cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-65381 AppleMobileFileIntegrity A malicious app may be able to break out of its sandbox TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84522 Archive Utility An app may be able to access sensitive user data TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84584 Archive Utility An app may be able to break out of its sandbox TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-65342 ATS An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84525 ATS An app may be able to access user-sensitive data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65339 Audio An app may be able to leak sensitive user information TBDTBD NoNoNoNoYesYesYesYesNoNo CVE-2026-84583 AuthKit A local app may be able to read a persistent account identifier TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84570 autofs An app may be able to bypass Gatekeeper checks TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65410 AVEVideoEncoder An app may be able to cause unexpected system termination TBDTBD YesYesYesYesNoYesYesYesNoNo CVE-2026-84616 AVEVideoEncoder An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-65406 BackgroundAssets An app may be able to access sensitive user data TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-86878 Camera An app may be able to access sensitive user data TBDTBD YesNoNoNoNoNoNoNoNoNo CVE-2026-84567 cd9660 An app may be able to cause unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-86893 CloudKit An app may be able to read device name TBDTBD YesNoNoNoNoYesYesYesNoNo CVE-2026-65399 copyfile An archive may be able to bypass Gatekeeper TBDTBD YesYesYesYesYesNoYesYesNoNo CVE-2026-86891 Core Bluetooth An app may be able to access Bluetooth device information TBDTBD NoNoYesYesYesNoYesNoNoNo CVE-2026-43683 CoreDrag An app may be able to cause unexpected process termination or disclose process memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-43789 CoreMedia An app may be able to access user-sensitive data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65344 CoreMedia Processing a maliciously crafted video file may lead to unexpected app termination TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-43702 CoreMedia Video Toolbox Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory TBDTBD NoYesNoYesYesNoNoNoNoNo CVE-2026-84624 CoreML A sandboxed app may be able to access restricted files TBDTBD YesYesYesYesYesNoNoYesNoNo CVE-2026-84559 CoreServices A malicious application may be able to access restricted files TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84574 CoreServices An app may be able to bypass Privacy preferences TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84511 CoreUI Processing a maliciously crafted asset catalog may lead to unexpected process termination TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-84571 CoreUI Processing a maliciously crafted image may lead to unexpected app termination TBDTBD YesNoYesNoNoYesYesYesNoNo CVE-2026-64790 CUPS An app may be able to gain elevated privileges TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84540 CUPS An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84541 CUPS An application may be able to access restricted files TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84612 DeviceCheck An app may be able to read persistent device identifiers TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84512 Disk Images Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84550 Disk Images An app may be able to cause unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84552 Disk Images An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-84565 Disk Images Processing a maliciously crafted disk image may lead to unexpected app termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84510 exFAT Mounting a maliciously crafted volume may lead to unexpected system termination TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-86900 exFAT Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-86901 exFAT Mounting a maliciously crafted exFAT volume may cause unexpected system termination or kernel memory disclosure TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-43785 File Bookmark An app may be able to modify a file it only had permission to read TBDTBD YesNoYesYesYesYesNoYesNoNo CVE-2026-43688 Filters Processing a maliciously crafted file may lead to unexpected app termination TBDTBD YesNoYesNoNoNoNoNoNoNo CVE-2026-84524 FontParser Processing a maliciously crafted font file may lead to unexpected app termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84569 Foundation An app may be able to access sensitive user data TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-86911 Foundation A malicious app may be able to bypass clickjacking protections for secure prompts TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84618 Game Center An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84533 Heimdal An attacker in a privileged network position may be able to modify network traffic TBDTBD YesNoYesNoNoYesYesNoNoNo CVE-2026-64714 ImageIO Processing a maliciously crafted image may lead to a denial-of-service TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84564 ImageIO Processing a maliciously crafted image may result in disclosure of process memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-86869 ImageIO Processing a maliciously crafted image may lead to unexpected app termination TBDTBD NoYesYesNoNoNoNoNoNoNo CVE-2026-43743 IOGPUFamily An app may be able to cause unexpected system termination TBDTBD NoYesNoYesNoNoNoNoNoNo CVE-2026-65398 IOMobileFrameBuffer An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesNoYesNoNoYesYesYesNoNo CVE-2026-65354 iWork A malicious app may be able to break out of its sandbox TBDTBD YesNoYesNoNoNoNoNoNoNo CVE-2026-28935 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD NoNoNoNoYesYesYesYesNoNo CVE-2026-28968 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-43790 Kernel A remote attacker may be able to cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65358 Kernel An app may be able to cause unexpected system termination TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-65359 Kernel A local user may be able to cause unexpected system termination or read kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-65360 Kernel An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-65369 Kernel A malicious application may bypass Gatekeeper checks TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65371 Kernel An app may be able to disclose kernel memory TBDTBD NoNoNoNoYesNoNoNoNoNo CVE-2026-65377 Kernel An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84507 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84530 Kernel An app may be able to disclose kernel memory TBDTBD YesYesYesYesNoYesYesYesNoNo CVE-2026-84544 Kernel Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84549 Kernel Connecting to a malicious NFS server may cause unexpected system termination or corrupt kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84558 Kernel An app may be able to cause unexpected system termination TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84561 Kernel An app may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84566 Kernel A local attacker may be able to cause unexpected system termination or corrupt kernel memory TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-84602 Kernel An app may be able to cause unexpected system termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84622 Kernel An app with root privileges may be able to read uninitialized kernel memory TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84514 Kext Management An app may be able to modify protected parts of the file system TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84556 Keychain Access An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65382 LaunchServices An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-86870 libarchive Processing a maliciously crafted file may lead to unexpected app termination TBDTBD YesYesYesNoNoNoYesYesNoNo CVE-2026-84577 libxpc An app may be able to bypass sandbox restrictions TBDTBD NoNoYesYesNoNoNoNoNoNo CVE-2026-43787 Mail An attacker in a privileged network position may be able to leak sensitive user information TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84573 Mail An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84628 MediaRemote A sandboxed app may be able to access the System Keychain TBDTBD YesNoYesNoNoYesYesYesNoNo CVE-2026-86924 MobileAccessoryUpdater Connecting a malicious accessory may cause unexpected system termination TBDTBD YesYesYesYesNoNoNoNoNoNo CVE-2026-65411 MobileBackup An app may be able to modify protected parts of the file system TBDTBD YesYesNoNoNoNoNoYesNoNo CVE-2026-84598 MobileBackup An attacker with physical access to a trust-paired device may be able to read and write arbitrary files TBDTBD YesYesNoNoNoNoNoNoNoNo CVE-2026-84497 Model I/O Opening a maliciously crafted file may lead to unexpected process termination TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-84615 Music An app may be able to access sensitive user data TBDTBD YesYesNoNoNoYesNoYesNoNo CVE-2026-43695 NetworkExtension An app may be able to access sensitive user data TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-84585 NetworkExtension An app may be able to access local network devices without user consent TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84626 NetworkExtension An app may be able to identify what other apps a user has installed TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-86902 NSDocument An app may be able to access sensitive user data TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84629 Photos Storage An app may be able to fingerprint the user TBDTBD YesNoNoNoNoYesYesYesNoNo CVE-2026-84623 Power Management An app may be able to fingerprint the device TBDTBD YesYesNoNoNoNoNoNoNoNo CVE-2026-84578 quarantine An app may be able to break out of its sandbox TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84580 quarantine An app may be able to break out of its sandbox TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84548 Quick Look Processing a maliciously crafted document may lead to an out-of-bounds read TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-28966 RealityKit Processing a maliciously crafted file may lead to unexpected app termination TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-84532 RealityKit Opening a maliciously crafted file may cause unexpected process termination or disclose process memory TBDTBD YesYesYesYesYesYesNoYesNoNo CVE-2026-65403 Reminders An app may be able to access sensitive user data TBDTBD YesYesYesYesYesNoYesYesNoNo CVE-2026-86897 Safe Browsing An app may be able to access sensitive user data TBDTBD YesYesYesNoNoNoNoYesYesNo CVE-2026-65380 Sandbox An app may be able to access protected user data TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84551 Sandbox An app may be able to bypass network restrictions TBDTBD YesNoYesNoNoNoYesYesNoNo CVE-2026-84603 Sandbox Profiles An app may be able to access sensitive user data TBDTBD YesNoNoNoNoNoYesYesNoNo CVE-2026-84625 Sandbox Profiles An app may be able to fingerprint the user TBDTBD YesNoYesNoNoNoYesYesNoNo CVE-2026-43697 SceneKit Processing a maliciously crafted 3D file may lead to an out-of-bounds read TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84526 SceneKit Processing a maliciously crafted 3D scene may lead to unexpected process termination TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84546 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84620 SceneKit Processing a maliciously crafted 3D model may lead to memory corruption TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84531 Security Processing maliciously crafted NTLM input may lead to unexpected app termination TBDTBD YesNoYesNoNoNoNoNoNoNo CVE-2026-86881 Security An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-84600 Shortcuts A malicious shortcut may be able to send messages without user confirmation TBDTBD YesNoYesNoNoYesYesYesNoNo CVE-2026-86884 Siri An app may be able to access sensitive user data TBDTBD YesNoYesNoNoYesYesNoNoNo CVE-2026-86890 Siri Suggestions An attacker with physical access to a locked device may be able to view sensitive user information TBDTBD YesYesNoNoNoNoNoNoNoNo CVE-2026-65376 SMB An app may be able to cause unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84509 SMB Connecting to a malicious SMB server may lead to unexpected system termination TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84609 Software Update An app may be able to modify protected system files TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-65361 SoftwareUpdate An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65378 Spotlight An app may be able to access sensitive user data TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84621 Spotlight An app may be able to access sensitive user data TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-86892 SpringBoard An app may be able to cause a denial-of-service TBDTBD YesYesNoNoNoNoNoYesNoNo CVE-2026-65345 Storage An app may be able to access user-sensitive data TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-65348 Storage An app may be able to modify protected parts of the file system TBDTBD YesYesYesYesYesNoNoNoNoNo CVE-2026-43791 StorageKit An app may be able to read arbitrary files TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-84513 Symptom Framework A malicious application may be able to determine a user's current location TBDTBD YesYesYesYesYesYesYesYesNoNo CVE-2026-65383 System Settings An app may bypass Gatekeeper checks TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-86909 System Settings An app may be able to bypass Gatekeeper checks TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84527 TCC An app may be able to access sensitive user data TBDTBD YesNoYesYesYesYesYesYesNoNo CVE-2026-84589 TCC An app may be able to modify Privacy preferences TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-86886 TCC An app may be able to modify protected system files TBDTBD YesYesNoNoNoNoYesNoNoNo CVE-2026-65329 Telephony An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic TBDTBD YesNoNoNoNoNoNoNoNoNo CVE-2026-86887 Time Zone An app may be able to bypass certain Privacy preferences TBDTBD YesYesNoNoNoNoNoYesNoNo CVE-2026-43696 Touch Bar An app may be able to capture Touch Bar content without authorization TBDTBD NoNoYesNoNoNoNoNoNoNo CVE-2026-84572 udf An app may be able to cause unexpected system termination or read kernel memory TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-28899 WebDAV An app may bypass Gatekeeper checks TBDTBD NoNoYesYesYesNoNoNoNoNo CVE-2026-65375 WebDAV An app may be able to cause unexpected system termination TBDTBD NoNoYesNoYesNoNoNoNoNo CVE-2026-84635 WebKit Processing maliciously crafted web content may lead to an unexpected process termination TBDTBD YesNoYesNoNoYesYesYesYesNo CVE-2026-86898 WebKit Opening a maliciously crafted webarchive file may lead to universal cross-site scripting TBDTBD YesNoYesNoNoNoNoYesYesNo CVE-2026-84636 Wi-Fi Connectivity An app may be able to access sensitive user data TBDTBD YesNoNoNoNoYesYesYesNoNo CVE-2026-43674 Wi-Fi3 An attacker with physical access to an unlocked device may be able to view Wi-Fi passwords without authentication TBDTBD YesNoNoNoNoNoNoNoNoNo We’ll continue these macOS updates if people find them useful. Stay tuned for the regularly schedule Patch Tuesday blog covering Adobe and Microsoft.
SC Media VulnConnectWise ScreenConnect bug exploited in the wild, CISA says
Experts warn teams to patch right away to prevent a potential ransomware incident.
CSO Online PolicyLinkedIn fights for the right to tell customers when the feds want their data
Microsoft’s top lawyer argued Tuesday that legislators “must make secrecy [orders] the exception” in government subpoenas demanding information about LinkedIn users. LinkedIn, which is owned by Microsoft, is fighting what it calls overly broad subpoena demands from the US government, which sometimes come with secrecy orders that prevent LinkedIn from alerting customers whose information is being requested. The company is asking federal courts “to enforce meaningful limits on both the scope of government demands and the secrecy that can accompany them,” wrote Jon Palmer, Microsoft’s chief legal officer, in a Tuesday blog post. “We recognize law enforcement’s important role in protecting public safety and investigating crime, and sometimes that does need to be done covertly. At the same time, customers and users deserve meaningful limits and independent oversight through an adversarial process.” He pointed out: “People and organizations increasingly entrust their most sensitive information to online services. If providers cannot challenge demands they know are overbroad—or if courts may silence them without a rigorous, adversarial review—the safeguards the law requires will be weakened precisely when they are most needed.” A tricky issue The issue is a tricky one. Law enforcement often use this type of subpoena as an investigative tool, seeking those who are engaged in illegal activities. The theoretical justification for secrecy is to avoid alerting the investigative target to make it less likely the suspect will try to destroy evidence or flee the jurisdiction. Government lawyers are supposed to only make secrecy requests when absolutely essential. Microsoft is suggesting that courts and congress need to step in to curtail blanket government efforts. “The Fourth Amendment protects the right to be free from unreasonable searches and seizures. That right applies to papers kept in a desk and it also applies when personal and business records are stored online,” Palmer wrote. “Online service providers, like LinkedIn and Microsoft, also have a First Amendment right to speak to their customers when the government obtains an order to search their private information. Secrecy may sometimes be justified, but it should be tailored to demonstrated needs and subject to meaningful review.” He added: “The government must seek only relevant information, justify secrecy with specific evidence and infringe on speech to the least extent possible.” In his post, he pointed to a recent legislative effort in the US House of Representatives that might mitigate the issue if it ends up becoming law. “On August 31, the House passed legislation to rein in secret surveillance and strengthen notice protections when the government seeks data held by technology providers,” he wrote. “The reforms would place clearer limits on secrecy orders, require greater accountability, and help ensure that secrecy is the exception – not the rule. The Senate should act promptly to send these historic reforms to the President.” LinkedIn privacy battles LinkedIn itself is currently fighting litigation that accuses it of directly violating the privacy rights of its customers, and a federal judge this month dismissed another similar case, but gave plaintiffs permission to refile, with a caveat. “Given LinkedIn’s further arguments that users voluntarily download browser extensions, which by their nature intentionally expose data to websites, it seems unlikely that the plaintiffs will ever be able to allege a privacy violation, much less prevail at the end of the day,” US District Court Judge Vince Chhabria wrote. “But in an abundance of caution, dismissal is with leave to amend.” But, he added, if the amended complaint isn’t filed within 14 days, “dismissal will be with prejudice.” Privacy now a ‘data stewardship obligation’ Jeff Valdes, a director at Acceligence, noted, “there is definitely some irony here.” “If Microsoft wants customers to view it as a steward of their privacy when the government comes asking for their information, customers are naturally going to apply that same standard to how Microsoft and LinkedIn collect, use, protect, and disclose information themselves,” he said. “Privacy is difficult to compartmentalize. You cannot have one philosophy of customer privacy for government access, another for product design, and another for your own commercial data practices without eventually creating a credibility problem.” Mike Wilkes, enterprise CISO at Aikido Security, agreed, pointing out, “without meaningful limits, judicial scrutiny, and an expiration mechanism, a temporary investigative necessity starts looking a lot like a permanent architecture for invisible surveillance. The individual may never have an opportunity to challenge the scope of the request, because they may never even know the request existed until prosecutors show up with an indictment.” That, he said, “is why Microsoft’s argument matters, despite the obvious irony of LinkedIn simultaneously defending itself against privacy claims from its own users.” But Ryan O’Leary, an IDC research director, offered a different perspective. “Microsoft makes no bones about using the data contained within its own systems for its own purposes. Both things can be true: Microsoft can fight for the privacy of its platform while still not necessarily respecting the privacy rights of its end users,” O’Leary noted. “This seems to come down to protecting its own proprietary data sets, not some altruistic privacy crusade.” At the same time, Valdes pointed out, Palmer’s post highlights how deeply privacy has become a top-tier enterprise IT priority. “Privacy is rapidly becoming a much broader data stewardship obligation,” he said. “Companies holding sensitive information increasingly have to think simultaneously about government requests, third-party access, their own collection practices, AI use, data retention and what they tell customers about all of it. If you want to be trusted as the custodian of the world’s data, customers are going to judge how you protect that data in every direction.” However, Wilkes noted, “Microsoft does not need to be a perfect privacy saint to be right about this particular problem.”
The Record Breach
Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’
U.S. personnel boarded an oil tanker in the Gulf of Mexico to “ensure integrity of the vessel’s operational and information technology systems," after an apparent cyberattack, the U.S. Coast Guard said.
The Record Policy
House passes bill to equip local law enforcement with scam-fighting tools
The Guarding Unprotected Aging Retirees from Deception Act (GUARD) attempts to address a common complaint from the victims of online scams like pig butchering — that such cases typically do not rise to the level of a federal investigation but local law enforcement is unequipped to properly investigate them.
SC Media GeneralHastily deployed agentic security is not the answer to enterprise cyber threats
Rushing agentic security into production could create new risks instead of strengthening cyber defenses.
Krebs on Security Policy
Data Broker Radaris Loses Domains in Privacy Fight
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge in the case ordered that radaris.com and more than a dozen other data broker domains be transferred to the plaintiffs.
Dark Reading General
Fighting Your Dragons Through Tough Tech Times
Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.
Dark Reading Breach
BragJack Attack Can Turn a Browser's Agentic AI Against It
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.
SecurityWeek BreachFirst Agentic AI Data Breach Reported to Spanish Regulator
Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek.
CSO Online PolicyBig Tech’s AI safety rift signals disruption and disparity for enterprises
A growing divide among leading AI companies over how to secure increasingly powerful models is beginning to translate into challenges for enterprise IT, with implications for how organizations access, deploy, and govern AI systems. The latest flashpoint came after Meta CEO Mark Zuckerberg called for neutral evaluators to independently test AI models, pushing back on calls from rivals to slow development or tighten coordination. “trust and alignment are quickly becoming the most important capabilities that will differentiate agents and models. Any lab that doesn’t focus on alignment will fall behind,” Zuckerberg wrote in a post on X. “Engaging independent evaluators and advisors is industry best practice,” he added, noting that Meta already does this in several areas. His comments follow a series of public proposals from AI industry leaders including Dario Amodei, who argued for a more cautious pace of development, and Sam Altman, who called for collaboration on safety standards. The debate has intensified amid disclosures from AI labs and policymakers on potential misuse of advanced systems. Anthropic has said it restricted attempts to use its Claude models in sensitive domains, while OpenAI has engaged with policymakers on AI-related risks, according to company statements and reports. Enterprise concerns While the debate is often framed as a choice between slowing innovation and strengthening oversight, analysts said enterprises should focus less on which approach prevails and more on the operational consequences already taking shape. “Divergent safety approaches will make access to advanced AI models less predictable, rather than producing an industrywide slowdown,” said Sushovan Mukhopadhyay, director analyst at Gartner. Vendors are likely to apply different release schedules, regional availability, access tiers, and usage restrictions, he said, meaning enterprises could encounter similar capabilities “at different times and under materially different conditions.” Mukhopadhyay said enterprises should plan for variability in access rather than assuming consistent availability across providers or geographies. “I read this week as the point where frontier AI became a managed supply,” said Bhupendra Chopra, chief revenue officer at Kanerika. “For three years CIOs could assume the next model would simply show up. A frontier model now behaves more like a critical component from a supplier whose delivery dates depend partly on outside reviewers and export rules.” Chopra added that “any AI roadmap built on a specific model arriving on a specific date is carrying supply risk it hasn’t priced.” Security pressure builds regardless of slowdown Analysts said slowing development alone is unlikely to materially change enterprise risk, particularly as open-source models proliferate. “The biggest point isn’t the pause itself. It’s that the leaders of AI companies are agreeing on something,” said Nikhil Gupta, founder and CEO of ArmorCode. Gupta said the threat landscape has already shifted. “Even if companies hit pause, open-source AI models are already out there,” he said. “I’m not convinced slowing down some companies meaningfully changes what adversaries can do.” “Even if AI development slows down tomorrow, security must accelerate,” Gupta added. “The job of securing these systems has effectively gotten ten times harder.” A new ‘AI assurance’ layer emerges The focus on evaluation is driving what analysts described as an emerging “AI assurance” layer, where third parties assess models for safety and compliance. “A distinct AI assurance layer is likely to emerge, but enterprises should not expect a single certification to establish that an AI system is safe,” Mukhopadhyay said. “Enterprise risk also depends on data, system instructions, tools, agents and deployment controls.” Chopra said enterprises risk misinterpreting such evaluations. “Procurement teams may see a third-party evaluation and treat the model as vetted,” he said. “Within a year it becomes a checkbox.” Instead, he said, enterprises will need to run their own validation. “CIOs who get ahead will test each model against their own data before it touches production.” Fragmentation complicates multi-model strategies For CIOs pursuing multi-vendor strategies, differing approaches across providers could introduce additional complexity. “Fragmentation was already the default. Safety divergence deepens it,” Chopra said. He said risk is most acute during transitions. “For an enterprise running several models, the exposure sits in the handoff,” he said. “When a model is delayed or replaced, the system can behave differently.” “I’d rank untested model substitution above vendor lock-in,” Chopra said. Gupta said open architectures will be important. “The framework needs to be open, not locked to any single vendor,” he said. Mukhopadhyay added that enterprises should prepare for models becoming unavailable or restricted. CIOs urged to build resilience Analysts said enterprises will need to design AI strategies that can adapt to changes in availability, pricing, and governance. “For critical applications, CIOs should separate application controls and business logic from the underlying model,” Mukhopadhyay said. Chopra emphasized flexibility. “A routing layer between applications and model providers turns switching into configuration work,” he said, adding that contracts should cover deprecation timelines. He also pointed to pricing implications. “Scarce access to the frontier starts to carry a premium,” Chopra said. This article first appeared on Computerworld.
Bellingcat General“A Recurring Pattern”: Civilians Paying the Price in Mali’s Drone Campaign
Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published. WARNING: This report contains links to graphic images and footage. A joint Bellingcat and Jeune Afrique investigation into drone strikes carried out by the Malian military adds new details about the attacks which frequently are carried out in civilian areas and have […] The post “A Recurring Pattern”: Civilians Paying the Price in Mali’s Drone Campaign appeared first on bellingcat.
CSO Online VulnOracle’s September patches put Fusion Middleware back in the hot seat
Oracle’s September 2026 Critical Security Patch Update has arrived with 673 new security patches spanning 17 Oracle product families, with Oracle E-Business Suite accounting for the largest share at 159 patches, followed by Fusion Middleware with 153. Of these, 19 E-Business Suite vulnerabilities and 78 Fusion Middleware vulnerabilities can be remotely exploited without authentication. Other product categories with 50 or more issues fixed in the rollout include Oracle Database Server, Oracle Communications, and Oracle Analytics. Oracle recently accelerated its patching rhythm from quarterly to monthly. It advised customers to apply the September patches immediately, warning that it continues to receive reports of successful attacks on its software where customers had not applied available fixes. Five max-severity flaws sit in Fusion Middleware The September update addresses five critical vulnerabilities carrying the maximum CVSS score of 10.0 within Fusion Middleware. They affect Oracle Access Manager (CVE-2026-71133), Oracle Forms (CVE-2026-83099), Oracle Internet Directory (CVE-2026-83059), Oracle Platform Security for Java (CVE-2026-83020), and Oracle WebLogic Server (CVE-2026-83021). All five are remotely exploitable without authentication over the network; attacking them is of low complexity and requires neither privileges nor user interaction. The update also addressed a sixth CVSS 10.0 vulnerability, this one in Oracle Hyperion Financial Management (CVE-2026-87230); it too can be remotely exploited without authentication. The update also includes 13 Fusion Middleware bugs with a CVSS score of 9.9, just below the maximum severity. These include CVE-2026-71163 and CVE-2026-73945 in Oracle Access Manager, CVE-2026-83055, CVE-2026-83057 and CVE-2026-83056 in Oracle Internet Directory, CVE-2026-83058, CVE-2026-73948 and CVE-2026-83039 in Oracle WebCenter Portal, CVE-2026-82999, CVE-2026-82997 and CVE-2026-82998 in Service Delivery Platform, and one each in Oracle WebCenter Sites (CVE-2026-83031) and Oracle WebLogic Server (CVE-2026-83038). None of these are remotely exploitable without authentication. However, they require low privileges, remain network-accessible and can have high confidentiality and integrity impacts. Oracle did not mark any of the six CVSS 10.0 and 13 CVSS 9.9 vulnerabilities as exploited in the wild. Fusion Middleware has featured heavily in Oracle’s recent patch cycles too. Its July update addressed 10 CVSS 10.0 vulnerabilities, highlighting the product family’s recurring exposure to maximum-severity flaws. Oracle’s patching message is as important as the patches Until patches can be deployed, Oracle said, customers may reduce exposure by blocking network protocols required for an attack or removing unnecessary privileges and package access. However, it cautioned, these measures can break application functionality and should be tested on non-production systems. They are not to be considered long-term solutions because they do not address the underlying vulnerabilities, the company said in its September critical patch update advisory. It also included a warning for organizations running older Oracle releases. The fixes are provided only for supported versions, the company said, adding that “Product releases that are not under Premier Support or Extended Support are not tested for the presence of vulnerabilities addressed by this Critical Security Patch Update.” Also, for organizations that have skipped earlier security updates, Oracle advises reviewing previous CSPUs and quarterly Critical Patch Updates rather than assuming the September releases covers the backlog. This article first appeared on CIO.
The Hacker News Vuln
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded
The Record Breach
International Meteor Organization says cyberattack dealt ‘critical blow’ to website
A website used around the world for reporting meteors faces weeks of downtime as the organization moves away from systems that were hacked recently.
CSO Online BreachAI agent authorization risks remain a gap in new NIST-CISA token security guidance
AI agents’ actions are out of scope for new guidance from US authorities on securing identity and access tokens, but there is still plenty enterprises can do to protect their systems from rogue humans and AI agents alike. “Protecting Tokens and Assertions from Forgery, Theft, and Misuse,” a new report from the National Institute of Standards and Technology (NIST) with help from the Cybersecurity and Infrastructure Security Agency (CISA), offers guidance for operators of systems that use digitally signed tokens to make access decisions, including single sign-on and API access. The guidelines, also known as NIST IR 8587, address what happens after authentication: Tokens and assertions can carry proof of authentication or authorization between systems, allowing an attacker who compromises them to exploit access that has already been granted. NIST recommends continuous monitoring, along with tighter controls throughout the token lifecycle. The issue is of particular significance for CISA. In May, a public GitHub repository believed to have been maintained by a CISA contractor was found to contain sensitive government credentials, including AWS tokens and GitHub access tokens. CISA said at the time there was no indication that sensitive data had been compromised. The unresolved question of agent authority NIST recommends applying the same guidelines for securing signed tokens used by AI agents as for securing those used by humans, but notes that the access risks posed by AI and AI agents “create additional IAM challenges that require further guidelines and, in some cases, new or expanded standards and protocols.” NIST and CISA are still working on those, but there are things that IT teams can do meanwhile to secure agentic systems. Managing the lifecycle of an agent’s identity is part of the challenge, said Yih Khai Wong, senior research manager for security services at IDC Asia/Pacific. Enterprises need visibility into who provisioned an agent’s credentials and what those credentials allow, Wong said. Access should also be withdrawn when the agent’s task ends. “Token hardening assumes the token holder is a known, bounded actor,” Wong said. “An agentic system breaks that assumption.” Delegation can make that boundary harder to establish, said Amit Kumar Jena, head of AI development at Kanerika. An agent may act on behalf of a user, invoke a tool and then reach another service, making it increasingly difficult to determine whose authority is being exercised as the chain grows. Jena said prompt injection could also steer an agent holding a valid token toward an action the user never requested. Token verification would not necessarily detect that misuse because the token itself could still be legitimate. Jain argued that CISOs should treat AI agents as low-trust non-human identities, granting only the access required for a task. Higher-risk actions should require human approval, he added. Wong also recommended maintaining an agent inventory and keeping those identities separate from human accounts. Credentials should expire when the task is complete, he said. Why valid tokens can still be dangerous A common weakness is assuming that because a token is valid, the activity associated with it is legitimate, according to Jonathan Ong, senior analyst for managed security services at Omdia. Organizations should consider the context in which a token is presented, including whether a user is accessing sensitive systems from an unusual location or at an unexpected time, Ong said. Detection should also correlate activity across security domains to identify behavior that may appear benign in isolation. Containment presents another challenge once a token has been compromised. “Token revocation may not always be possible due to architectural limitations,” Ong said. Other controls can limit the usefulness of a compromised token. Neil Shah, vice president for research and partner at Counterpoint Research, said that NIST’s recommendations can reduce both the duration and reach of a token compromise. Audience restrictions can limit where a stolen token is accepted, while cryptographically binding a token to the client holding the corresponding private key makes replay by an attacker more difficult. The report also points organizations toward shared-signal mechanisms such as the Continuous Access Evaluation Profile (CAEP) and Risk Incident Sharing and Coordination (RISC), which can help connected systems respond when token-related security conditions change, Shah said. Token security extends beyond IAM The CISA credential exposure also highlights how token security can break down outside traditional IAM controls, Jain said. Credentials can surface in source code, CI/CD pipelines, logs and contractor environments even when access policies themselves are sound. “If a contractor can copy a cloud credential to their local machine, the identity governance has already failed,” Shah said. Managing that risk through policy alone can be difficult in DevOps environments, where credentials can be copied onto developer machines or exposed through automated pipelines, Shah said. He argued that enterprises should eliminate static tokens wherever possible and replace them with short-lived credentials. The CISA incident also exposes a boundary in the NIST guidance, Jena said. IR 8587 focuses on asymmetrically signed tokens and explicitly places mechanisms such as API keys outside the scope of its controls. NIST nevertheless requires covered tokens to be kept out of logs, CI/CD pipelines, and build artifacts.
The Hacker News Malware
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
InfoSecurity Magazine VulnPHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
CyberScoop BreachCoast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.” The post Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks appeared first on CyberScoop.
The Hacker News General
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was installed, it could access each product's built-in AI with a single click. On Comet, Edge,
SecurityWeek BreachVirtual Event Today: Attack Surface Management Summit
Join SecurityWeek today for a virtual summit exploring the strategies and tools organizations need to discover, prioritize, and defend their expanding attack surfaces. The post Virtual Event Today: Attack Surface Management Summit appeared first on SecurityWeek.
The Record Breach
Three Ukrainians to face charges for alleged hack of 610,000 Roblox accounts
Three Ukrainians are set to stand trial for allegedly stealing access to more than 610,000 Roblox accounts and selling them to buyers in Russia, authorities said.
SecurityWeek BreachEU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media
Ursula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture” of children. The post EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media appeared first on SecurityWeek.
Qualys Security Blog VulnOracle Critical Security Patch Update, September 2026 Review
Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. Out of the 673 security updates published, a total of 104 […]
SC Media GeneralPreparing for AI-enabled incidents: Helping business leaders understand enterprise risk
Here's a primer on proactive incident response in the age of AI.
CyberScoop GeneralTreasury’s Scott Bessent says no liability exemptions for AI labs
The secretary told House Financial Services Committee lawmakers that the “best way to guarantee safety” is for AI creators to be held “liable for what they build and generate.” The post Treasury’s Scott Bessent says no liability exemptions for AI labs appeared first on CyberScoop.
InfoSecurity Magazine GeneralCISA and NIST Issue Guidance to Protect Cloud Identity Tokens
CISA and NIST issued final guidance to help protect cloud identity tokens and assertions
Security Affairs VulnGoogle Patches Pixel Modem Zero-Day Exploited in Targeted Attacks
Google has patched a high-severity zero-day in the Pixel cellular modem after finding evidence that the vulnerability was exploited in limited, targeted attacks. Google has released its September 2026 Pixel security update, addressing a large set of vulnerabilities, including a high-severity flaw, tracked as CVE-2026-58704 (CVSS score of 8.0), in the cellular modem that has […]
The Record Breach
Flock camera use by internal affairs unit puts DC police at odds with officers’ union
Washington, D.C.'s police department has used information from Flock cameras for misconduct investigations, prompting a formal complaint from its officers' union.
SecurityWeek BreachAIUC Raises $40 Million to Certify Enterprise AI Agents
The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions. The post AIUC Raises $40 Million to Certify Enterprise AI Agents appeared first on SecurityWeek.
The Hacker News Malware
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the
The Hacker News Vuln
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attack needs code already running on the machine as a normal user, so it does not work over the network. JFrog says the fix is in Parallels Desktop 27, a version that Intel Macs cannot install. Yuval Moravchick, who leads
The Record Breach
EU chief wants joint response to cyberattacks, sabotage
Delivering her annual State of the Union address in Strasbourg, Ursula von der Leyen said threats were “mounting on our soil,” pointing to recent incidents in Denmark, Lithuania and Poland and an attempted drone attack in Leipzig.
SecurityWeek VulnPixel Modem Zero-Day Exploited in Targeted Attacks
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek.
Security Affairs BreachRevolut Data Leak May Trace Back to Compromised Italian Government Accounts
A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The Revolut data exposure may be part of a much broader cyber incident involving compromised Italian government infrastructure. Revolut has confirmed that its systems were not breached. Instead, […]
The Record Breach
Ukraine moves to crack down on scam call centers after corruption scandal
Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations.
SecurityWeek MalwareUS, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek.
CISA Advisories Breach
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-58704 Google Pixel Improper Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
CISA Advisories Policy
Using Cyber Decoys to Strengthen Detection and Response
CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI). As organizations adopt Zero Trust models, they should assume that a malicious threat actor may gain some level of access to their environment and plan accordingly. Cyber decoys complement Zero Trust by: Supporting continuous monitoring and verification, Creating high-fidelity alerts for suspicious activity, Reducing alert fatigue, and Helping defenders detect post-compromise activity, including adversary LOTL techniques. This guidance introduces decoy concepts—including tripwires, breadcrumbs, and honeytokens—and uses the MITRE Engage™ and MITRE ATT&CK® frameworks to provide practical, low-complexity steps for planning, implementing, and refining decoy operations. For additional information, visit CISA’s Best Practices for MITRE ATT&CK Mapping. Note: CISA is committed to providing access to our web pages and documents for individuals with disabilities, both members of the public and federal employees. If the format of any elements or content within this document interferes with your ability to access the information, as defined in the Rehabilitation Act, please email contact@cisa.dhs.gov. To enable us to respond in a manner most helpful to you, please indicate the nature of your accessibility problem and the preferred format in which to receive the material. CISA will update Using Cyber Decoys to Strengthen Detection and Response when the 508 compliance has been completed.
CISA Advisories Breach
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
The Hacker News Breach
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud
SecurityWeek VulnUnauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek.
Schneier on Security Policy
Fake CAPTCHA Scams
New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.
The Hacker News Vuln
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database