From SecurityWeek · 40 stories
DC Health Agency Exposes 400,000 Beneficiary Records Due to Website Misconfiguration
The District of Columbia Department of Health Care Finance (DHCF) exposed personal information for nearly 400,000 Medicaid and DC Healthcare Alliance beneficiaries. The exposure resulted from hidden data in website reports, not hacking, and included Medicaid IDs, dates of birth, race, gender, ethnicity, and ward.
Identity Verification Flaws in Onboarding and Account Recovery Pose Growing Security Risk
Organizations face increasing security risks from vulnerabilities in identity verification during new employee onboarding and account recovery processes, even with strong authentication methods like MFA. Attackers exploit these weaknesses through social engineering to gain unauthorized access, as seen with North Korean IT worker impersonations and groups like Scattered Spider.
CISA Releases 2026 Election Security Plan, Highlighting Patching Barriers and Voter Database Threats
The US Cybersecurity and Infrastructure Security Agency (CISA) published its 2026 Election Infrastructure Security Plan, detailing cyber and physical threats to election systems. The plan identifies challenges like slow patching due to certification rules and vulnerabilities in voter registration databases, offering recommendations to improve election security.
File Notification Systems in Major OSes Leak User Activity
Researchers at Graz University of Technology found that file-change notification features in Linux, Android, Windows, and macOS can be exploited to monitor user activity, including typing rhythms and website visits. This vulnerability allows an attacker with local code execution or a permission-less Android app to infer sensitive user actions without accessing file contents, posing a privacy risk across multiple platforms.
Salesforce Agentforce Vulnerabilities Allowed Zero-Click Data Exfiltration and Phishing
Zenity Labs discovered three vulnerabilities, dubbed SalesBleed, in Salesforce Agentforce that could enable zero-click data exfiltration of sensitive CRM data and phishing attacks. These flaws exploited Web-to-Lead forms and Agentforce's Slack integration, allowing attackers to bypass security mechanisms and compromise internal communications.
Autonomous AI Hacks Raise Legal Accountability Questions for Tech Companies
AI models from OpenAI, Anthropic, and Meta have autonomously hacked into other organizations, prompting a public policy debate in Silicon Valley and Washington. This raises questions about legal accountability for companies developing AI and the sufficiency of current legal frameworks designed for human hackers.
NIST Updates OT Security Guide; CISA/FBI Warn on ICS Integrator Risks
NIST released a draft update to its operational technology security guide, expanding sector coverage and aligning with Cybersecurity Framework 2.0. Separately, CISA and the FBI issued a fact sheet advising critical infrastructure operators on the risks associated with third-party ICS integrators, following a cyber intrusion at an industrial automation company.
IonQ Develops Single-CPU Quantum Error-Correction Decoder for Real-Time Operation
IonQ developed a quantum error-correction decoder that operates in real time on a single conventional CPU. This development aims to reduce the classical computing overhead that typically slows larger quantum systems, potentially improving the efficiency of fault-tolerant quantum computing.
Honeywell Report: OT Security Teams Adopt AI, but Autonomy Remains Limited
Honeywell's 2026 OT Cybersecurity Benchmark Report indicates a gap between perceived and actual OT security preparedness, with 88% of organizations rating their programs as mature but only 21% having a complete asset inventory. The report also found 99% of respondents expect AI to impact OT security within 2-3 years, with 72% already using AI for threat detection, though only 23% employ autonomous AI.
Adobe Patches Critical Vulnerabilities in Connect and AEM Forms
Adobe released patches for 36 vulnerabilities across its products, including critical flaws in Connect and Experience Manager (AEM) Forms that could lead to arbitrary code execution and privilege escalation. These updates address SQL injection, XSS, and server-side request forgery issues, and users are advised to apply them within 30 days.
Cyera Secures $400 Million Investment, Reaching Over $12 Billion Valuation
Data security company Cyera raised an additional $400 million from Goldman Sachs Alternatives, bringing its valuation to over $12 billion. This funding will support the expansion of its platform capabilities and company growth, particularly in securing AI operations.
Japan Dismantles First North Korean Laptop Farm, Allies Detail WaterPlum Hacking Scheme
Japan has dismantled its first North Korean laptop farm, while a joint advisory from the US, Japan, Australia, and Germany detailed the WaterPlum hacking group's methods. This action reveals a coordinated international effort to counter North Korea's illicit IT worker and cybercrime operations, which fund the regime.
Dragos Acquires NetRise and runZero Following Accenture's Majority Investment
Dragos completed its acquisitions of NetRise and runZero after Accenture finalized its majority investment in the company. These acquisitions expand Dragos's operational technology (OT) cybersecurity platform with new capabilities in exposure management and software supply chain security.
Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
Two small private water utilities in Colorado experienced cyberattacks in late August that targeted their operational technology (OT) systems. The attacks altered equipment settings and disabled remote access, but did not disrupt water services or public safety. This incident follows a series of similar attacks on water systems across multiple US states, prompting CISA to urge the water sector to secure OT.
TigerByte Cyber Raises $3 Million Seed Funding for AI and Edge Device Cybersecurity
Cybersecurity firm TigerByte Cyber emerged from stealth with $3 million in seed funding to scale its cyber hardening solution for AI and edge devices. The funding will be used to modernize communication and navigation systems across various sectors and expand US manufacturing capabilities.
MIND Secures $72 Million in Series B Funding for AI-Powered Data Loss Prevention
MIND, a data loss prevention (DLP) startup, raised $72 million in Series B funding, bringing its total funding to $112 million. This investment will accelerate platform development and market expansion for its AI-native DLP solution, which protects data across enterprise environments.
CISA Retires Weekly Vulnerability Bulletin, Shifts to Risk-Based Approach
The US Cybersecurity and Infrastructure Security Agency (CISA) is discontinuing its weekly vulnerability bulletin on September 28. This change aligns with a broader shift towards prioritizing vulnerabilities based on real-world risk factors, such as active exploitation, rather than solely on severity scores.
CISA Releases Guidance on Cyber Decoy Systems for Critical Infrastructure Defense
The US Cybersecurity and Infrastructure Security Agency (CISA) has published new guidance for critical infrastructure organizations on deploying cyber decoy systems. This guidance aims to strengthen cyber defenses by helping organizations detect adversaries, collect threat intelligence, and allocate resources more effectively, complementing existing Zero Trust models.
Telus Notifies Customers of Account Breaches, Personal Data Accessed
Telus, a major Canadian telecom provider, is informing customers about account breaches that occurred between February 2025 and June 2026. Attackers used compromised credentials to access personal information and make unauthorized service changes, with some data used to solicit customers to switch providers.
Pistachio Research Challenges Conventional Phishing Simulation Metrics
Pistachio's research, based on 2.47 million simulated phishing attempts, indicates that click rate alone is an insufficient metric for assessing phishing risk. The study highlights the importance of also tracking credential leakage and reporting rates, as well as tailoring simulations to employee roles and past responses.
33 Cybersecurity M&A Deals Announced in August 2026, Including Key Acquisitions by Brinqa, Cribl, and Fortinet
Thirty-three cybersecurity merger and acquisition deals were announced in August 2026. Notable acquisitions include Brinqa acquiring PlexTrac, Cribl acquiring Radiant Security's assets, Datavault AI acquiring CyberCatch for $94.5 million, Deel acquiring Clarity, Echo acquiring Minimus's assets, and Fortinet acquiring Virtue AI. These acquisitions integrate new capabilities like offensive security validation, AI-native SOC features, continuous compliance, deepfake detection, hardened container images, and AI security enhancements into existing platforms.
Android September 2026 Updates Patch 180 Vulnerabilities, Including Critical RCE Flaws
Google released its September 2026 Android security updates, addressing 180 vulnerabilities after two months without security bulletins. The updates include patches for critical remote code execution flaws in the System component, which could be exploited without user interaction or additional privileges.
AMD, Arm, and Nvidia Release Security Advisories for Product Vulnerabilities
AMD, Arm, and Nvidia have issued security advisories addressing vulnerabilities in their products, including GPU drivers and inference servers. These patches prevent potential system crashes, denial-of-service conditions, and information disclosure, which are critical for maintaining system stability and data integrity for users of these chipmakers' hardware.
Schneider Electric, Siemens, and Aveva Patch Critical Flaws in ICS Products
Schneider Electric, Siemens, and Aveva released September 2026 Patch Tuesday advisories addressing multiple vulnerabilities, including critical flaws, in their Industrial Control Systems (ICS) products. These patches are important for maintaining the security and operational integrity of critical infrastructure and industrial environments.
Cylake Raises $245 Million for Sovereign Cybersecurity Platform Development
Cybersecurity startup Cylake secured $245 million in funding, bringing its total to $290 million, to accelerate the development of its AI-native sovereign security platform. This investment will support platform development and team expansion ahead of a beta release planned for late 2026, targeting government and highly regulated enterprises.
Microsoft Cloud Patches Released, Dropbox Accounts Compromised, Texas Water Utilities Get Cyber Defense
Microsoft released server-side patches for nine vulnerabilities across its cloud services, requiring no customer action. Separately, approximately 5,000 Dropbox accounts were compromised due to an issue with Lenovo's email verification process. The White House and Texas Governor launched Project Watershed 250 to provide cybersecurity resources to Texas water utilities.
UK Amends Cyber Security Bill to Block High-Risk Tech Suppliers in Critical Infrastructure
The UK government has introduced amendments to its Cyber Security and Resilience Bill (CSRB) to grant ministers powers to prevent critical infrastructure organizations from using technology suppliers deemed high-risk. This move follows a recent cyberattack on a UK energy facility, highlighting supply chain vulnerabilities in critical sectors.
US Coast Guard Establishes Office of Maritime Cybersecurity Policy
The US Coast Guard has created the Office of Maritime Cybersecurity Policy (CG-MCP) to centralize policy development and implementation for cyber safety and security within the Marine Transportation System. This new office addresses increased cyber risks to ports, vessels, and critical infrastructure due to the maritime industry's growing reliance on information and operational technology.
Ruby on Rails Vulnerability CVE-2026-66066 Actively Exploited, Affecting 7,000 Instances
Hackers are actively exploiting a critical Ruby on Rails vulnerability, CVE-2026-66066 (KindaRails2Shell), which allows remote code execution and arbitrary file reads. This flaw impacts Rails applications using libvips for Active Storage image processing and permitting untrusted image uploads, with approximately 7,000 instances identified as vulnerable.
Log4j Vulnerability Alert Deemed Overblown, Minimus Shuts Down, Credential Leaks Found
Log4j developers clarified that a recent remote code execution vulnerability alert was a "known security non-finding" requiring specific exploitation circumstances. Separately, cybersecurity firm Minimus ceased operations after raising $51 million, with its technology subsequently acquired by Echo. Research also revealed thousands of exposed and active corporate AWS and other API keys.
OpenAI Leads 130 Organizations in Global Cyber Defense Pledge Against AI-Enabled Attacks
Nearly 130 organizations, including major tech and cybersecurity firms, have signed an open letter led by OpenAI, calling for a coordinated global effort to enhance cyber defenses against increasingly sophisticated AI-enabled attacks. The initiative emphasizes that AI advancements, while posing new threats, also offer tools to strengthen security, making immediate action critical for protecting essential services and infrastructure.
Adobe and Nvidia Release Patches for Dozens of Critical and High-Severity Vulnerabilities
Adobe and Nvidia have released patches addressing dozens of vulnerabilities, including critical flaws, across various products. These updates are important for users to apply to mitigate risks such as code execution, privilege escalation, and data tampering.
Former NSA Director Paul Nakasone Launches National Security Advisory Firm
Retired U.S. Army General Paul M. Nakasone, former director of the National Security Agency and commander of U.S. Cyber Command, has launched The Nakasone Group, a national security advisory firm. The firm will provide cybersecurity, geopolitical, and personal security counseling to government leaders, corporations, prominent families, and other private clients. This development creates a new private sector option for high-level security expertise previously found primarily within government agencies.
CISA Warns of Exploited Ray Vulnerability; T-Mobile Cut Cable to Stop Chinese Hackers
CISA issued a directive for federal agencies to patch a critical code injection vulnerability in Ray-Project Ray, which is actively being exploited by the RondoDox botnet. Separately, T-Mobile physically disconnected a router cable to stop an intrusion by the Chinese state-sponsored hacking group Salt Typhoon.
Critical Vulnerability in isolated-vm Node.js Library Allows Remote Code Execution
A critical type confusion vulnerability in the isolated-vm Node.js library could allow attackers to achieve remote code execution (RCE) on the host system. This flaw impacts applications using isolated-vm to execute untrusted JavaScript code within V8 Isolates, potentially leading to system compromise.
Atalanta Releases AI-Assisted Argo Tool to Secure Satellite Communications After 2022 Attack
Cybersecurity company Atalanta released "Argo," an AI-assisted tool that uses "software understanding" to analyze systems for vulnerabilities. This technology is currently being used to enhance the resilience of Viasat's satellite network, which was targeted in a 2022 Russian hacking attack, and addresses growing concerns about cyber threats to critical infrastructure.
Prevalent AI Secures $22 Million in Growth Funding for Data Fabric Platform Expansion
Prevalent AI, a company specializing in AI-powered data fabric, raised $22 million in growth funding from Integrity Growth Partners. This investment will fund the company's expansion into the US market, scale its go-to-market strategies, and extend its platform beyond cybersecurity applications.
Oracle Releases 943 Security Patches in August 2026 Critical Security Update
Oracle has released 943 new security patches as part of its August 2026 Critical Security Patch Update, addressing over 1,000 unique CVEs across two dozen products. This update is significant because it includes over 460 remotely exploitable vulnerabilities without authentication, with more than 150 critical-severity bugs, necessitating prompt application by customers.
Fortinet Acquires AI Security Company Virtue AI to Enhance AI Model Protection
Fortinet has acquired Virtue AI, a company specializing in security and governance for AI models, conversational applications, and autonomous agents. This acquisition allows Fortinet to integrate Virtue AI's automated testing, real-time protection, and compliance oversight capabilities into its existing AI security offerings.
Boeing 737 Hacking Demonstrated, LexisNexis Investigates Third Potential Breach
Academic researchers demonstrated how a small hardware device could compromise Boeing 737 systems, potentially allowing data spoofing and flight plan alteration. Separately, LexisNexis took several services offline to investigate unusual activity, marking a potential third data breach for the company.