Source context

Why this day matters

  • Days after reports linked IDScan to a dark web database holding more than 153 million driver’s license scans, the identity verification company has confirmed hackers accessed customer data stored on its cloud platform.
  • chore(cmake): bump libs to `0.26.0-rc2` Pin `FALCOSECURITY_LIBS_VERSION` to the `0.26.0-rc2` tag, cut from the libs `release/0.26.x` branch. `DRIVER_VERSION` stays at `11.0.0-rc1+driver` (no driver changes since `0.26.0-rc1`).
Validated article intelligence

Enriched source records

Expand a row to inspect claims and citations

Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.

Luna-enriched source article · helpnetsecurity

Ubuntu 24.04.5 LTS release patches security bugs across ten flavors

Ubuntu 24.04.5 LTS installation media bundles security updates and fixes for high-severity bugs for the Noble Numbat release.

3 retained claims4 cited excerpts

Source published Sep 11, 2026, 4:07 AM UTC · Evidence retrieved Sep 11, 2026, 8:51 AM UTC

What happened

Ubuntu 24.04.5 LTS installation media bundles security updates and fixes for high-severity bugs for the Noble Numbat release. [1]

The point release applies beyond Ubuntu desktop and server editions: nine additional flavors also moved to version 24.04.5, including Kubuntu, Xubuntu, Ubuntu MATE, Ubuntu Studio, and Edubuntu. [3] [4]

Why it matters

Fresh installations using the updated media start with these corrections already included, reducing the updates normally required after setup. [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Canonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the “Noble Numbat” release.
  2. [2]
    Anyone installing fresh now gets those corrections baked in from the start, cutting the batch of updates that would normally follow setup.
  3. [3]
    The point release covers more than the desktop and server editions.
  4. [4]
    Nine other flavors, including Kubuntu, Xubuntu, Ubuntu MATE, Ubuntu Studio, and Edubuntu, also moved to version 24.04.5, each carrying its … More → The post Ubuntu 24.04.5 LTS release patches security bugs across ten flavors appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

AI is changing what Salesforce security needs to govern

Existing security and governance practices have largely focused on identities, permissions, access, configurations, and controls.

3 retained claims2 cited excerpts

Source published Sep 11, 2026, 4:30 AM UTC · Evidence retrieved Sep 11, 2026, 8:51 AM UTC

What happened

Existing security and governance practices have largely focused on identities, permissions, access, configurations, and controls. [1]

WithSecure’s paper says Salesforce environments also require organizations to understand the information they rely on, how trust extends across connected systems, what actions are performed, and what outcomes those actions produce. [2]

Why it matters

Interpretation: The supplied excerpt suggests that Salesforce security governance may need to address information, connected-system trust, actions, and outcomes in addition to conventional access controls. [1] [2]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Existing security and governance practices have largely focused on identities, permissions, access, configurations and controls.
  2. [2]
    WithSecure’s Navigating Trust in the Modern Salesforce Ecosystem paper says Salesforce environments also require organizations to understand what information they rely on, how trust extends across connected systems, what actions are performed and what outcomes those actions produce.

Read the original article →

Luna-enriched source article · helpnetsecurity

Building a ransomware decision tree before the call comes in

Kerri Shafer-Page, Arctic Wolf’s VP of Incident Response, discusses a ransomware decision tree in a Help Net Security video.

4 retained claims5 cited excerpts

Source published Sep 11, 2026, 5:30 AM UTC · Evidence retrieved Sep 11, 2026, 8:51 AM UTC

What happened

Kerri Shafer-Page, Arctic Wolf’s VP of Incident Response, discusses a ransomware decision tree in a Help Net Security video. [1]

The decision tree addresses four areas where decisions should be settled in advance, beginning with containment. [2]

The decision tree also addresses the extortion demand, including who is authorized to negotiate. [4] [5]

Why it matters

Containment decisions require someone who understands the network well enough to assess how taking a system offline could affect client data, a manufacturing line, or a website. [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    In this Help Net Security video, Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walks through the ransomware decision tree in this video.
  2. [2]
    She covers four areas where decisions need settling in advance, starting with containment.
  3. [3]
    Someone has to know the network well enough to judge what pulling a system offline does to client data, a manufacturing line, or a website.
  4. [4]
    Then comes the extortion demand.
  5. [5]
    Who is authorized to negotiate, and what is … More → The post Building a ransomware decision tree before the call comes in appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Getting a stranger’s phone kicked off the cellular network costs a few dollars

Researchers reported that a new, unopened Samsung Galaxy Z Fold 7 could not connect to its cellular network after they copied the identification number from its sealed box and reported the phone as lost to its carrier.

2 retained claims5 cited excerpts

Source published Sep 11, 2026, 6:00 AM UTC · Evidence retrieved Sep 11, 2026, 8:51 AM UTC

What happened

Researchers reported that a new, unopened Samsung Galaxy Z Fold 7 could not connect to its cellular network after they copied the identification number from its sealed box and reported the phone as lost to its carrier. [1] [2] [3] [4]

The team reported finding six weaknesses in the process, but the supplied excerpt truncates the description of those weaknesses. [5]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Researchers at Michigan State University and three partner schools bought a Samsung Galaxy Z Fold 7, copied the identification number printed on the sealed box, and reported the phone to its carrier as lost.
  2. [2]
    Then they opened the box and set the phone up the way a launch-day buyer would.
  3. [3]
    It would not connect.
  4. [4]
    The phone was new, unopened, and sitting on a lab bench the entire time.
  5. [5]
    The team found six weaknesses in the … More → The post Getting a stranger’s phone kicked off the cellular network costs a few dollars appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Automox Mitigation Worklets cut endpoint exposure to unpatchable flaws

Automox announced an AI-speed Mitigation Worklet Pipeline intended to automate mitigation for vulnerabilities associated with frontier-model AI.

4 retained claims4 cited excerpts

Source published Sep 11, 2026, 7:48 AM UTC · Evidence retrieved Sep 11, 2026, 8:51 AM UTC

What happened

Automox announced an AI-speed Mitigation Worklet Pipeline intended to automate mitigation for vulnerabilities associated with frontier-model AI. [1]

The announcement says the pipeline shortens the time from vulnerability disclosure to exposure mitigation from days or weeks to minutes or hours. [2]

Automox states that Worklets have mitigated risk across billions of policy runs and millions of endpoints since 2019. [3]

A Worklet is described as an automation that takes verifiable action on an endpoint. [4]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Automox has announced its AI-speed Mitigation Worklet Pipeline, which automates mitigation to reduce risk from the increased volume and velocity of frontier-model AI vulnerabilities.
  2. [2]
    Now the time from vulnerability disclosure to exposure mitigation is shortened from days or weeks to minutes or hours.
  3. [3]
    Since 2019, Automox Worklets have mitigated risk across billions of policy runs and millions of endpoints.
  4. [4]
    A Worklet is an automation that takes verifiable action on an endpoint, whether that’s enforcing a … More → The post Automox Mitigation Worklets cut endpoint exposure to unpatchable flaws appeared first on Help Net Security .

Read the original article →

Luna-enriched source article · helpnetsecurity

Kiteworks expands runtime data governance with Bonfy.AI acquisition

Kiteworks acquired Bonfy.AI to extend runtime data governance across its control plane.

4 retained claims4 cited excerpts

Source published Sep 11, 2026, 8:04 AM UTC · Evidence retrieved Sep 11, 2026, 8:51 AM UTC

What happened

Kiteworks acquired Bonfy.AI to extend runtime data governance across its control plane. [1]

The acquisition is described as enabling governance of data exchanges as they occur, including exchanges initiated by people, machines, or autonomous agents. [2]

Why it matters

The article characterizes the acquisition as addressing a structural gap in enterprise protection of sensitive data. [3]

Enterprises are described as having invested a decade in data discovery and posture management, creating inventories of sensitive data in their data stores. [4]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Kiteworks has acquired Bonfy.AI, extending runtime data governance across its control plane.
  2. [2]
    The acquisition enables organizations to govern data exchanges as they happen, whether initiated by a person, machine, or autonomous agent.
  3. [3]
    The acquisition addresses a structural gap in how enterprises protect sensitive data.
  4. [4]
    Enterprises have invested a decade in data discovery and posture management, building detailed inventories of the sensitive data that sits inside their data stores.

Read the original article →

Luna-enriched source article · helpnetsecurity

IDScan confirms breach after 153 million driver’s licenses leak on dark web

IDScan confirmed that hackers accessed customer data stored on its cloud platform after reports linked the company to a dark-web database containing more than 153 million driver’s-license scans.

3 retained claims3 cited excerpts

Source published Sep 11, 2026, 8:39 AM UTC · Evidence retrieved Sep 11, 2026, 8:51 AM UTC

What happened

IDScan confirmed that hackers accessed customer data stored on its cloud platform after reports linked the company to a dark-web database containing more than 153 million driver’s-license scans. [1]

IDScan processes identity checks for car-rental companies, retailers, and cannabis dispensaries. [2]

The company posted an incident notice on its website on September 4, stating that it had received information around September 1 indicating certain data may have been affected; the supplied text is truncated before completing the statement. [2] [3]

Cited source evidence

These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.

  1. [1]
    Days after reports linked IDScan to a dark web database holding more than 153 million driver’s license scans, the identity verification company has confirmed hackers accessed customer data stored on its cloud platform.
  2. [2]
    The Louisiana-based firm, which processes ID checks for car rental companies, retailers and cannabis dispensaries, posted a notice on its website September 4 acknowledging the incident.
  3. [3]
    “On or around September 1, 2026, IDScan.net received information indicating that certain data may have been … More → The post IDScan confirms breach after 153 million driver’s licenses leak on dark web appeared first on Help Net Security .

Read the original article →

Published records

Additional source records

Expand a row to inspect provenance
Material developments

0.45.0-rc2

Falcosecurity Falco Releases published a source item for review.

1 source recordAuthoritative source

What happened

Falcosecurity Falco Releases published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

  • 0.45.0-rc2 Falcosecurity Falco Releases · Published 2026-09-11T08:19:21Z · Retrieved Sep 11, 2026, 8:51 AM UTC

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Material developments

UK Council Attack Linked to Mass Exploitation of SonicWall Flaw

Securityaffairs published a source item for review.

1 source recordContext source

What happened

Securityaffairs published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Threat and risk signals

Companies may be measuring phishing resilience the wrong way

Helpnetsecurity published a source item for review.

1 source recordContext source

What happened

Helpnetsecurity published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

Conti ransomware gang member sentenced to 4 years in prison

Bleepingcomputer published a source item for review.

1 source recordContext source

What happened

Bleepingcomputer published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.

Incidents and exposure

New infosec products of the week: September 11, 2026

Helpnetsecurity published a source item for review.

1 source recordContext source

What happened

Helpnetsecurity published a source item for review.

Why it matters

A reviewed impact interpretation has not been published for this record.

Reviewed next steps

  • Review the exact source item and determine whether it changes exposure or monitoring priorities.

Evidence

Known limitation

This item is supported by one source record and has not been independently corroborated here.