The Signal
The most consequential items concern boundaries that organizations routinely trust: authentication infrastructure, user-owned conversations, public-sector services, and industrial-control environments. They should be considered distinct exposure problems rather than collapsed into a single AI or critical-infrastructure category. [1][2][3][4]
Must Know
AI & Agents · Arstechnica Security
What happened
The FBI is investigating ShinyHunters’ claims that the group exploited a previously unknown bug on FBIJobs.gov and stole personal data belonging to thousands of current and former employees. [3]
The reported incident involved taking down FBIJobs.gov and posting a banner claiming the site had been seized; ShinyHunters told The New York Times that approximately two to three terabytes of data were taken. [3]
Why it matters
The data reportedly included names, home addresses, phone numbers, spouses’ names, certain medical information and other information concerning current and former agents and applicants. [3]
Identity · Certcc Vulnotes
What happened
Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform, contains CVE-2026-82356 in versions 26.2.6 and below because it lacks a supported mechanism to rotate the RSA key pair used to generate the appliance’s X.509 certificate. [1]
The advisory states that the vendor is aware of the issue and reportedly working toward a resolution, but no fix or timeline had been provided at publication. [1]
Why it matters
If an attacker obtains the private key through backup exfiltration, a hypervisor snapshot, or privileged filesystem access, they can impersonate the trusted appliance to endpoints that rely on it for authentication. [1]
Exploitation · Cyberscoop
What happened
The article reports that state and local governments overseeing critical resources are routinely targeted by state-backed actors, while many lack sufficient cybersecurity budgets and staffing. [4]
CISA issued a joint advisory describing an active threat against Siemens S7 programmable logic controllers, which control industrial equipment including valves, motors, and pumps. [4]
Why it matters
The Center for Internet Security reportedly found that about one-third of surveyed local agencies conducted minimal or no cybersecurity activities. [4]
AI & Agents · Certcc Vulnotes
What happened
Cinnamon’s Kotaemon through v0.12.0 does not verify conversation ownership when loading conversations, allowing any authenticated user with a victim conversation UUID to read, delete, rename, or overwrite that conversation. [2]
The affected handlers query by conversation ID without constraining the conversation owner to the authenticated user. [2]
Why it matters
Unauthorized reads can expose full chat transcripts, retrieval history, plot history, and suggestions; retrieval history may contain verbatim excerpts from private enterprise documents. [2]
Also Worth Knowing
Identity · Malwarebytes Labs
What happened
Device code phishing tricks a victim into entering a temporary code and approving a legitimate sign-in that the attacker initiated, potentially giving the attacker access to the victim’s account. [5]
Incident · The Hacker News
What happened
Cybersecurity researchers disclosed Go-based malware distributed through two Go modules and two Terraform providers, using HashiCorp’s centralized repository as a malware distribution vector. [6]
Identity · Hashicorp Terraform Releases
What happened
Terraform v1.17.0-beta2 adds support for variables and locals in provider requirements and introduces a -minimal-refresh planning option that refreshes only resources with proposed changes. [7]
The release combines configuration-language changes with a generally available policy capability, so each change can be assessed separately against existing automation and governance. [7]