View all sources for this day →

The Signal

The most consequential items concern boundaries that organizations routinely trust: authentication infrastructure, user-owned conversations, public-sector services, and industrial-control environments. They should be considered distinct exposure problems rather than collapsed into a single AI or critical-infrastructure category. [1][2][3][4]

Must Know

AI & Agents · Arstechnica Security

Incident · Exploitation

What happened

The FBI is investigating ShinyHunters’ claims that the group exploited a previously unknown bug on FBIJobs.gov and stole personal data belonging to thousands of current and former employees. [3]

The reported incident involved taking down FBIJobs.gov and posting a banner claiming the site had been seized; ShinyHunters told The New York Times that approximately two to three terabytes of data were taken. [3]

Why it matters

The data reportedly included names, home addresses, phone numbers, spouses’ names, certain medical information and other information concerning current and former agents and applicants. [3]

Identity · Certcc Vulnotes

Identity · Vulnerability

What happened

Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform, contains CVE-2026-82356 in versions 26.2.6 and below because it lacks a supported mechanism to rotate the RSA key pair used to generate the appliance’s X.509 certificate. [1]

The advisory states that the vendor is aware of the issue and reportedly working toward a resolution, but no fix or timeline had been provided at publication. [1]

Why it matters

If an attacker obtains the private key through backup exfiltration, a hypervisor snapshot, or privileged filesystem access, they can impersonate the trusted appliance to endpoints that rely on it for authentication. [1]

Exploitation · Cyberscoop

Exploitation · Vulnerability

What happened

The article reports that state and local governments overseeing critical resources are routinely targeted by state-backed actors, while many lack sufficient cybersecurity budgets and staffing. [4]

CISA issued a joint advisory describing an active threat against Siemens S7 programmable logic controllers, which control industrial equipment including valves, motors, and pumps. [4]

Why it matters

The Center for Internet Security reportedly found that about one-third of surveyed local agencies conducted minimal or no cybersecurity activities. [4]

AI & Agents · Certcc Vulnotes

AI & Agents · Vulnerability

What happened

Cinnamon’s Kotaemon through v0.12.0 does not verify conversation ownership when loading conversations, allowing any authenticated user with a victim conversation UUID to read, delete, rename, or overwrite that conversation. [2]

The affected handlers query by conversation ID without constraining the conversation owner to the authenticated user. [2]

Why it matters

Unauthorized reads can expose full chat transcripts, retrieval history, plot history, and suggestions; retrieval history may contain verbatim excerpts from private enterprise documents. [2]

Also Worth Knowing

Identity · Malwarebytes Labs

Identity · Security

What happened

Device code phishing tricks a victim into entering a temporary code and approving a legitimate sign-in that the attacker initiated, potentially giving the attacker access to the victim’s account. [5]

Incident · The Hacker News

Supply Chain · Incident

What happened

Cybersecurity researchers disclosed Go-based malware distributed through two Go modules and two Terraform providers, using HashiCorp’s centralized repository as a malware distribution vector. [6]

Identity · Hashicorp Terraform Releases

Platform · Identity

What happened

Terraform v1.17.0-beta2 adds support for variables and locals in provider requirements and introduces a -minimal-refresh planning option that refreshes only resources with proposed changes. [7]

The release combines configuration-language changes with a generally available policy capability, so each change can be assessed separately against existing automation and governance. [7]

Sources (7)
  1. [1] VU#273940: Enterprise Access Management EAM does not rotate RSA keys

    certcc vulnotes · September 23, 2026

  2. [2] VU#754548: Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers

    certcc vulnotes · September 23, 2026

  3. [3] FBI rushes to investigate if ShinyHunters hack of thousands of employees is real

    arstechnica security · September 23, 2026

  4. [4] How tax policy can stop threat actors from breaching US water systems

    cyberscoop · September 24, 2026

  5. [5] How device code phishing gives scammers access to your account

    malwarebytes labs · September 23, 2026

  6. [6] Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

    the hacker news · September 23, 2026

  7. [7] v1.17.0-beta2

    hashicorp terraform releases · September 23, 2026