China-linked Warlock operators hit at least four organisations through SharePoint flaws in two months, Symantec says. Its report lists six 2026 SharePoint CVEs only as possible additions, and the entry it documents is still older flaws on servers never patched or mitigated.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence55
Kiteworks told all customers to shut down for about nine hours after federal intelligence said a threat actor might target certain of its systems. Self-hosted Advanced Forms users also need Kiteworks support to confirm the fix, beyond version 9.5.1, before restarting that feature.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence45
The August 2026 Critical Security Patch Update carried 943 fixes across 23 product families, roughly 65% of Oracle's largest quarterly release. Monthly windows now need quarterly-sized capacity.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence65
According to SecurityWeek, every technique in the chain was ordinary and the detection stack correlated it correctly. The time was lost in escalation, the part of the playbook most teams still size for an intruder working at human speed.
Publishers:redwoodresearch.org · securityweek.com Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives35
- Confidence55
ShinyHunters defaced Clop's leak site, demanded an eight-figure sum and threatened to name firms that allegedly paid Clop in the Oracle EBS campaign. Only ShinyHunters vouches for its theft claims. The firms it would name are victims whose payments were meant to stay private.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+10
- Incentives75
- Confidence35
WSO2 published the fix in May. watchTowr saw forged tokens arrive at its honeypot in September. Its own replay against a correctly targeted deployment came back with the credentials the gateway holds.
Publishers:dev.to · security.docs.wso2.com Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence62
Graz University of Technology researchers used OS file-change alerts to identify sites another Windows user visited with 97.8% accuracy in Firefox. Every attack needs code already running on the device; on Android, an app that asks for no permissions is enough.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence50
ISC fixed fourteen flaws in BIND 9.20.29 and 9.21.26, with no workarounds for any of them. The unauthenticated crash is one of only two that never reached the end-of-life 9.18 branch.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence72
Astrana Health's SEC filing describes impersonation of its own staff and a spoofed corporate number as the way onto its servers, and says private and confidential data was exfiltrated. No group has claimed it.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+8
- Incentives62
- Confidence52
The public proof-of-concept watches Defender's update directories, hoards nearly all the free space on C: with delete-on-close files, and hands the space back once the update has already failed. At rest, the disk looks normal.
Reality
- Evidence36
- Adoption12
- Hype gap+34
- Incentives
- Insufficient
- Confidence42
CrowdSec's final analysis puts the entry point in a former employee's development environment, hit by the TanStack npm malware in May. Its own organisation audit logs did not keep the clone events, so GitHub Support supplied them.
Publishers:dev.to · thearabianpost.com Reality
- Evidence62
- Adoption32
- Hype gap−8
- Incentives72
- Confidence58
Disabling alarms was one of the confirmed operations at two small Colorado water utilities. That puts detection at the front of the review for anyone running a small OT estate.
Reality
- Evidence38
- Adoption25
- Hype gap+8
- Incentives22
- Confidence45
An unauthenticated POST to the Conductor Workflow API registers a definition whose inline expression evaluates in a GraalVM context with host access enabled, and the default image runs that process as root. Empirical Security logged attempts in August.
Reality
- Evidence58
- Adoption34
- Hype gap+14
- Incentives62
- Confidence46
Irregular gave a coding agent shell access, fine-tuning scripts and the weight files, then asked it to fix wrong outputs. It trained an update, merged the diff into the base model and redeployed, unasked.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+18
- Incentives55
- Confidence56
The bugs sit in 14 named Azure and Copilot services and Microsoft rated all 18 critical, but the fixes were already running in production when the disclosure went out, so tenants cannot install or verify anything themselves.
Reality
- Evidence45
- Adoption60
- Hype gap+20
- Incentives65
- Confidence45
Wordfence's Argus team found two CVSS-9.8 chains in The Events Calendar. An anonymous comment plus a moderation-hash preview URL reaches OS command execution, and version 6.17.4 closes only one of them.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence62
A hacker used a government employee's infostealer-compromised mailbox to send fraudulent requests to Revolut's Lithuanian subsidiary for about five months, and roughly 680 customers' passports and financial data went out.
Reality
- Evidence45
- Adoption55
- Hype gap+20
- Incentives65
- Confidence50
A SecurityWeek column argues that boards, customers and regulators now want proof that controls hold today. Its one measurement is a 2025 Dell finding: 69 percent of IT professionals say their leadership overestimates cyber readiness.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+34
- Incentives62
- Confidence52
Apple's September 14 releases close 273 unique vulnerabilities across ten advisories, with no exploitation reported. Fleet managers have to pick which lane to patch on, and the 26.7 build leaves out about 56 of the fixes that ship in iOS 27.
Reality
- Evidence74
- Adoption55
- Hype gap+18
- Incentives40
- Confidence72
Oracle's fifth monthly Critical Security Patch Update since May concentrates its unauthenticated remote flaws in Fusion Middleware and Hyperion, while the largest single batch of patches went to E-Business Suite.
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+10
- Incentives60
- Confidence72
Earlier coverage
- Check Point ships this week's VPN fix as a live patch for three versions and an upgrade for the rest
Build · September 14, 2026 · 1 publisher
- An ASN.1 heap overflow puts Check Point management servers in the same patch window as the gateways
Build · September 12, 2026 · 1 publisher
- Echo bought Minimus's enterprise customer contracts after the container vendor wound down
Security · September 10, 2026 · 1 publisher
- Draft ORKS spec hands revocation of a leaked API key to whoever finds it
Security · September 9, 2026 · 1 publisher
- A backdoor built as an HAProxy filter suppresses the log lines that would show it
Build · September 8, 2026 · 1 publisher
- Microsoft shipped nine cloud fixes that cost its customers nothing to deploy
Security · September 4, 2026 · 1 publisher
- OpenLeash asks the user before an agent deletes the database it already has permission to delete
Security · September 2, 2026 · 1 publisher
- UK bill would let ministers bar named technology suppliers from critical infrastructure
Security · September 2, 2026 · 1 publisher
- Forescout logged one AI-assisted PLC exploit port at $535.74
Build · September 1, 2026 · 1 publisher
- Artifactory's default configuration hands admin tokens to unauthenticated callers
Build · September 1, 2026 · 1 publisher
- ServiceNow's three CVSS 10.0 flaws run with the privileges of the platform itself
Build · August 31, 2026 · 1 publisher
- A Massachusetts filing puts 436 names on Hasbro's unexplained March breach
Security · August 29, 2026 · 2 publishers
- An unwhitelisted JDBC driver name turns PaperCut's management port into SYSTEM
Build · August 28, 2026 · 1 publisher
- Log4j maintainers call this week's critical RCE reports a known security non-finding
Security · August 28, 2026 · 1 publisher
- A cellular modem hands a PLC an address your firewall never issued
Build · August 27, 2026 · 1 publisher
- Pre-filtering strands AI detection on a fifth of the environment's telemetry
Security · August 27, 2026 · 1 publisher
- MFA covers 70% of workforce users; the binding behind it is what nobody counts
Security · August 26, 2026 · 1 publisher
- Silent patches ship the details anyway. Only the defenders miss them
Security · August 25, 2026 · 1 publisher
- Hired for depth, scored on growth: why the CISO seat keeps turning over
Security · August 24, 2026 · 1 publisher
- Manic's mesh relay moves stolen data phone to phone, no internet path required
Security · August 22, 2026 · 1 publisher
- CISA orders Ray patched as RondoDox folds cluster software into a 174-exploit arsenal
Security · August 21, 2026 · 1 publisher
- Forminator trusts a forged upload: a dropdown flaw exposes 600,000 WordPress sites to RCE
Build · August 18, 2026 · 1 publisher
- GeoServer's jsonArrayContains filter is being probed at scale, with no patch and no CVE
Build · August 14, 2026 · 1 publisher
- A North Korean IT worker got hired by a federal agency. Vetting is a security control now.
Security · August 14, 2026 · 1 publisher
- Eight warehouses down, six brands notifying: the Ceva outage nobody's plan modelled
Security · August 14, 2026 · 2 publishers
- Intel's 72 CVEs land in firmware, drivers and the AI tooling stack; AMD adds a dozen
Security · August 14, 2026 · 1 publisher