CISA and NIST Issue Guidance to Protect Cloud Identity Tokens

2026-09-16T14:52:09Z•669f3aa6439317735e12c3bc39538a32083cad5066170e91694ad807ee1c7b5c
CVE-2026-86218active-exploitationai-securityandroidcloud-securitycredential-theftcybercrimedata-breachfraudidentity-securityinsider-threatiranmalwarenorth-koreaoauthpatch-managementphishingransomwareremote-code-executionsoftware-securitystate-sponsoredsupply-chain-securityvulnerabilitieszero-day

What happened

Infosecurity Magazine coverage from September 7–16, 2026 highlights critical vulnerabilities and active exploitation, ransomware and data breaches, phishing and credential theft, Android malware, cloud and non-human identity risks, software supply-chain compromise, AI-related security concerns, and state-sponsored cyber activity. Notable issues include exploited maximum-severity GitLab and SAP flaws, Microsoft’s record September patch release, an N-able critical RCE (CVE-2026-86218), TP-Link camera zero-days, malicious OAuth-token theft, ransomware extortion, and campaigns targeting Microsoft

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
669f3aa6439317735e12c3bc39538a32083cad5066170e91694ad807ee1c7b5c
Enrichment time
2026-09-16T14:52:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.