September 11, 2026
Why this day matters
- Days after reports linked IDScan to a dark web database holding more than 153 million driver’s license scans, the identity verification company has confirmed hackers accessed customer data stored on its cloud platform.
- chore(cmake): bump libs to `0.26.0-rc2` Pin `FALCOSECURITY_LIBS_VERSION` to the `0.26.0-rc2` tag, cut from the libs `release/0.26.x` branch. `DRIVER_VERSION` stays at `11.0.0-rc1+driver` (no driver changes since `0.26.0-rc1`).
Enriched source records
Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.
Luna-enriched source article · helpnetsecurityUbuntu 24.04.5 LTS release patches security bugs across ten flavors
Ubuntu 24.04.5 LTS installation media bundles security updates and fixes for high-severity bugs for the Noble Numbat release.
Ubuntu 24.04.5 LTS release patches security bugs across ten flavors
Ubuntu 24.04.5 LTS installation media bundles security updates and fixes for high-severity bugs for the Noble Numbat release.
Source published Sep 11, 2026, 4:07 AM UTC · Evidence retrieved Sep 11, 2026, 8:51 AM UTC
What happened
Ubuntu 24.04.5 LTS installation media bundles security updates and fixes for high-severity bugs for the Noble Numbat release. [1]
The point release applies beyond Ubuntu desktop and server editions: nine additional flavors also moved to version 24.04.5, including Kubuntu, Xubuntu, Ubuntu MATE, Ubuntu Studio, and Edubuntu. [3] [4]
Why it matters
Fresh installations using the updated media start with these corrections already included, reducing the updates normally required after setup. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Canonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the “Noble Numbat” release.
- [2]
Anyone installing fresh now gets those corrections baked in from the start, cutting the batch of updates that would normally follow setup.
- [3]
The point release covers more than the desktop and server editions.
- [4]
Nine other flavors, including Kubuntu, Xubuntu, Ubuntu MATE, Ubuntu Studio, and Edubuntu, also moved to version 24.04.5, each carrying its … More → The post Ubuntu 24.04.5 LTS release patches security bugs across ten flavors appeared first on Help Net Security .
Luna-enriched source article · helpnetsecurityAI is changing what Salesforce security needs to govern
Existing security and governance practices have largely focused on identities, permissions, access, configurations, and controls.
AI is changing what Salesforce security needs to govern
Existing security and governance practices have largely focused on identities, permissions, access, configurations, and controls.
Source published Sep 11, 2026, 4:30 AM UTC · Evidence retrieved Sep 11, 2026, 8:51 AM UTC
What happened
Existing security and governance practices have largely focused on identities, permissions, access, configurations, and controls. [1]
WithSecure’s paper says Salesforce environments also require organizations to understand the information they rely on, how trust extends across connected systems, what actions are performed, and what outcomes those actions produce. [2]
Why it matters
Interpretation: The supplied excerpt suggests that Salesforce security governance may need to address information, connected-system trust, actions, and outcomes in addition to conventional access controls. [1] [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Existing security and governance practices have largely focused on identities, permissions, access, configurations and controls.
- [2]
WithSecure’s Navigating Trust in the Modern Salesforce Ecosystem paper says Salesforce environments also require organizations to understand what information they rely on, how trust extends across connected systems, what actions are performed and what outcomes those actions produce.
Luna-enriched source article · helpnetsecurityBuilding a ransomware decision tree before the call comes in
Kerri Shafer-Page, Arctic Wolf’s VP of Incident Response, discusses a ransomware decision tree in a Help Net Security video.
Building a ransomware decision tree before the call comes in
Kerri Shafer-Page, Arctic Wolf’s VP of Incident Response, discusses a ransomware decision tree in a Help Net Security video.
Source published Sep 11, 2026, 5:30 AM UTC · Evidence retrieved Sep 11, 2026, 8:51 AM UTC
What happened
Kerri Shafer-Page, Arctic Wolf’s VP of Incident Response, discusses a ransomware decision tree in a Help Net Security video. [1]
The decision tree addresses four areas where decisions should be settled in advance, beginning with containment. [2]
The decision tree also addresses the extortion demand, including who is authorized to negotiate. [4] [5]
Why it matters
Containment decisions require someone who understands the network well enough to assess how taking a system offline could affect client data, a manufacturing line, or a website. [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
In this Help Net Security video, Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walks through the ransomware decision tree in this video.
- [2]
She covers four areas where decisions need settling in advance, starting with containment.
- [3]
Someone has to know the network well enough to judge what pulling a system offline does to client data, a manufacturing line, or a website.
- [4]
Then comes the extortion demand.
- [5]
Who is authorized to negotiate, and what is … More → The post Building a ransomware decision tree before the call comes in appeared first on Help Net Security .
Luna-enriched source article · helpnetsecurityGetting a stranger’s phone kicked off the cellular network costs a few dollars
Researchers reported that a new, unopened Samsung Galaxy Z Fold 7 could not connect to its cellular network after they copied the identification number from its sealed box and reported the phone as lost to its carrier.
Getting a stranger’s phone kicked off the cellular network costs a few dollars
Researchers reported that a new, unopened Samsung Galaxy Z Fold 7 could not connect to its cellular network after they copied the identification number from its sealed box and reported the phone as lost to its carrier.
Source published Sep 11, 2026, 6:00 AM UTC · Evidence retrieved Sep 11, 2026, 8:51 AM UTC
What happened
Researchers reported that a new, unopened Samsung Galaxy Z Fold 7 could not connect to its cellular network after they copied the identification number from its sealed box and reported the phone as lost to its carrier. [1] [2] [3] [4]
The team reported finding six weaknesses in the process, but the supplied excerpt truncates the description of those weaknesses. [5]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Researchers at Michigan State University and three partner schools bought a Samsung Galaxy Z Fold 7, copied the identification number printed on the sealed box, and reported the phone to its carrier as lost.
- [2]
Then they opened the box and set the phone up the way a launch-day buyer would.
- [3]
It would not connect.
- [4]
The phone was new, unopened, and sitting on a lab bench the entire time.
- [5]
The team found six weaknesses in the … More → The post Getting a stranger’s phone kicked off the cellular network costs a few dollars appeared first on Help Net Security .
Luna-enriched source article · helpnetsecurityAutomox Mitigation Worklets cut endpoint exposure to unpatchable flaws
Automox announced an AI-speed Mitigation Worklet Pipeline intended to automate mitigation for vulnerabilities associated with frontier-model AI.
Automox Mitigation Worklets cut endpoint exposure to unpatchable flaws
Automox announced an AI-speed Mitigation Worklet Pipeline intended to automate mitigation for vulnerabilities associated with frontier-model AI.
Source published Sep 11, 2026, 7:48 AM UTC · Evidence retrieved Sep 11, 2026, 8:51 AM UTC
What happened
Automox announced an AI-speed Mitigation Worklet Pipeline intended to automate mitigation for vulnerabilities associated with frontier-model AI. [1]
The announcement says the pipeline shortens the time from vulnerability disclosure to exposure mitigation from days or weeks to minutes or hours. [2]
Automox states that Worklets have mitigated risk across billions of policy runs and millions of endpoints since 2019. [3]
A Worklet is described as an automation that takes verifiable action on an endpoint. [4]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Automox has announced its AI-speed Mitigation Worklet Pipeline, which automates mitigation to reduce risk from the increased volume and velocity of frontier-model AI vulnerabilities.
- [2]
Now the time from vulnerability disclosure to exposure mitigation is shortened from days or weeks to minutes or hours.
- [3]
Since 2019, Automox Worklets have mitigated risk across billions of policy runs and millions of endpoints.
- [4]
A Worklet is an automation that takes verifiable action on an endpoint, whether that’s enforcing a … More → The post Automox Mitigation Worklets cut endpoint exposure to unpatchable flaws appeared first on Help Net Security .
Luna-enriched source article · helpnetsecurityKiteworks expands runtime data governance with Bonfy.AI acquisition
Kiteworks acquired Bonfy.AI to extend runtime data governance across its control plane.
Kiteworks expands runtime data governance with Bonfy.AI acquisition
Kiteworks acquired Bonfy.AI to extend runtime data governance across its control plane.
Source published Sep 11, 2026, 8:04 AM UTC · Evidence retrieved Sep 11, 2026, 8:51 AM UTC
What happened
Kiteworks acquired Bonfy.AI to extend runtime data governance across its control plane. [1]
The acquisition is described as enabling governance of data exchanges as they occur, including exchanges initiated by people, machines, or autonomous agents. [2]
Why it matters
The article characterizes the acquisition as addressing a structural gap in enterprise protection of sensitive data. [3]
Enterprises are described as having invested a decade in data discovery and posture management, creating inventories of sensitive data in their data stores. [4]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Kiteworks has acquired Bonfy.AI, extending runtime data governance across its control plane.
- [2]
The acquisition enables organizations to govern data exchanges as they happen, whether initiated by a person, machine, or autonomous agent.
- [3]
The acquisition addresses a structural gap in how enterprises protect sensitive data.
- [4]
Enterprises have invested a decade in data discovery and posture management, building detailed inventories of the sensitive data that sits inside their data stores.
Luna-enriched source article · helpnetsecurityIDScan confirms breach after 153 million driver’s licenses leak on dark web
IDScan confirmed that hackers accessed customer data stored on its cloud platform after reports linked the company to a dark-web database containing more than 153 million driver’s-license scans.
IDScan confirms breach after 153 million driver’s licenses leak on dark web
IDScan confirmed that hackers accessed customer data stored on its cloud platform after reports linked the company to a dark-web database containing more than 153 million driver’s-license scans.
Source published Sep 11, 2026, 8:39 AM UTC · Evidence retrieved Sep 11, 2026, 8:51 AM UTC
What happened
IDScan confirmed that hackers accessed customer data stored on its cloud platform after reports linked the company to a dark-web database containing more than 153 million driver’s-license scans. [1]
IDScan processes identity checks for car-rental companies, retailers, and cannabis dispensaries. [2]
The company posted an incident notice on its website on September 4, stating that it had received information around September 1 indicating certain data may have been affected; the supplied text is truncated before completing the statement. [2] [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Days after reports linked IDScan to a dark web database holding more than 153 million driver’s license scans, the identity verification company has confirmed hackers accessed customer data stored on its cloud platform.
- [2]
The Louisiana-based firm, which processes ID checks for car rental companies, retailers and cannabis dispensaries, posted a notice on its website September 4 acknowledging the incident.
- [3]
“On or around September 1, 2026, IDScan.net received information indicating that certain data may have been … More → The post IDScan confirms breach after 153 million driver’s licenses leak on dark web appeared first on Help Net Security .
Additional source records
Material developments0.45.0-rc2
Falcosecurity Falco Releases published a source item for review.
0.45.0-rc2
Falcosecurity Falco Releases published a source item for review.
What happened
Falcosecurity Falco Releases published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- 0.45.0-rc2 Falcosecurity Falco Releases · Published 2026-09-11T08:19:21Z · Retrieved Sep 11, 2026, 8:51 AM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsUK Council Attack Linked to Mass Exploitation of SonicWall Flaw
Securityaffairs published a source item for review.
UK Council Attack Linked to Mass Exploitation of SonicWall Flaw
Securityaffairs published a source item for review.
What happened
Securityaffairs published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- UK Council Attack Linked to Mass Exploitation of SonicWall Flaw Securityaffairs · Published 2026-09-11T07:11:14Z · Retrieved Sep 11, 2026, 8:51 AM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsCompanies may be measuring phishing resilience the wrong way
Helpnetsecurity published a source item for review.
Companies may be measuring phishing resilience the wrong way
Helpnetsecurity published a source item for review.
What happened
Helpnetsecurity published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Companies may be measuring phishing resilience the wrong way Helpnetsecurity · Published 2026-09-11T05:00:07Z · Retrieved Sep 11, 2026, 8:51 AM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Incidents and exposureConti ransomware gang member sentenced to 4 years in prison
Bleepingcomputer published a source item for review.
Conti ransomware gang member sentenced to 4 years in prison
Bleepingcomputer published a source item for review.
What happened
Bleepingcomputer published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Conti ransomware gang member sentenced to 4 years in prison Bleepingcomputer · Published 2026-09-11T06:48:37Z · Retrieved Sep 11, 2026, 7:23 AM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Incidents and exposureNew infosec products of the week: September 11, 2026
Helpnetsecurity published a source item for review.
New infosec products of the week: September 11, 2026
Helpnetsecurity published a source item for review.
What happened
Helpnetsecurity published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- New infosec products of the week: September 11, 2026 Helpnetsecurity · Published 2026-09-11T04:00:08Z · Retrieved Sep 11, 2026, 8:51 AM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.