- UK government rolls out passkeys to 20 million users
- Phishing-resistant authentication and replay resistance
- Passkey adoption, device security, and user acceptance
- EU Cyber Resilience Act guidance, scope, and compliance
- CRA vulnerability disclosure and reporting requirements
- The real cost of cyberattacks and cybersecurity spending
- Cyber insurance and improving organizational security
- Nightmare Eclipse and the release of Windows zero-days
- Check Point VPN vulnerabilities and perimeter security
- GitLab security updates and shadow IT
- Discovering unmanaged GitLab instances
- Cyberattacks against oil tankers and insider threats
- VPN patching and implied rules
- Zero-downtime GitLab updates and version management
- Running Windows ARM on Apple Silicon with VMware and Parallels
- Attackers aren’t breaking in, they’re logging in. MFA fatigue, token theft, and lateral movement through identity are real problems in modern environments.So how do you catch it?At the Identity Virtual Cybersecurity Summit on September 30th, learn how to detect identity-based attacks, reduce privilege sprawl, and improve visibility across your environment.Security Weekly listeners can register for free at https://securityweekly.com/identity using the promo code: CSS26-SW
- AI is changing financial services fast. Join us December 9 in New York City for the Financial Services AI Security Forum, where industry leaders will tackle AI security, risk, fraud, governance, and resilience. Register by October 2 and save $400. Tickets are just $195, so secure your seat today at securityweekly.com/aiforum2026
Larry Pesce
- International Cyber Digest (@IntCyberDigest) on X
- Cops Search Thousands of Flock Cameras for Reasons of ‘LMAO,’ ‘IDK,’ ‘Hehe,’ and ‘asdfg’
- Cops Searched Thousands of Flock Cameras for Reasons of ‘LMAO,’ ‘IDK,’ ‘Hehe,’ And ‘Asdfg’ – Slashdot
- InjectEave: Eavesdropping on Headphones by Injecting a Carrier and Listening to the Modulated Retransmission
- Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
- Critical ScreenConnect flaw now actively exploited in attacks
- Cyber-Attacks Cost Organizations $52,000 on Average
- Coast Guard, FBI investigating after 2 oil tankers bound for US hit with cyberattacks: Sources
- Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) – Help Net Security
- Google says some Pixel phone owners were hacked in zero-day attacks
- International Meteor Organization says cyberattack dealt ‘critical blow’ to website
- CISA Adds One Known Exploited Vulnerability to Catalog
Lee Neely
- Check Point Patches Critical VPN Vulnerabilities
Summary: Cybersecurity firm Check Point this week announced patches for two critical-severity vulnerabilities in its gateway and firewall products using VPN functionality. Tracked as CVE-2026-85102 and CVE-2026-85103 (CVSS score of 9.8), both security defects could be exploited without authentication for remote code execution (RCE), Check Point warns.
Lee's Take: Here we go, another unauthenticated RCE exploit. This time on your VPN gateway, which was already a target. CVE-2026-85102 impacts Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN, CVE-2026-85103 impacts the Check Point Security Management Server, Security Gateway and Spark Firewall. In addition to applying the update, if you're using a Site to Site VPN, you'll want to disable implied rules for VPN and manually define access for UDP/500 & UDP/4500 to specific peer IP addresses. Make sure that you have Check Point LivePatch enabled to get patches automatically.
- More JFrog Artifactory bugs under attack, and all 3 have patches
Summary: JFrog Artifactory instances continue to get hit hard. Multiple attackers are exploiting three JFrog Artifactory bugs to gain administrative control over vulnerable instances - in some cases, just days after the vendor published a patch - and then using this illicit access to install malicious plugins and backdoors.
Lee's Take: There are patches for these flaws. Even so, about half the organizations with JFrog instances remain unpatched. The flaws can be remotely exploited without authentication. Exploiting an Artifactory zero-dayflaw was how the OpenAI model broke out of their cages to attack Hugging Face back in July. Use this, as well as the KEV information, to get the go-ahead on patching right away.
- ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
Summary: ConnectWise has released urgent patches for a critical-severity vulnerability in the ScreenConnect remote access and support software that has been exploited in worm-like attacks. Tracked as CVE-2026-84869 (CVSS score of 9.9/10), the security defect is described as a missing authorization and improper privilege management issue.
Lee's Take: Short version: Update your ScreenConnect server to 26.6.5 then reinstall your host clients and update your access agents, both of which can be done centrally. If you're on the cloud service, you still need to reinstall the host clients and update access agents. The attackers are using social engineering to trick victims into executing rogue ScreenConnect clients, including VBScript files which establish persistence, then check for active sessions to propagate them to other SreenConnect clients. Don't forget to hunt for the IOCs, they're in the Huntress blog: https://www.huntress.com/blog/rogue-screenconnect-installations
- UK Government Login Rolls Out Passkeys to 23M+ Users
Summary: The UK government's Department for Digital, Culture, Media and Sport (DCMS) has announced that passkeys will now be available as an authentication option for the more than 23 million users of GOV.UK One Login, the national identity verification system for government services. This rollout follows a trial period during which over 300,000 users successfully adopted passkeys. Currently almost 10% of GOV.UK One Login users already employ passkeys — in the form of a fingerprint, face ID, or device PIN — and the DCMS press release notes that the current adoption of passkeys is already "sav[ing] the British taxpayer nearly £600 a day in SMS costs."
Lee's Take: Bravo UK One Login! If you've not played with passkeys, you need to. Think of phishing resistant MFA without the SMS risks. When an application offers one, accept it, adding it to the appropriate wallet, then login with it. Learn what happens when you switch devices, or use a password manager for cross-device access. The goal is to be ready to tell your users they can successfully adopt Passkeys as well as build support for implementation/roll-out in your shop.
- Watch what you say: Apple opens the door to a nightmare world of always-listening tech
Summary: The Apple Watch Series 12 and Apple Watch Ultra 4 will include new features that continuously process ambient sounds and conversations when active. Live Rewind activates when the user double-presses the crown, displaying a transcript of the last 15 seconds audible to the watch, and Siri Recap produces a distilled written summary of all conversations heard throughout the day. Important sounds and music will also be automatically identified without prompting. Apple notes that each feature is opt-in, and that "these features do not create or store audio recordings, and raw audio used for processing is completely inaccessible to the operating systems, apps, the user, or Apple. This is because the S11 chip on Apple Watch Series 12 includes Secure Exclave, a dedicated hardware-isolated compartment that processes audio in complete isolation from the rest of the system, then immediately deletes it."
Lee's Take: Not going to throw Apple under the bus here, they appear to be taking steps to limit what is captured and how it's stored. But it's a good time to consider, especially in a business environment, all electronics with microphones, from smart-watches and phones to TV's and digital assistants, to be listening, recording and processing full time. Then asses the risks of having them in the presence of sensitive conversations. Be sure to differentiate recordings where you're controlling the distribution and storage and these ad-hoc scenarios. Think of someone with an unreported tape recorder in a meeting. Provide appropriate guidance and policy, with some teeth, don't assume people will do the right thing.
- Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023
Summary: The federal government wants financial institutions to be more vigilant in spotting and reporting schemes perpetrated by overseas scam centers. The Treasury Department’s Financial Crimes Enforcement Network (FinCEN) released an alert to the financial industry alongside a comprehensive study of more than 33,000 cyber fraud incident reports filed between September 2023 and December 2025.
Lee's Take: The cryptocurrency scams seem to be spread across all age groups, essentially tricking victims into transferring large sums of money from their retirement or other savings plans to them for fictional digital assets or property then returned posing as investment recovery services, it was their charging a fee for recovery which caused victims to realize they were being scammed. Treasury is seeking reporting from all financial institutions, banks, credit unions and non-traditional. If you're using cryptocurrency, make sure that you know what's behind it; things get really dicey when you're working with an organization which has been sanctioned by OFAC.
- Rapid Reaction: GitLab Path Traversal Vulnerability (CVE-2026-85706)
Summary: On September 10, 2026, GitLab released versions 19.3.2, 19.2.6, and 19.1.8 for GitLab Community Edition and Enterprise Edition. The release addresses a critical path traversal vulnerability tracked as CVE-2026-85706, affecting the repository commits API. GitLab assigned this issue a CVSS score of 10.0.
Lee's Take: The update can be applied with zero downtime in a multi-node instance. Focus on getting to version 19.3.2, there are a lot of other bug fixes you're going to want to leverage there. Make sure that you've identified all the self-hosted GitLab instances in your environment and that they all were updated, check their access logs on the repository commits API for any unauthorized activity which may indicate probing or exploitation attempts.
- Commission publishes new guidance to support timely Cyber Resilience Act implementation
Summary: Vulnerability reporting obligations under the European Union's Cyber Resilience Act (CRA) took effect last week. As of Friday, September 11, 2026, companies selling products that include digital elements in the European Union must now submit initial reports of actively exploited vulnerabilities through the European Union Agency for Cybersecurity's (ENISA's) Single Reporting Platform (SRP) within 24 hours of learning of those vulnerabilities; the covered entities must submit more detailed information within 72 hours. Earlier this summer, the European Commission "published practical guidance to help manufacturers, developers, and businesses of all sizes meet their obligations under the Cyber Resilience Act."
Lee's Take: he CRA is broad in coverage, meaning it covers anything digital sold in the EU, from baby-monitors to smart watches, applications, connectable hardware and software. The purpose was to raise the bar on digital product security, to include timely security updates, support periods, guidance on modifications and aid consumers in setting products up securely as well as make it easier to identify hardware and software with appropriate security features. Compliant products will have the CE marking. With the broad applicability of the CRA, you should read the document to understand how it may apply to you, even if you're just providing open-source software others use. The guidance, which is 84 pages, provides detailed information and examples, even so, you want to pace yourself. There is a lot to digest here, you're going to want to read it a couple of times. Start getting processes, reporting, etc. setup now, it'll be December 11th 2027 before you know it.
Sam Bowne
- Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key
LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential.
- Hackers abused Claude to extract secrets from 1.8M Android apps
Attackers mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog. In 34 hours, they found more than 2,100 sets of Azure AD authentication tokens linked to over 40 separate corporate Microsoft tenants.
- Uncensor any LLM with abliteration
This article is two years old, but I think it's important to point out now that there is serious discussion of AI risks and regulations. Open-source models can't have meaningful guardrails, because it is very easy to remove them. This is an argument in favor of closed-source models like Claude and ChatGPT which only provide API access to them, not the ability to view and modify their internal operations.
- Anthropic Reveals Rogue AI Agents Hate CAPTCHAs
The agent had a hard time with the technical challenge of seeing the CAPTCHA's imagery, interpreting correctly, and clicking on the right choices. It spent 150 pages of thinking solving the CAPTCHA, so they are still useful at slowing down bots.
- Anthropic Reveals Rogue AI Agents Hate CAPTCHAs
The agent had a hard time with the technical challenge of seeing the CAPTCHA's imagery, interpreting correctly, and clicking on the right choices. It spent 150 pages of thinking solving the CAPTCHA, so they are still useful at slowing down bots.
- Anthropic Reveals Rogue AI Agents Hate CAPTCHAs
The agent had a hard time with the technical challenge of seeing the CAPTCHA's imagery, interpreting correctly, and clicking on the right choices. It spent 150 pages of thinking solving the CAPTCHA, so they are still useful at slowing down bots.
- Misconfigured security tools are putting virtually every organization at risk
97% of organizations suffered a breach or near miss linked to security tool misconfigurations in the past year. Firewalls emerged as the most common source of these vulnerabilities at 42%, followed closely by endpoints at 40%.
- IonQ Publishes World’s First Fully Compiled, End-to-End Blueprint for Breaking 256-Bit Elliptic-Curve Signatures
A 20,000-physical-qubit IonQ quantum computer is expected to break secp256k1, the 256-bit elliptic curve used by blockchain technology such as Bitcoin, in just under 26 days. We are on track to produce our fully fault tolerant 10,000 physical qubit system in 2027.