CIS Community Defense Model v3.0: Turning Threat Intelligence Into Action

Source: Blog Feed – Center for Internet Security

Author: unknown

URL: https://www.cisecurity.org/insights/blog/cis-community-defense-model-v3-turning-threat-intelligence-into-action

ONE SENTENCE SUMMARY:

CDM v3.0 prioritizes high-value CIS Controls Safeguards, improving visibility, resilience, and risk reduction through standardized, confidence-driven cybersecurity management.

MAIN POINTS:

  1. CDM v3.0 helps identify and prioritize high-value CIS Controls Safeguards.
  2. A risk-based approach aligns cybersecurity actions to mission-critical outcomes.
  3. Continuous monitoring improves visibility into assets, vulnerabilities, and configurations.
  4. Standardized metrics enable consistent measurement across programs and organizations.
  5. Centralized reporting supports faster, data-driven decision-making for leadership.
  6. Implementation guidance clarifies which safeguards deliver the greatest risk reduction.
  7. Improved cyber hygiene strengthens resilience against common and advanced threats.
  8. Confidence increases by validating controls through measurable performance indicators.
  9. Resource allocation becomes more efficient by focusing on highest-impact safeguards first.
  10. Reduced uncertainty supports defensible compliance and audit readiness efforts.

TAKEAWAYS:

  1. Prioritize safeguards that measurably reduce the most risk.
  2. Use continuous monitoring to maintain accurate, actionable security visibility.
  3. Apply standardized measures to compare progress and effectiveness over time.
  4. Focus investments where they strengthen resilience and mission assurance.
  5. Validate outcomes with metrics to reduce guesswork and increase confidence.

Revoking the token didn’t kill the backdoor

Source: CSO Online

Author: unknown

URL: https://www.csoonline.com/article/4223975/revoking-the-token-didnt-kill-the-backdoor.html

ONE SENTENCE SUMMARY:

GraphWorm uses Microsoft Graph/OneDrive C2 and can remotely swap OAuth identities, making token revocation insufficient without endpoint isolation.

MAIN POINTS:

  1. Typical identity runbooks prioritize revoking tokens to end session-based compromise.
  2. GraphWorm communicates via Microsoft Graph, using OneDrive as a dead-drop C2.
  3. Tasking uses encrypted job/result folders plus heartbeat and fingerprint files.
  4. Network controls struggle because traffic looks like normal Microsoft 365 TLS activity.
  5. Implant stores client ID, client secret, tenant ID, and long refresh token in cleartext.
  6. Victim ID is hardware-derived, resisting containment via hostname, subnet, or egress changes.
  7. An upgrade command replaces all credentials and scopes from a single task.
  8. Operator can recover immediately after token revocation by switching to a spare OneDrive identity.
  9. Effective detection relies on cloud telemetry: app ID, tenant anomalies, user-agent, file names.
  10. Containment must target the app registration and endpoint behavior, not just token artifacts.

TAKEAWAYS:

  1. Reframe token revocation as a delay when adversaries control application identities.
  2. Sequence response to block channel access while burning credentials, not afterward.
  3. File platform suspension requests early because third-party tenant action can be slow.
  4. Query sign-in telemetry for fixed malicious application IDs to confirm exposure quickly.
  5. Focus hunts on endpoint-resident code and repeatable behaviors attackers can’t cheaply replace.

5 ways AI is reshaping the cybersecurity job market

Source: CSO Online

Author: unknown

URL: https://www.csoonline.com/article/4224019/5-ways-ai-is-reshaping-the-cybersecurity-job-market.html

ONE SENTENCE SUMMARY:

AI automation is reshaping cybersecurity teams through consolidation, shifting analyst work to judgment, demanding AI fluency, and shrinking pipelines globally.

MAIN POINTS:

  1. LastPass dissolved dedicated vulnerability management, moving duties into IT and product security.
  2. Triage and analysis increasingly rely on AI and business intelligence tools.
  3. WEF reports 87% see AI-related vulnerabilities as fastest-growing risk category.
  4. SANS/GIAC found 74% say AI is changing security team sizes and roles.
  5. Leadership structures are consolidating, avoiding new C-level roles for AI governance.
  6. Routine GRC compliance is being automated so staff can become higher-level risk advisors.
  7. Analysts now evaluate automated findings and tune systems, not just work alert queues.
  8. Judgment has become the scarcest capability, especially validating AI outputs against business context.
  9. The “AI loop” can reinforce wrong assumptions, producing confident but flawed risk reports.
  10. Entry-level rungs are disappearing, widening skills gaps and linking workforce shortages to breaches.

TAKEAWAYS:

  1. Consolidate governance thoughtfully while ensuring accountability doesn’t overload a few leaders.
  2. Re-skill SOC staff toward validation, root-cause reasoning, and system engineering oversight.
  3. Prioritize senior judgment development to counter confidently incorrect automation at scale.
  4. Hire for balanced AI fluency—neither skepticism nor hype—aligned to real control needs.
  5. Protect junior-to-senior pathways to prevent future talent shortages becoming operational security risk.

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html

ONE SENTENCE SUMMARY:

TASK#STOMP is a VBScript-orchestrated, PowerShell-based backdoor campaign enabling stealthy persistence, surveillance, credential theft, document exfiltration, and redundant C2.

MAIN POINTS:

  1. Campaign deploys a PowerShell backdoor for data theft and remote command execution.
  2. Infection begins with wscript.exe running an encoded VBScript staged on the desktop.
  3. Initial delivery vector is unclear, possibly phishing or social engineering via email.
  4. Randomized VBScript filename likely aims to evade simple name-based detections.
  5. Persistence established through scheduled tasks masquerading as legitimate Windows services.
  6. Backup persistence uses Startup folder to run msdiag.vbs at user logon.
  7. Malware kills prior instances to enforce a single active session.
  8. Stealth techniques include timestomping, hidden execution, and trace-cleanup behaviors.
  9. Two PowerShell modules provide redundancy, mutual watchdogging, and separate C2 channels.
  10. C2 domains corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz use token-authenticated communications.

TAKEAWAYS:

  1. Native Windows tooling abuse can make malicious activity resemble routine administration.
  2. Layered persistence significantly increases resilience against partial remediation.
  3. Mutual watchdog processes help maintain long-lived access despite interruptions.
  4. Collection focuses on business documents, Wi‑Fi credentials, clipboard data, and screenshots.
  5. Unusual user-facing actions (opening Iran tenders site) may indicate staging, distraction, or operator workflow.

Data center failure affects New Mexico credit union services

Source: Top Stories

Author: unknown

URL: https://www.koat.com/article/data-center-failure-affects-new-mexico-credit-union-services/73795685

ONE SENTENCE SUMMARY:

A third-party data center cooling failure triggered a Sharetec outage, disrupting New Mexico credit union access without evidence of breach.

MAIN POINTS:

  1. Cooling system failure occurred at an out-of-state third-party data center.
  2. Sharetec experienced a nationwide outage beginning Sept. 15.
  3. New Mexico credit union members faced limited account access.
  4. Service impacts differed depending on each credit union’s reliance on Sharetec.
  5. Direct deposit availability was restricted for some affected members.
  6. Cash withdrawal access was limited at certain institutions.
  7. Everyone’s Federal Credit Union handled member needs individually.
  8. Manual processing using paper records replaced automated transactions.
  9. Sharetec provided only a voicemail acknowledging connectivity issues and remediation efforts.
  10. Credit unions stated the incident was not identified as a data breach.

TAKEAWAYS:

  1. Third-party infrastructure failures can cascade into widespread financial service outages.
  2. Manual fallback procedures help maintain limited operations during prolonged vendor downtime.
  3. Customer impacts may include delayed deposits and constrained cash access.
  4. Lack of timely vendor communication increases uncertainty for affected institutions and members.
  5. Ongoing restoration timelines can remain unclear even when breaches are ruled out.

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Source: Help Net Security

Author: Zeljka Zorz

URL: https://www.helpnetsecurity.com/2026/09/17/cisco-ise-vulnerability-exploited-cve-2026-76460/

ONE SENTENCE SUMMARY:

Cisco warns CVE-2026-76460 actively exploits Cisco ISE API authentication bypass; update, hunt indicators, and reimage compromised nodes.

MAIN POINTS:

  1. Cisco confirmed active exploitation of CVE-2026-76460 in Cisco Identity Services Engine.
  2. Vulnerability is an authentication bypass caused by insufficient API endpoint authentication controls.
  3. Remote unauthenticated attackers can bypass the web management interface via crafted requests.
  4. Affected products include Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC).
  5. Impacted versions span releases 3.0 through 3.5 across deployments.
  6. Cisco provided indicators of compromise but withheld observed attack details.
  7. Investigation should review access.log for suspicious usernames on every node.
  8. If compromise suspected, re-image affected nodes and restore configurations from backups.
  9. Verify external firewall and network logs for suspicious uploads/downloads tied to affected devices.
  10. Fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4.

TAKEAWAYS:

  1. Patch immediately because no workaround mitigates this actively exploited authentication bypass.
  2. Treat all cluster nodes as potentially affected and perform uniform log review.
  3. Preserve evidence by correlating device activity with external network and firewall telemetry.
  4. Plan migration away from 3.0–3.2 due to limited or ended maintenance support.
  5. Expect additional ISE/ISE-PIC security fixes, including findings from researchers and internal AI-assisted testing.

Certificate failures can cost firms over $250,000

Source: Help Net Security

Author: Anamarija Pogorelec

URL: https://www.helpnetsecurity.com/2026/09/14/digicert-certificate-management-automation-report/

ONE SENTENCE SUMMARY:

DigiCert warns 47-day TLS certificates will multiply renewals, validations and outages unless enterprises rapidly gain visibility and automate lifecycles everywhere.

MAIN POINTS:

  1. Shifting to 47-day public TLS certificates by 2029 increases renewals eightfold and validations 40x.
  2. Expired certificates caused outages for 34% of firms; 40% reported downtime from mismanagement.
  3. Downtime severity is high: nearly three-quarters lost five hours, while 21% lost 25+.
  4. Financial impact is substantial, with 25% citing their worst incident exceeding $250,000.
  5. Operational ownership skews to infrastructure: 57% label outages IT issues versus 17% security incidents.
  6. Certificate sprawl is common, as over half of organizations manage more than 1,000 certificates.
  7. Key “very/extremely concerned” challenges include expiration, customer trust, regulatory compliance, and multi-cloud/platform management.
  8. Managing internal and external systems simultaneously worries 52%, highlighting fragmented environments needing central control.
  9. Adoption momentum is growing: ~70% are preparing for shorter lifetimes, and volumes are expected to rise.
  10. Automation expansion is constrained by cost, legacy incompatibility, weak executive buy-in, and limited expertise.

TAKEAWAYS:

  1. Inventory completeness (what, where, owner) becomes mandatory when lifecycles shrink to 47 days.
  2. Eliminating manual tracking reduces outage risk more effectively than relying on reminders and spreadsheets.
  3. Building an ROI case should emphasize avoided downtime and remediation labor, not just tooling costs.
  4. Integrating certificate management into DevOps pipelines is the top near-term improvement priority.
  5. Addressing “very/extremely concerned” areas requires lifecycle-wide automation across clouds, platforms, and compliance workflows.

How to level up from security pro to security leader

Source: CSO Online

Author: unknown

URL: https://www.csoonline.com/article/4221303/how-to-level-up-from-security-pro-to-security-leader.html

ONE SENTENCE SUMMARY:

Aspiring CISOs must evolve from technical experts into business-focused leaders who communicate risk, influence stakeholders, build trust, and learn continuously.

MAIN POINTS:

  1. Translating technical risk into business priorities separates top CISOs from technical specialists.
  2. Employers prioritize communication skills, regulatory knowledge, and broad education over specific tools.
  3. Modern CISO expectations center on strategy and leadership, not daily hands-on security tasks.
  4. Trust-building requires collaboration without reverting to an “IT guy” posture.
  5. Professional presence means concise, confident communication and appropriate cultural fit.
  6. Cross-functional relationships enable influence across engineering, operations, legal, finance, and executives.
  7. Admitting mistakes and sharing lessons can strengthen credibility and leadership maturity.
  8. Business fluency comes from understanding revenue models, budgets, and organizational tradeoffs.
  9. Curiosity and learning are mandatory as AI agents, APIs, and machine identities expand.
  10. Mentorship and focusing on impact today matter more than rigid career-path scripting.

TAKEAWAYS:

  1. Develop an executive narrative that ties security decisions to outcomes leaders care about.
  2. Invest in political and partnership skills to drive shared accountability beyond formal authority.
  3. Build business competence through MBA alternatives like budgeting, product work, and risk roles.
  4. Seek diverse technical exposure to better govern emerging enterprise technologies.
  5. Use mentors and present authentic growth, prioritizing results over title-chasing.

Why Patch Automation Needs Brakes, Not Just an Accelerator

Source: BleepingComputer

Author: Sponsored by Action1

URL: https://www.bleepingcomputer.com/news/security/why-patch-automation-needs-brakes-not-just-an-accelerator/

ONE SENTENCE SUMMARY:

Software updates outpace IT capacity, so controlled patch automation using staged rings, defined success criteria, and human oversight reduces risk.

MAIN POINTS:

  1. Update volume and vulnerability disclosures are rising faster than IT teams can evaluate.
  2. Staffing constraints and complex environments cause patch backlogs and risky deployment trade-offs.
  3. Compressed testing and skipped reviews increase chances of outages or insecure exposure windows.
  4. Automation can rapidly spread failures if speed becomes the primary metric.
  5. Effective patch automation requires “brakes” to control progression, timing, and stop conditions.
  6. Test labs help but cannot mirror diverse production configurations and behaviors.
  7. Controlled production validation using staged deployment better reflects real-world conditions.
  8. Establish upfront success definitions: install success, endpoint health, app functionality, acceptable failure rates.
  9. Update rings enable gradual rollout governed by predefined criteria, reducing ad-hoc human decisions.
  10. Human involvement remains essential for business-critical systems while routine decisions get automated.

TAKEAWAYS:

  1. Treat speed as secondary to safety by pairing automation with enforceable deployment controls.
  2. Implement staged rollouts that automatically advance or halt based on measurable outcomes.
  3. Formalize what “success” means before deploying, then monitor continuously against those baselines.
  4. Reserve manual approvals and expert judgment for high-impact systems and exceptions.
  5. Aim for consistent, controlled automation first, then optimize for faster patching over time.

Microsoft releases emergency Windows updates to fix RDS failures

Source: BleepingComputer

Author: Lawrence Abrams

URL: https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-windows-updates-to-fix-rds-failures/

ONE SENTENCE SUMMARY:

Microsoft issued out-of-band Windows updates to fix September 2026 security-update regressions breaking RDS, plus Hyper-V and USB audio issues.

MAIN POINTS:

  1. September 2026 security updates destabilized Remote Desktop Services, causing RDP sign-in and connection failures.
  2. Some impacted servers became unresponsive, indicating severe service disruption beyond simple login issues.
  3. Related tools like MMC, Licensing Diagnoser, File Explorer, and Windows Update could hang.
  4. Out-of-band fixes shipped September 14 to remediate the introduced regressions.
  5. Windows Server 2025 failures traced to KB5122871; Windows Server 2022 issues tied to KB5122882.
  6. Temporary mitigations were previously provided via Group Policy while engineering developed permanent patches.
  7. Uninstalling September updates restored Remote Desktop, but removed included security protections.
  8. Windows 11 26H1 KB5129194 is distributed via WU, WUfB, Catalog, and WSUS.
  9. Server out-of-band updates for 2022/2025 are offered through the Microsoft Update Catalog only.
  10. Additional OOB updates include KB5129195 (Win11 24H2/25H2) and KB5129236 (Win10 21H2/22H2).

TAKEAWAYS:

  1. Treat Patch Tuesday deployments cautiously; critical regressions can break core remote administration paths.
  2. Use Microsoft’s out-of-band patches rather than rolling back security updates when feasible.
  3. Validate RDS plus management tooling after updates, not just RDP connectivity.
  4. Hyper-V Plan9 shared-folder issues and multichannel USB audio failures are also addressed in Windows 11 OOB updates.
  5. Remaining USB Audio Class 1.0 “Code 10/no audio” problems persist, with a future fix pending.

CQURE Hacks #82: Microsoft Entra ID Conditional Access Bypass via User-Agent Policy Gap

Source: CQURE Academy

Author: Asia

URL: https://cqureacademy.com/blog/cqure-hacks-82-microsoft-entra-id-conditional-access-bypass-via-user-agent-policy-gap/

ONE SENTENCE SUMMARY:

A User-Agent–based Conditional Access gap enabled Xbox token issuance without MFA, leading to Graph access, secret discovery, and full tenant compromise.

MAIN POINTS:

  1. Conditional Access trusted device platforms based solely on client-controlled User-Agent strings.
  2. Policies blocked Windows, Linux, and iPhone, but overlooked Xbox Series X.
  3. Xbox User-Agent allowed Microsoft Graph token acquisition without triggering MFA.
  4. Obtained access token enabled direct Graph API access despite portal restrictions.
  5. GraphRunner enumerated users, groups, and roles through Microsoft Graph.
  6. Portal blocking proved ineffective because underlying APIs remained accessible.
  7. Custom scripting searched directory objects for exposed credentials and secrets.
  8. A clear-text password was found stored in a group description attribute.
  9. Exposed credentials belonged to a break-glass Global Administrator account.
  10. Chaining policy gaps with poor secret storage resulted in full tenant compromise.

TAKEAWAYS:

  1. Expand Conditional Access coverage to include Graph/API token acquisition flows.
  2. Avoid security decisions based on manipulable client signals like User-Agent.
  3. Enforce MFA consistently across all sensitive access paths, not just portals.
  4. Prevent secrets from being stored in readable directory attributes and descriptions.
  5. Assume attackers will chain minor misconfigurations into high-impact compromises.

Update your firewall rules: Teams and Copilot are changing address

Source: CSO Online

Author: unknown

URL: https://www.computerworld.com/article/4221272/teams-and-copilot-are-changing-addresses-update-your-firewalls.html

ONE SENTENCE SUMMARY:

Microsoft will redirect M365 and Teams web traffic to new cloud.microsoft domains, requiring enterprises to update controls by October.

MAIN POINTS:

  1. Redirects will send M365 web users to copilot.cloud.microsoft starting this month.
  2. Teams web users are being redirected to teams.cloud.microsoft already.
  3. Microsoft announced changes via MessageCenter posts MC1465764 and MC1462915.
  4. Organizations must update systems and documentation to preserve user access.
  5. Client device configurations should be reviewed for compatibility with new destinations.
  6. Proxies, firewalls, and secure web gateways may need rule adjustments.
  7. Enterprise network controls must allow connections to the new addresses.
  8. Troubleshooting should reference Microsoft 365 Copilot network requirement guidance.
  9. TenantRestrictions can replace blocking copilot.cloud.microsoft to limit personal account access.
  10. Limited Teams redirect exceptions may continue until December 31, 2026.

TAKEAWAYS:

  1. Change management is needed to prevent service disruption from domain redirects.
  2. Network security tooling should be validated against updated Microsoft endpoint destinations.
  3. Policy-based tenant controls are preferred over blunt domain blocking for account restrictions.
  4. Early October is the target completion date; support is available through account representatives.
  5. Long-term planning must assume Teams exceptions end permanently after the 2026 deadline.

GitLab urges users to patch max severity path traversal flaw

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/

ONE SENTENCE SUMMARY:

GitLab released urgent patches for critical path traversal and deserialization flaws, warning self-managed users to upgrade immediately to prevent sensitive data exposure.

MAIN POINTS:

  1. Maximum-severity path traversal vulnerability tracked as CVE-2023-2825 prompted immediate patching guidance.
  2. Researcher “s3ntago” reported the issue via GitLab’s HackerOne bug bounty program.
  3. Root cause involves improper path confinement and missing authentication in repository commits API.
  4. Unauthenticated attackers could read arbitrary files from vulnerable GitLab servers under conditions.
  5. Second critical flaw, CVE-2026-87719, involves insecure deserialization in GraphQL subscription serializer.
  6. CVE-2026-87719 impacts GitLab EE and requires authenticated Duo Chat access.
  7. Exploitation could expose sensitive credentials and Advanced Search instance configurations.
  8. Fixes shipped in GitLab CE/EE versions 19.3.2, 19.2.6, and 19.1.x releases.
  9. GitLab.com already runs patched code; GitLab Dedicated customers need no action.
  10. CISA has listed multiple GitLab vulnerabilities as exploited since 2021, underscoring active risk.

TAKEAWAYS:

  1. Upgrade self-managed GitLab immediately to patched versions to reduce exposure windows.
  2. Enforce strong API authentication and path confinement to prevent traversal-style data leaks.
  3. Treat deserialization in GraphQL-related components as high-risk and audit serializers rigorously.
  4. Monitor CISA exploited-vulnerability listings to prioritize patching and threat-informed remediation.
  5. Past GitLab security incidents show recurring attacker interest, requiring continuous vulnerability management.

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html

ONE SENTENCE SUMMARY:

Wiz found many exposed LiteLLM gateways using default master keys, enabling credential theft, code execution, and urgent hardening upgrades needed.

MAIN POINTS:

  1. Scan found 3,074 Shodan-listed LiteLLM gateways; 294 accepted the example key.
  2. Of those 294, 191 had no master key set, accepting any value.
  3. Prior to 1.82.0-stable, missing master key granted full admin to all requests.
  4. Administrators can view stored model-provider API keys and all prompts/responses passing through.
  5. Pass-through endpoints allow SSRF to cloud instance metadata, exposing IAM credentials.
  6. IMDSv2 protections were bypassed using LiteLLM’s x-pass- header forwarding behavior.
  7. Maintainers classify misconfiguration-based attacks as out-of-scope; no CVE for metadata access.
  8. CVE-2026-59821 enabled container code execution via guardrail checks bypass pre-1.82.0-stable.
  9. CISA lists exploited CVE-2026-59822, enabling MCP access with trivial Bearer tokens.
  10. Mitigations include upgrading to 1.84.0+, blocking risky endpoints, and least-privilege cloud roles.

TAKEAWAYS:

  1. Replace sk-1234 with a long random master key and follow correct rotation procedure.
  2. Adopt LiteLLM 1.84.0 or later to cover all listed CVE fixes.
  3. Enforce outbound network restrictions and minimal IAM permissions to limit blast radius.
  4. Disable or proxy-block /mcp/, MCP test endpoints, and unsafe guardrail routes.
  5. Assume compromise if exposed: audit guardrails, restart services, and rotate provider/database credentials.

Threat matrix: Mapping threats across cloud web applications

Source: Microsoft Security Blog

Author: Microsoft Security Research and Lior Leizerovich

URL: https://www.microsoft.com/en-us/security/blog/2026/09/09/threat-matrix-mapping-threats-across-cloud-web-applications/

ONE SENTENCE SUMMARY:

Microsoft’s MITRE ATT&CK-aligned cloud web applications threat matrix maps techniques across app and cloud layers to prioritize defenses.

MAIN POINTS:

  1. Attack paths span code, runtimes, identities, pipelines, and connected cloud resources.
  2. Separate app-versus-cloud investigations create blind spots and missed adversary chaining opportunities.
  3. Matrix organizes cloud web app and serverless techniques by MITRE ATT&CK tactics.
  4. Subdomain takeover can occur from orphaned DNS pointing at reusable provider endpoints.
  5. Initial access includes app vulnerabilities, repo injections, compromised images, misconfigured admin interfaces, trigger abuse.
  6. Execution vectors include remote code execution exploits, cloud-native terminals, and malicious App Service extensions.
  7. Persistence occurs via scheduled jobs, source modification in canonical artifacts, and compromised valid accounts.
  8. Privilege escalation leverages app-stored secrets or workload identity tokens via metadata/identity endpoints.
  9. Defense evasion uses staging slots/aliases and disabling or manipulating cloud logging controls.
  10. Impact techniques include theft, destruction, defacement, resource hijacking, and denial-of-wallet cost abuse.

TAKEAWAYS:

  1. Prioritize MFA and least privilege for users, workloads, and deployment access paths.
  2. Lock down repositories, build systems, registries, and extensions to trusted sources only.
  3. Eliminate reusable secrets in code/config by using workload identities and proper secrets management.
  4. Centralize protected logging and prevent tampering to enable detection and incident reconstruction.
  5. Reduce blast radius with quotas, concurrency limits, cost guardrails, and tested backup recovery.

Is a Quantified Cyber Risk Number Defensible? The Inputs

Source: Rivial Security Blog

Author: Randy Lindberg

URL: https://www.rivialsecurity.com/blog/is-cyber-risk-quantification-defensible

ONE SENTENCE SUMMARY:

Defensible cyber risk quantification uses external breach data, ATT&CK scenarios, Monte Carlo loss curves, and validated controls to justify dollar figures.

MAIN POINTS:

  1. Security leaders often dismiss CRQ as guesses disguised as precise dollars.
  2. High/medium/low ratings also rely on subjective inputs but conceal assumptions.
  3. Quantified models can be defensible by transparently showing calculations and sources.
  4. Self-populated likelihood estimates merely reformat opinion and undermine board credibility.
  5. Independent breach datasets anchor incident frequency and cost baselines objectively.
  6. Organization specifics adjust baselines using systems, data types, records, and controls.
  7. MITRE ATT&CK grounds threat scenarios in observed adversary techniques across attack chains.
  8. Monte Carlo simulation models lognormal losses, capturing both expected loss and catastrophic tail risk.
  9. Interview-only control assessments weaken models; validation ties inputs to evidence and testing.
  10. Quantified, validated outputs support regulator scrutiny and enable cost-effective risk reduction decisions.

TAKEAWAYS:

  1. Replacing colors with dollars improves auditability because assumptions become inspectable.
  2. External, regularly updated research reduces bias in likelihood and impact estimation.
  3. ATT&CK-based scenarios increase credibility by using a widely accepted public framework.
  4. Simulation provides board-relevant views of tail losses, not just single expected values.
  5. Evidence-backed control effectiveness turns CRQ into actionable capital allocation and tolerance management.

Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”

Source: Tenable Blog

Author: Eric Doerr

URL: https://www.tenable.com/blog/tenable-one-claude-mythos-5-adversary-view-ai-exposure-management

ONE SENTENCE SUMMARY:

Tenable integrates Anthropic Claude Mythos 5 into Tenable One, enabling adversarial reasoning to prioritize vulnerability chains and disrupt attacks faster.

MAIN POINTS:

  1. Claude Mythos 5 will be embedded into the Tenable One Exposure Management Platform.
  2. Frontier adversarial reasoning helps defenders anticipate attacker paths across complex environments.
  3. Tenable One Adversary View is the first customer-facing capability, launching in coming weeks.
  4. Adversary View identifies hidden, viable vulnerability chains specific to each environment.
  5. Analysis uses raw scanner evidence beyond typical findings and rule-based detection.
  6. Inputs include connections, service enumeration, installed software, configurations, and plugin outputs.
  7. The Tenable agentic harness supplies context, validation, and controlled action around model reasoning.
  8. Workflow starts with scoping assets through a guided conversation in Tenable One.
  9. Output is ranked disruption actions with supporting evidence, not an expanded findings list.
  10. Recommendations can be executed via Tenable Hexa AI; no new deployment required.

TAKEAWAYS:

  1. Exposure management shifts from “find issues” to “understand exploit chains and fix order.”
  2. Low-signal artifacts can become high-impact risk when correlated across the environment.
  3. Attacker-perspective reasoning can reveal pathways no prewritten rule anticipated.
  4. Productizing frontier models requires contextual harnessing for safety, accuracy, and control.
  5. Tenable signals a broader roadmap of AI-powered exposure management beyond Adversary View.

Microsoft discloses two actively exploited zero-days among 974 vulnerabilities

Source: CyberScoop

Author: Matt Kapko

URL: https://cyberscoop.com/microsoft-patch-tuesday-september-2026/

ONE SENTENCE SUMMARY:

Microsoft’s record Patch Tuesday fixed 974 flaws, including two exploited privilege-escalation zero-days, urging risk-based prioritization amid AI-driven discovery.

MAIN POINTS:

  1. Microsoft patched 974 defects across its product suite in a single Patch Tuesday.
  2. Two zero-day vulnerabilities were actively exploited before public disclosure.
  3. AI-assisted vulnerability discovery is accelerating vulnerability identification and disclosures.
  4. Despite more disclosures, researchers haven’t observed a matching surge in active exploits.
  5. CVE-2026-81963 impacts the Windows Update Stack and enables privilege escalation.
  6. CVE-2026-85880 affects Windows Advanced Local Procedure Call with privilege escalation potential.
  7. Both exploited zero-days carry CVSS scores of 7.8.
  8. Over 10% of the month’s disclosed defects were rated critical.
  9. Patch counts included Windows 723, Office 111, Office 2016 111, SQL 62, tools 22.
  10. Experts recommend focusing on applicable, reachable, exploitable issues rather than totals.

TAKEAWAYS:

  1. Prioritize patches by exploitability, exposure, and business impact instead of raw vulnerability volume.
  2. Monitor for privilege-escalation vectors in core Windows components during emergency patch cycles.
  3. Large AI-driven disclosure “haystacks” require stronger triage and vulnerability management processes.
  4. Separate urgent fixes from routine updates to prevent operational overload and patching delays.
  5. Use vendor advisories like Microsoft’s Security Response Center to map updates to your environment.

Why Proofpoint Is Eyeing a Buy of Data Security Firm Varonis

Source: BankInfoSecurity.com RSS Syndication

Author: unknown

URL: https://www.bankinfosecurity.com/blogs/proofpoint-eyeing-buy-data-security-firm-varonis-p-4185

ONE SENTENCE SUMMARY:

Proofpoint is negotiating to buy Varonis to strengthen data security ahead of an IPO, while offering Varonis shareholders an exit.

MAIN POINTS:

  1. Recent cybersecurity IPOs often underperform, making private acquisitions more common after weak stock pops.
  2. Proofpoint, owned by Thoma Bravo, doubled ARR to $2.45B and nearly $1B EBITDA.
  3. The company expanded beyond email security into data and AI security via tuck-in acquisitions.
  4. Forrester rated Proofpoint’s data security platform weakest in 2025 due to limited controls and manageability.
  5. Varonis topped Forrester’s 2025 data security rankings and has two decades of focus.
  6. Bloomberg reported Proofpoint-Varonis acquisition talks, potentially announced within weeks near Protect 2026.
  7. A deal would be 2026’s largest pure-play cyber acquisition, exceeding Accenture’s planned Dragos purchase.
  8. Overlap includes DSPM plus discovery/classification; Proofpoint gained DSPM through buying Normalyze.
  9. Varonis adds access intelligence, activity monitoring, DDR, and UEBA; Proofpoint contributes AI security and DLP.
  10. Varonis stock lags post-renewal drop; SaaS revenue rose to 95.4% but losses widened.

TAKEAWAYS:

  1. Portfolio gaps in masking/tokenization and operational usability appear to be driving Proofpoint’s interest.
  2. Combining Varonis DDR/UEBA with Proofpoint DLP and AI protections could create a broader data security suite.
  3. Acquisition timing suggests Proofpoint wants a stronger data narrative before re-entering public markets.
  4. Market dynamics and Cyera’s rapid valuation growth pressure Varonis’s standalone public-market story.
  5. The transaction hinges on valuation agreement despite strategic fit and investor appetite for an exit.

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

Source: Tenable Blog

Author: Research Special Operations

URL: https://www.tenable.com/blog/microsofts-september-2026-patch-tuesday-addresses-964-cves-cve-2026-81963-cve-2026-85880

ONE SENTENCE SUMMARY:

Microsoft’s September 2026 Patch Tuesday fixed 964 CVEs, including two exploited zero-days, dominated by privilege escalation and major RCE risks.

MAIN POINTS:

  1. September 2026 release set a record with 964 patched vulnerabilities across Microsoft products.
  2. Severity breakdown included 104 Critical and 860 Important issues, with none Moderate/Low.
  3. Two zero-day vulnerabilities were exploited in the wild and patched this month.
  4. Elevation-of-privilege flaws comprised 44.7% of all fixed vulnerabilities.
  5. Remote code execution issues represented 26.8% of the patched vulnerabilities.
  6. CVE-2026-81963 abused Windows Update Stack link-following to gain SYSTEM privileges.
  7. CVE-2026-85880 targeted Windows ALPC to elevate privileges to SYSTEM as a zero-day.
  8. CVE-2026-69380 in Exchange allowed mailbox-to-mailbox access via missing authorization.
  9. CVE-2026-69525 enabled Remote Desktop Services RCE via use-after-free, exploitation more likely.
  10. CVE-2026-69730 let unauthenticated attackers achieve DNS Server RCE via crafted packets.

TAKEAWAYS:

  1. Prioritize patching for exploited EoP zero-days enabling SYSTEM-level compromise.
  2. Treat DNS Server RCE and RDP RCE vulnerabilities as urgent due to “more likely” exploitation.
  3. Review Exchange mailbox permission models to mitigate authorization-driven lateral email access.
  4. Focus remediation on privilege escalation categories, given their outsized share of fixes.
  5. Use vulnerability scanning to verify patch coverage and identify systems still exposed.

New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privileges

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/

ONE SENTENCE SUMMARY:

Researcher Nightmare Eclipse released FalconFlank, a CrowdStrike Falcon zero-day enabling SYSTEM privilege escalation on updated Windows, prompting mitigations and broader scrutiny.

MAIN POINTS:

  1. Anonymous researcher “Nightmare Eclipse” published a CrowdStrike Falcon zero-day exploit named FalconFlank.
  2. Exploit reportedly works on fully updated Windows 11 25H2 and Windows Server 2025.
  3. Vulnerability currently lacks a CVE assignment and remains under investigation.
  4. Attack abuses Falcon Sensor’s Office malicious macros remediation to gain SYSTEM privileges.
  5. Successful exploitation spawns a SYSTEM command prompt via a proof-of-concept technique.
  6. Researcher expects detections, suggesting exclusions or PoC obfuscation to test.
  7. CrowdStrike advised disabling the Office policy enabling File Suspicious Macro Removal.
  8. CrowdStrike stated Cloud Anti-malware for Office Files continues to protect customers.
  9. FalconFlank technical alert exists but is restricted to CrowdStrike support portal accounts.
  10. Kevin Beaumont verified released privilege-escalation exploits from Nightmare Eclipse function as claimed.

TAKEAWAYS:

  1. EDR/AV features that remediate Office macros can become privilege-escalation attack surfaces.
  2. Immediate mitigation centers on disabling the specific Office policy tied to macro removal.
  3. Vendor guidance and detailed advisories may be gated, complicating rapid public understanding.
  4. Multiple concurrent zero-days from one source increase operational risk across security stacks.
  5. Technique-level evaluation matters because credentialed post-compromise stages reduce prevention effectiveness.

Critical Citrix NetScaler auth bypass now leveraged in attacks

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/

ONE SENTENCE SUMMARY:

Attackers are probing Citrix NetScaler CVE-2026-19490 auth-bypass flaw; agencies urge urgent patching amid PoC-driven exploitation attempts worldwide.

MAIN POINTS:

  1. Previdian reports in-the-wild targeting of critical Citrix NetScaler vulnerability CVE-2026-19490.
  2. Flaw enables remote authentication bypass by unprivileged attackers under specific NetScaler configurations.
  3. Affected setups include AAA virtual server and Gateway modes like SSL VPN and ICA Proxy.
  4. Exploitability depends on firmware version and whether SAML Action is configured.
  5. Citrix patched the issue mid-August and urged immediate upgrades to recommended builds.
  6. Citrix advisory (Aug 19) did not yet confirm active exploitation.
  7. Credible PoC publication preceded observed exploitation-like requests, per researcher Ryan Dewhurst.
  8. NetScaler sensor saw matching PoC attempts from IPs in Australia, US, and Germany.
  9. Belgium’s NCC-BE also warned of exploitation attempts and prioritized patching guidance.
  10. Shadowserver observes 22,000+ ADC and 1,700+ Gateway instances exposed, patch status unknown.

TAKEAWAYS:

  1. Patch NetScaler appliances promptly, prioritizing AAA and Gateway deployments.
  2. Validate firmware and SAML-related configuration to determine actual exposure.
  3. Treat publicly released PoCs as immediate risk accelerants for mass scanning.
  4. Monitor for exploit-pattern requests, but distinguish attempts from confirmed compromises.
  5. Citrix NetScaler remains a recurring target, with multiple prior flaws quickly exploited.

Incident response guide for AWS CloudTrail investigations – Part 1

Source: AWS Security Blog

Author: Oscar Diaz

URL: https://aws.amazon.com/blogs/security/incident-response-guide-for-aws-cloudtrail-investigations-part-1/

ONE SENTENCE SUMMARY:

Guide teaches CloudTrail-based incident investigations, highlighting key fields, attacker patterns, and response checklists across cross-account S3 deletion and cryptomining scenarios.

MAIN POINTS:

  1. CloudTrail investigation hinges on interpreting specific fields, context, and event chains.
  2. Real-world scenarios cover cross-account unauthorized access, ransomware-like deletions, and console-driven cryptomining.
  3. Terminology glossary defines recon, enumeration, lateral movement, persistence, and other IR concepts.
  4. Scenario 1 starts with assumed-role activity performing S3 ListBuckets reconnaissance.
  5. Suspicious session naming can indicate masquerading to blend into normal automation noise.
  6. Listing objects followed by a silence gap suggests planning before rapid automated execution.
  7. S3 COPY operations before DELETE imply steal-then-destroy behavior and possible exfiltration.
  8. Tight deletion timing, consistent IP, and aws-cli user agent indicate scripted automation.
  9. Broad cross-account role permissions expose blast-radius risk without least-privilege and reviews.
  10. Scenario 2 shows CloudFormation abuse via console session and CloudShell, lacking MFA.

TAKEAWAYS:

  1. Prioritize containment by confirming ongoing access, sensitive exposure, and spread potential.
  2. Validate cross-account trust policies and role assumption paths to identify initial compromise.
  3. Correlate source IPs, session names, and user agents to uncover pivots and related actions.
  4. Treat cost anomalies as security signals; billing spikes can reveal resource hijacking early.
  5. Enforcing MFA for console access blocks many credential-abuse paths enabling rapid automation.

Incident response guide for AWS CloudTrail investigations – Part 2

Source: AWS Security Blog

Author: Oscar Diaz

URL: https://aws.amazon.com/blogs/security/incident-response-guide-for-aws-cloudtrail-investigations-part-2/

ONE SENTENCE SUMMARY:

An SSRF flaw stole IMDSv1 role credentials, enabling console access and cross-Region Amazon Bedrock misuse, shown through CloudTrail forensics analysis.

MAIN POINTS:

  1. Describes five-stage chain: SSRF, metadata credential theft, probing, pivoting, region hopping.
  2. CloudTrail CreateUser failure exposed webdev role and ec2RoleDelivery 1.0 indicating IMDSv1.
  3. ConsoleLogin success without MFA revealed interactive access from same source IP.
  4. ListFoundationModels in us-east-2 marked reconnaissance and intentional alternate Bedrock endpoint targeting.
  5. Converse invocation confirmed Amazon Nova Pro model abuse and token counts for cost estimation.
  6. Correlation hinges on consistent role ARN, session name instance ID, and sourceIPAddress.
  7. Key fields: userIdentity for attribution, readOnly for intent, awsRegion for evasion.
  8. Absence of userIdentity.invokedBy indicated direct credential use, not service-linked automation.
  9. Investigation prioritized role over-permissioning to Bedrock and searching other instances with same role.
  10. Response checklist includes fixing SSRF, enforcing IMDSv2, expanding multi-Region log queries and billing review.

TAKEAWAYS:

  1. Enforce IMDSv2 with hop-limit to neutralize SSRF-based metadata credential theft.
  2. Require MFA and restrict console sessions for workload roles to prevent interactive pivots.
  3. Standardize monitoring and controls across all Regions to reduce cross-Region blind spots.
  4. Enable Bedrock model invocation logging and telemetry to capture prompts, responses, and agent actions.
  5. Apply least-privilege policies and regularly analyze unused permissions to limit lateral movement.

Windows memory integrity switches on automatically for eligible devices in October 2026

Source: Help Net Security

Author: Anamarija Pogorelec

URL: https://www.helpnetsecurity.com/2026/09/03/windows-memory-integrity-update/

ONE SENTENCE SUMMARY:

Starting October 2026, Windows quality updates automatically enable VBS and memory integrity on eligible devices after readiness checks, preserving prior disablement choices.

MAIN POINTS:

  1. Windows quality updates begin enabling memory integrity automatically starting October 2026.
  2. Devices lacking Virtualization-based Security will have VBS enabled by those updates.
  3. Memory integrity allows only trusted kernel-mode code and drivers to run.
  4. Protection helps prevent attackers from compromising the Windows kernel and core OS functions.
  5. Deployment occurs via patches, shifting fleet security posture between update cycles.
  6. Previously disabled memory integrity settings and policies remain unchanged during rollout.
  7. Organizations can still configure and enable memory integrity using existing management tools.
  8. Windows evaluates hardware capabilities, compatibility, and performance before enabling protections.
  9. Microsoft acknowledges readiness checks may miss incompatible or unusual kernel drivers.
  10. Memory integrity is required to support hotpatch updates that install without rebooting.

TAKEAWAYS:

  1. Plan for a notable security baseline shift tied directly to routine patching cadence.
  2. Verify hardware and driver compatibility now to avoid surprises from eligibility gating.
  3. Keep governance intact: explicit disablement decisions won’t be overridden automatically.
  4. Treat uncommon kernel-level software as a special risk needing manual validation.
  5. Enabling memory integrity also unlocks rebootless hotpatch servicing benefits.