{"id":5843,"date":"2026-09-06T12:30:56","date_gmt":"2026-09-06T17:30:56","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5843"},"modified":"2026-09-06T12:30:56","modified_gmt":"2026-09-06T17:30:56","slug":"security-operations-weekly-september-6-2026","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5843","title":{"rendered":"Security Operations Weekly &mdash; September 6, 2026"},"content":{"rendered":"<style>\n.single .entry-title,\n.single .entry-header .entry-title,\n.single .post-title,\n.single header.entry-header h1,\n.single h1.entry-title,\n.single .page-title,\n.post-template-default h1.entry-title,\n.post-template-default .entry-header,\narticle .entry-header,\narticle .entry-title { display: none !important; }\n.single .entry-header { margin: 0 !important; padding: 0 !important; }\n.single .entry-content { margin-top: 0 !important; padding-top: 0 !important; }\n<\/style>\n<table role=\"presentation\" class=\"wrapper\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"100%\">\n<tr>\n<td align=\"center\">\n<table role=\"presentation\" class=\"container\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"680\">\n<p>        <!-- Banner --><\/p>\n<tr>\n<td class=\"banner\" style=\"background-color:#0f2c4d;background:linear-gradient(135deg,#0f2c4d 0%,#1e5a8f 50%,#2b8fb3 100%);padding:36px 32px;color:#ffffff;\">\n<p class=\"date\" style=\"color:#ffffff !important;\">September 6, 2026 &middot; Weekly Edition<\/p>\n<h1 style=\"color:#ffffff !important;\">Security Operations Weekly<\/h1>\n<p class=\"tagline\" style=\"color:#ffffff !important;\">A heavy patch week, and the numbers underneath it are the story. Nearly 22,000 Exchange servers were still exposed three weeks after Microsoft shipped the fix. Cisco ran an internal review of IOS XR and found so much that it bundled the results into a release. Seven CVEs went into KEV, three of them in AI and workflow-orchestration plumbing. Meanwhile Echo&rsquo;s audit of Claude Mythos found 91.8% of 23,019 candidate findings had never been looked at by a human, and Contrast Security measured AI scanners agreeing with each other on 5% of findings &mdash; and with themselves on 17%. Two Defender false-positive incidents in four days round it off. Discovery is cheap now. Everything after discovery is not.<\/p>\n<\/td>\n<\/tr>\n<p>        <!-- At a glance --><\/p>\n<tr>\n<td class=\"content\">\n<h2>This week at a glance<\/h2>\n<p>The week&rsquo;s spine is a patch queue that keeps getting longer while the population that has actually applied last month&rsquo;s fixes keeps getting smaller: CVE-2026-62911, an authentication-bypass-by-capture-replay flaw in Exchange Server at CVSS 8.0, was patched on 11 August, and three weeks later Shadowserver counts still put nearly 22,000 servers exposed &mdash; roughly 6,200 in the United States, roughly 5,100 in Germany, where the BSI figure quoted alongside them has about 85% of on-premises Exchange still vulnerable &mdash; with NCSC-NL warning that public exploit code is circulating and reducing its advisory to four words, &ldquo;Install these updates as soon as possible&rdquo;; on top of that sit a 23-vulnerability HPE bulletin led by CVE-2026-73749, an unauthenticated remote code execution flaw in an ArubaOS-CX daemon, a pair of VMware Workstation and Fusion escapes through the VMXNET3 adapter (CVE-2026-59346 at CVSS 9.3, CVE-2026-59347 at CVSS 8.1, fixed only in 26H1u1, no workarounds), a Cisco batch built from a self-directed internal review that produced two CVSS 9.8 flaws in IOS XR plus CVE-2026-20212, unauthenticated root on ten Nexus 9000 models with mitigation but no permanent fix, and seven new KEV entries whose BOD 26-04 deadlines fell on 5 and 16 September &mdash; three of them, notably, in Kestra, LiteLLM and Starlette, which is to say in the control plane of the AI stack rather than in anything a traditional asset inventory calls a security product. Behind the queue is the reason it will not shorten: Echo&rsquo;s analysis of Claude Mythos found 23,019 candidate findings across 281 projects of which only 1,900 &mdash; 8.2% &mdash; were ever reviewed by an external human, and of the 27 CVEs that did get assigned, severity was overstated in 13; Contrast Security&rsquo;s AppSec Overflow 2026 report found AI scanners agreeing on 5% of findings against an identical codebase and a single scanner reproducing 17% of its own results across three runs, at $315 of API charges to scan two million lines and roughly $128,000 to triage what came back, which is why David Lindner&rsquo;s &ldquo;AI is not going to triage its way out of this problem&rdquo; is the most useful sentence published this week. The defensive build-out continued regardless &mdash; CrowdStrike&rsquo;s Fal.Con launch of SafeMind, Red Tempest and Blue Solano out of a new Cyber Superintelligence Lab, F5 adding anomaly detection and agentic threat intelligence alongside faster virtual patching, Figma publishing self-reported numbers for an alert-triage agent in production, OpenAI committing $1 billion of subsidised access and training under a six-month &ldquo;Daybreak for Frontline Defenders&rdquo; pilot and coordinating an open letter signed by more than 100 companies &mdash; while the control layer itself misfired twice, with Windows falsely reporting Defender Antivirus disabled and, separately, Defender for Office 365 Safe Links flagging Google Search results as unsafe for a day. And the quiet corrective sits in a foundational piece: an intrusion that no amount of patching would have stopped, because it began with SQL injection into a public-facing application and ended with Java source uploaded straight into the Oracle database behind it.<\/p>\n<p>            <!-- Watch list --><\/p>\n<div class=\"watchlist\">\n<h2>On our watch list<\/h2>\n<ul>\n<li><strong>Whether the Exchange 2016\/2019 population shrinks before October.<\/strong> ESU cover for both ends in October, in the same month Windows 11 24H2 Home and Professional go out of support. If the exposed count has not moved substantially by then, that population becomes permanently unpatched rather than temporarily behind.<\/li>\n<li><strong>How many more KEV entries land in the AI stack.<\/strong> Three of seven in one week is a data point, not a trend. A second week with the same composition would mean the exploited-vulnerability catalogue has effectively expanded into infrastructure most security teams do not yet own.<\/li>\n<li><strong>Whether BOD 26-04 deadlines start showing up in commercial contracts.<\/strong> KEV timelines already function as a de facto private-sector benchmark. Watch for the first supplier agreements that cite the directive by name and attach the deadlines to a service credit.<\/li>\n<li><strong>Severity inflation in machine-generated findings.<\/strong> Claude Mythos overstated severity in 13 of 27 assigned CVEs, rating eight Critical where independent scoring left one. Watch whether the platforms consuming automated findings start publishing calibration data, or whether the inflated scores just propagate into everyone&rsquo;s prioritisation queue unchallenged.<\/li>\n<li><strong>Scanner determinism as a procurement question.<\/strong> A single tool reproducing 17% of its own findings across three runs is a testable claim. The interesting development would be a buyer requiring repeat-run consistency in an evaluation rather than accepting a one-shot demo.<\/li>\n<li><strong>Whether anyone publishes independent numbers for an agentic SOC.<\/strong> Figma&rsquo;s 70% and 20% are self-reported and specific enough to be worth reproducing. The gap to watch is between vendor launch claims and operator-published measurements taken the same way twice.<\/li>\n<li><strong>What Daybreak actually delivers in six months.<\/strong> The OpenAI programme is subsidised access and training on a six-month pilot, aimed at utilities, local government, community banks, healthcare and open-source maintainers. The test is whether any of those recipients reports a measurable change, and whether the pilot converts into something durable.<\/li>\n<li><strong>Fallout from the October memory-integrity rollout.<\/strong> The change arrives through the quality-update channel without a change request, on a population Windows selects. Watch for driver-compatibility incidents in the first fortnight, and decide now whether you would rather pre-empt the decision on your own schedule.<\/li>\n<\/ul><\/div>\n<p>            <!-- Topic map --><\/p>\n<div class=\"topic-map\">\n              <img decoding=\"async\" src=\"https:\/\/www.cybersecurityinstitute.com\/blog\/wp-content\/uploads\/2026\/09\/topic-map-security-operations-2026-09-06.png\" alt=\"Topic map of this week's Security Operations Weekly themes\" loading=\"eager\"><\/p>\n<p class=\"caption\">This week&rsquo;s topic map &mdash; the patch queue and who is still exposed (Exchange and CVE-2026-62911, ArubaOS-CX, IOS XR and Nexus 9000, VMware, the seven KEV additions under BOD 26-04), the disclosure-capacity problem behind it (Claude Mythos and Echo&rsquo;s audit, Contrast Security&rsquo;s agreement numbers, prioritisation when KEV, EPSS and CVSS disagree), agentic AI arriving in the SOC on both sides of the ledger (CrowdStrike, F5, Figma, OpenAI, HiddenLayer, GitHub&rsquo;s malware-intel pipeline, agent drift), the week the security control was itself the incident (Defender, Windows memory integrity), and identity and credential exposure as the layer everything else runs on.<\/p>\n<p>              <!-- INTERACTIVE_MAP_LINK_START --><\/p>\n<p style=\"margin:10px 0 0;text-align:center;\"><a href=\"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5842\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:8px 18px;background-color:#0f172a;color:#ffffff !important;text-decoration:none;border-radius:6px;font-size:13px;font-weight:600;\">View interactive topic map &rarr;<\/a><\/p>\n<p><!-- INTERACTIVE_MAP_LINK_END -->\n            <\/div>\n<p>            <!-- Article index --><\/p>\n<h2>Article index<\/h2>\n<h4>Patch this week: critical flaws, KEV and the shrinking window<\/h4>\n<div class=\"cluster-intro\">The hard operational core of the issue &mdash; Exchange, ArubaOS-CX, VMware, IOS XR and Nexus, seven new KEV entries and the September Patch Tuesday forecast &mdash; bracketed by two foundational pieces on why applying everything on time still would not have been enough.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>1. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/02\/microsoft-exchange-cve-2026-62911-critical-authentication-bypass-flaw\/\">Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Sep 2, 2026<\/td>\n<\/tr>\n<tr>\n<td>2. <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/09\/02\/cisa-adds-seven-known-exploited-vulnerabilities-catalog\">CISA Adds Seven Known Exploited Vulnerabilities to Catalog<\/a><\/td>\n<td class=\"src\">CISA<\/td>\n<td class=\"dt\">Sep 2, 2026<\/td>\n<\/tr>\n<tr>\n<td>3. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw\/\">HPE patches critical ArubaOS-CX remote code execution flaw<\/a><\/td>\n<td class=\"src\">BleepingComputer<\/td>\n<td class=\"dt\">Sep 3, 2026<\/td>\n<\/tr>\n<tr>\n<td>4. <a href=\"https:\/\/www.securityweek.com\/vmware-workstation-and-fusion-updates-patch-critical-vulnerability\/\">VMware Workstation and Fusion Updates Patch Critical Vulnerability<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Sep 4, 2026<\/td>\n<\/tr>\n<tr>\n<td>5. <a href=\"https:\/\/www.theregister.com\/security\/2026\/09\/04\/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release\/5294410\">Cisco searched for IOS XR bugs and found so many it rolled them into an update release<\/a><\/td>\n<td class=\"src\">The Register<\/td>\n<td class=\"dt\">Sep 4, 2026<\/td>\n<\/tr>\n<tr>\n<td>6. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/04\/september-2026-patch-tuesday-forecast\/\">September 2026 Patch Tuesday forecast: All we need is more time<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Sep 4, 2026<\/td>\n<\/tr>\n<tr>\n<td>7. <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/25\/you-couldve-applied-all-1449-oracle-patches-and-still-been-hit-by-this-attack\/5292335\">You could&rsquo;ve applied all 1,449 Oracle patches and still been hit by this attack<\/a><\/td>\n<td class=\"src\">The Register<\/td>\n<td class=\"dt\">Aug 25, 2026<\/td>\n<\/tr>\n<tr>\n<td>8. <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/zimbra-flaw-exploitation-shrinking-window-patch\">Exploited Zimbra Flaw Highlights Shrinking Window to Patch<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Aug 24, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>AI finds bugs faster than anyone can fix them<\/h4>\n<div class=\"cluster-intro\">The disclosure-capacity story: machine-generated vulnerability volume, the unreliability of the tools generating it, and the triage question that follows &mdash; eliminate whole classes, or prioritise better when the scoring systems disagree.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>9. <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/ai-ending-era-hidden-vulnerabilities-are-vendors-ready\">AI Is Ending the Era of Hidden Vulnerabilities &mdash; Are Vendors Ready?<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Sep 4, 2026<\/td>\n<\/tr>\n<tr>\n<td>10. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/04\/echo-claude-mythos-vulnerability-findings\/\">Most of the bugs Claude Mythos found have never been checked by a human<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Sep 4, 2026<\/td>\n<\/tr>\n<tr>\n<td>11. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/08\/31\/contrast-security-ai-appsec-tools-security-findings-report\/\">AI AppSec tools agree on just 5% of security findings<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Aug 31, 2026<\/td>\n<\/tr>\n<tr>\n<td>12. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/01\/cisa-on-eliminating-recurring-security-weaknesses\/\">CISA review makes the case for eliminating vulnerability classes<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Sep 1, 2026<\/td>\n<\/tr>\n<tr>\n<td>13. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/08\/31\/joye-purser-cohesity-kev-epss-cvss-conflicts\/\">What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Aug 31, 2026<\/td>\n<\/tr>\n<tr>\n<td>14. <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/22\/if-youre-not-using-ai-to-attack-your-own-systems\/5291346\">If you&rsquo;re not using AI to attack your own systems, your adversaries will<\/a><\/td>\n<td class=\"src\">The Register<\/td>\n<td class=\"dt\">Aug 22, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>AI in the SOC: deployed in practice<\/h4>\n<div class=\"cluster-intro\">What actually shipped and what it is being pointed at &mdash; an alert-triage agent running in production, a frontier-model launch, WAF work that is broader than its headline, the reality of ingesting malware intelligence at scale, and the failure modes of an agent that authenticates cleanly.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>15. <a href=\"https:\/\/www.infoq.com\/news\/2026\/09\/figma-security-agents\/\">How Figma Uses AI Agents for Security<\/a><\/td>\n<td class=\"src\">InfoQ<\/td>\n<td class=\"dt\">Sep 6, 2026<\/td>\n<\/tr>\n<tr>\n<td>16. <a href=\"https:\/\/www.csoonline.com\/article\/4217135\/crowdstrike-launches-cyber-frontier-ai-models-agentic-security-system.html\">CrowdStrike launches cyber frontier AI models, agentic security system<\/a><\/td>\n<td class=\"src\">CSO Online<\/td>\n<td class=\"dt\">Sep 1, 2026<\/td>\n<\/tr>\n<tr>\n<td>17. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/02\/f5-waf-anomaly-detection-ai-threats\/\">F5 speeds up virtual patching to counter AI-driven threats<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Sep 2, 2026<\/td>\n<\/tr>\n<tr>\n<td>18. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/03\/github-threat-intelligence-feed-ingestion\/\">Your threat feed is someone else&rsquo;s database: What ingesting malware intel at scale takes<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Sep 3, 2026<\/td>\n<\/tr>\n<tr>\n<td>19. <a href=\"https:\/\/venturebeat.com\/security\/ai-agents-that-pass-authentication-can-still-drift-expose-data-or-get-memory-poisoned\">AI agents that pass authentication can still drift, expose data, or get memory-poisoned<\/a><\/td>\n<td class=\"src\">VentureBeat<\/td>\n<td class=\"dt\">Aug 30, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>AI in the SOC: the market and the institutions<\/h4>\n<div class=\"cluster-intro\">Where the money and the credentialing are going &mdash; a $1 billion subsidised-access programme, an open letter with more than a hundred signatures, a funding round in AI runtime security, the first accreditation cohort for AI-enabled pentesting, and a practitioner&rsquo;s view of what agent trust actually requires.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>20. <a href=\"https:\/\/www.cybersecuritydive.com\/news\/openai-pledges-1-billion-resources-cyber-defenders\/829676\/\">OpenAI pledges $1B to provide resources, training for frontline cyber defenders<\/a><\/td>\n<td class=\"src\">Cybersecurity Dive<\/td>\n<td class=\"dt\">Sep 4, 2026<\/td>\n<\/tr>\n<tr>\n<td>21. <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/28\/industry-that-built-the-problem-offers-to-sell-you-the-solution\/5293207\">Industry that built the problem offers to sell you the solution<\/a><\/td>\n<td class=\"src\">The Register<\/td>\n<td class=\"dt\">Aug 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>22. <a href=\"https:\/\/www.securityweek.com\/hiddenlayer-raises-100-million-for-ai-runtime-security\/\">HiddenLayer Raises $100 Million for AI Runtime Security<\/a><\/td>\n<td class=\"src\">SecurityWeek<\/td>\n<td class=\"dt\">Sep 3, 2026<\/td>\n<\/tr>\n<tr>\n<td>23. <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/crest-first-cohort-ai-pentesting\/\">CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation<\/a><\/td>\n<td class=\"src\">Infosecurity Magazine<\/td>\n<td class=\"dt\">Sep 3, 2026<\/td>\n<\/tr>\n<tr>\n<td>24. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/securing-ai-agents-rick-holland-on-data-identity-and-trust\">Securing AI agents: Rick Holland on data, identity, and trust<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Sep 2, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>When the security tooling is the incident<\/h4>\n<div class=\"cluster-intro\">A Microsoft-centric cluster about misplaced trust in the control itself: memory integrity arriving without a change request, two separate Defender false-positive incidents in four days, and a filter-evasion technique that turns the mail gateway into the weak point.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>25. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/03\/windows-memory-integrity-update\/\">Windows memory integrity switches on automatically for eligible devices in October 2026<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Sep 3, 2026<\/td>\n<\/tr>\n<tr>\n<td>26. <a href=\"https:\/\/www.csoonline.com\/article\/4216607\/windows-bug-incorrectly-tells-users-that-microsoft-defender-antivirus-is-turned-off-2.html\">Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off<\/a><\/td>\n<td class=\"src\">CSO Online<\/td>\n<td class=\"dt\">Aug 31, 2026<\/td>\n<\/tr>\n<tr>\n<td>27. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-defender-flags-legitimate-google-search-links-as-malicious\/\">Microsoft Defender flags legitimate Google search links as malicious<\/a><\/td>\n<td class=\"src\">BleepingComputer<\/td>\n<td class=\"dt\">Sep 2, 2026<\/td>\n<\/tr>\n<tr>\n<td>28. <a href=\"https:\/\/www.scworld.com\/news\/ascii-smuggling-challenges-email-phishing-filters-microsoft-warns\">ASCII smuggling challenges email phishing filters, Microsoft warns<\/a><\/td>\n<td class=\"src\">SC Media<\/td>\n<td class=\"dt\">Sep 4, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Identity, access and the exercised organisation<\/h4>\n<div class=\"cluster-intro\">The layer everything else runs on: what to do when a corporate credential turns up in an infostealer dump, the access plane widening beyond the VPN, and a readiness case study drawn from two red-team engagements that ended very differently.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>29. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/your-employees-password-appeared-in-an-infostealer-log-now-what\/\">Your Employee&rsquo;s Password Appeared in an Infostealer Log. Now What?<\/a><\/td>\n<td class=\"src\">BleepingComputer<\/td>\n<td class=\"dt\">Sep 3, 2026<\/td>\n<\/tr>\n<tr>\n<td>30. <a href=\"https:\/\/www.networkworld.com\/article\/4215616\/tailscale-expands-from-vpn-into-a-full-connectivity-platform.html\">Tailscale expands from VPN into a full connectivity platform<\/a><\/td>\n<td class=\"src\">Network World<\/td>\n<td class=\"dt\">Aug 31, 2026<\/td>\n<\/tr>\n<tr>\n<td>31. <a href=\"https:\/\/www.cybersecuritydive.com\/news\/cisa-red-team-exercises-lessons-cloud-soc\/828733\/\">CISA identifies security hurdles that led to very different results in two red-team engagements<\/a><\/td>\n<td class=\"src\">Cybersecurity Dive<\/td>\n<td class=\"dt\">Aug 28, 2026<\/td>\n<\/tr>\n<\/table>\n<p>            <!-- Detailed write-ups --><\/p>\n<h2>Detailed write-ups<\/h2>\n<div class=\"article\">\n<h4>1. Three weeks after the fix, nearly 22,000 Exchange servers were still listening<\/h4>\n<p class=\"meta\">Help Net Security &middot; September 2&ndash;4, 2026<\/p>\n<p>CVE-2026-62911 is an authentication bypass by capture-replay in Microsoft Exchange Server, rated CVSS 8.0, and Microsoft shipped the fix on 11 August. Roughly three weeks later, Help Net Security reports, nearly 22,000 internet-facing servers were still running unpatched code. Shadowserver Foundation&rsquo;s scan data puts about 6,200 of those in the United States and about 5,100 in Germany &mdash; and the German number is worse than the raw count suggests, because the BSI figure cited alongside it has roughly 85% of German on-premises Exchange servers still vulnerable. The affected products are Exchange Server 2016 and Exchange Server 2019, both of which now receive security updates only through the Extended Security Updates programme, which tells you something about the population: a meaningful share of those 22,000 belong to organisations that have already decided, explicitly, not to migrate. The flaw was found by Orange Tsai of the DEVCORE Research Team and reported through Trend Micro&rsquo;s Zero Day Initiative; NCSC-NL has flagged that public exploit code is circulating online, and its advisory reduces to a single instruction: &ldquo;Install these updates as soon as possible.&rdquo; A related Exchange flaw, CVE-2026-42897, was fixed back in June, so this is a product line under sustained research attention as well as sustained operational neglect.<\/p>\n<p>The forecast column that ran two days later frames the same problem from the intake side. It is Ivanti&rsquo;s monthly look-ahead, written by senior product manager Todd Schell, and the baseline it starts from is the reason nobody is catching up: August 2026 Patch Tuesday resolved 398 CVEs &mdash; 42 Critical, 355 Important, one Moderate. The items Schell flags ahead of September are CVE-2026-55040 and CVE-2026-63520 in SharePoint; CVE-2026-62911 in Exchange Server again; CVE-2026-65816 and CVE-2026-69555 in Azure Arc, both at CVSS 10.0; CVE-2026-65801 in Exchange Server Online, also 10.0; and CVE-2026-69414, an elevation-of-privilege flaw in Microsoft Defender. Outside Microsoft, CVE-2026-85046 in Chrome is flagged as actively exploited, in a release (152.0.7977.82\/.83) that addressed 12 CVEs in total. The date to put in the change calendar is not the Patch Tuesday itself but October, which brings a genuine cliff edge: end of support for Windows 11 version 24H2 Home and Professional, and the end of ESU cover for Server 2012 and 2012 R2 and for Exchange Server 2016 and 2019 &mdash; the same estate carrying the 22,000 exposed servers above. The column&rsquo;s quotable line comes from Igor Sahknov, Microsoft&rsquo;s corporate vice president for Azure Networking, on what to do while the queue drains: &ldquo;The objective is not to avoid patching. The objective is to create a meaningful layer of defense.&rdquo; Exchange 2016 and 2019 users are about to find out how meaningful theirs is.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/02\/microsoft-exchange-cve-2026-62911-critical-authentication-bypass-flaw\/\">Help Net Security (22,000 Exchange servers exposed to CVE-2026-62911)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/04\/september-2026-patch-tuesday-forecast\/\">Help Net Security (September 2026 Patch Tuesday forecast)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>2. Seven KEV additions, and three of them are AI plumbing<\/h4>\n<p class=\"meta\">CISA &middot; Dark Reading &middot; August 24 &ndash; September 2, 2026<\/p>\n<p>CISA added seven vulnerabilities to the Known Exploited Vulnerabilities catalogue on 2 September. The detail below comes from The Hacker News&rsquo;s reporting of the additions rather than from the catalogue entry itself, and the composition of the list is the interesting part. Two are in SonicWall SMA 1000 &mdash; CVE-2026-83548, a server-side request forgery, and CVE-2026-83549, an OS command injection. One is in Sangoma Switchvox: CVE-2026-9586, SQL injection. Those three were used to drop reverse shells, which is the familiar pattern for edge appliances and telephony. CVE-2026-82329 is an improper-authentication flaw in JFrog Artifactory, with admin-token minting observed in the wild &mdash; a build-system compromise wearing the clothes of an authentication bug. And then the three that should change where your monitoring points: CVE-2026-48710, an HTTP request\/response smuggling flaw in Kludex Starlette; CVE-2026-49869, OS command injection in Kestra OSS; and CVE-2026-59822, improper authentication in Berri LiteLLM. The last two were used to deploy cryptocurrency miners. Federal remediation deadlines were set under BOD 26-04 &mdash; not the older BOD 22-01 that most runbooks still cite &mdash; with 5 September for five of the seven and 16 September for CVE-2026-48710 and CVE-2026-59822.<\/p>\n<p>Starlette, Kestra and LiteLLM are an ASGI framework, a workflow orchestrator and an LLM gateway. None of them appears in a CMDB as a security product, and in many organisations none of them was procured through a process that would produce a patch owner. They are also, collectively, the control plane through which model traffic, credentials and scheduled jobs move &mdash; which is exactly the framing Microsoft supplied in the coverage: &ldquo;Defenders should monitor AI workloads according to their control-plane role, not only as isolated applications.&rdquo; The practical consequence is that three of the week&rsquo;s seven confirmed-exploited flaws sit in infrastructure that most SOCs discover only after an incident, and that the first observed use of two of them was cryptomining &mdash; the cheapest possible monetisation, and therefore the clearest evidence that access is easy rather than targeted. Dark Reading&rsquo;s piece on the exploited Zimbra flaw makes the companion argument about how little time the patch cycle now leaves; taken with the Exchange numbers above, the honest reading is that KEV deadlines are no longer a compliance artefact for federal agencies but the closest thing the industry has to a public service-level agreement, and one that most private estates would currently miss.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/09\/02\/cisa-adds-seven-known-exploited-vulnerabilities-catalog\">CISA (seven known exploited vulnerabilities added)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/zimbra-flaw-exploitation-shrinking-window-patch\">Dark Reading (exploited Zimbra flaw and the shrinking patch window)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>3. The infrastructure batch: ArubaOS-CX, a self-inflicted Cisco audit, and a VM escape<\/h4>\n<p class=\"meta\">BleepingComputer &middot; The Register &middot; SecurityWeek &middot; September 3&ndash;4, 2026<\/p>\n<p>HPE&rsquo;s bulletin is the one to schedule first. CVE-2026-73749 is a critical buffer overflow in an ArubaOS-CX daemon that allows unauthenticated remote code execution via specially crafted packets &mdash; no credentials, no user interaction, on the network operating system that runs HPE Aruba Networking enterprise switches. It did not ship alone: the bulletin covers 23 vulnerabilities in total, including CVE-2026-73750 through CVE-2026-73753 and CVE-2026-73777 through CVE-2026-73782, with the secondary flaws carrying high-severity scores between CVSS 8.1 and 8.8. The fixed-version matrix is unusually branchy, so read it against your actual inventory rather than your standard build: 10.18.0001 moves to 10.18.1002 or later; 10.17.1021 and earlier to 10.17.1030 or later; 10.16.1051 and earlier to 10.16.1060 or later; 10.13.1180 and earlier to 10.13.1190 or later; and 10.10.1180 and earlier to 10.10.1181 or later. At the time of publication HPE said it was not aware of active exploitation or of any publicly available proof-of-concept exploit &mdash; which is the window, not the reprieve.<\/p>\n<p>Cisco&rsquo;s batch is more interesting for how it was produced than for any single entry. The company disclosed it after what it describes as a comprehensive internal security review, and then bundled the fixes into an IOS XR update release instead of issuing them one at a time &mdash; an admission, effectively, that the volume made piecemeal advisories impractical. Two entries top the list at CVSS 9.8. CVE-2026-20274 covers buffering issues, out-of-bounds writes and insecure resource initialisation in IOS XR; CVE-2026-20279 covers improper access control across four distinct failures &mdash; improper certificate validation, missing authentication for a critical function, missing authorisation and incorrect authorisation. Behind them sit three more flaws at 8.8, one at 8.6 and one at 8.2, and Silicon One networking processors are named among the affected platforms. The one that needs action tonight rather than at the next maintenance window is CVE-2026-20212: unauthenticated remote code execution as root on ten Nexus 9000 Series switch models, because TCP ports 43210 and 43211 are reachable in the default Layer 3 VRF. Software fixes exist for the IOS XR flaws; for CVE-2026-20212 there is mitigation only, with no permanent fix released at publication, and Cisco&rsquo;s guidance is an infrastructure ACL: &ldquo;the iACLs may be used to explicitly deny all TCP packets that are destined to a locally configured IP address with a destination port of 43210 or 43211.&rdquo; Cisco says it has seen no attacks on any of these flaws.<\/p>\n<p>The VMware pair is smaller in blast radius and higher in consequence per instance. CVE-2026-59346, CVSS 9.3, is an integer overflow leading to arbitrary code execution; CVE-2026-59347, CVSS 8.1, is a stack-based buffer overflow. Both affect VMware Workstation and VMware Fusion versions 25H2 and 26H1, both are fixed in 26H1u1, and there are no workarounds. Exploitation requires local administrative privileges inside a guest virtual machine, and the escape runs through the VMXNET3 virtual network adapter &mdash; Broadcom&rsquo;s own wording is that &ldquo;a malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host.&rdquo; That is a precise description of the malware-analysis bench, the developer laptop running an untrusted image, and the detonation VM that a lot of SOCs treat as disposable. Broadcom published the advisory (ID 38288) on 4 September, says there is no known exploitation in the wild, and notes both issues were reported privately. If your analysts run local hypervisors, this is the patch that protects the people looking at the samples.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw\/\">BleepingComputer (HPE ArubaOS-CX critical RCE)<\/a> &middot; <a href=\"https:\/\/www.theregister.com\/security\/2026\/09\/04\/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release\/5294410\">The Register (Cisco IOS XR bug batch and Nexus 9000)<\/a> &middot; <a href=\"https:\/\/www.securityweek.com\/vmware-workstation-and-fusion-updates-patch-critical-vulnerability\/\">SecurityWeek (VMware Workstation and Fusion critical patch)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>4. AI finds the bugs. Almost nobody has checked them.<\/h4>\n<p class=\"meta\">Help Net Security &middot; Dark Reading &middot; The Register &middot; August 22 &ndash; September 4, 2026<\/p>\n<p>Start with the cleanest number published this week. Echo, a software supply-chain security company, went through the output of Anthropic&rsquo;s Claude Mythos and counted: 281 projects scanned, 23,019 candidate findings produced, and 1,900 of them &mdash; 8.2% &mdash; ever reviewed by an external human. That leaves 91.8% unreviewed. The reviewed portion looks reasonable in isolation: 1,726 were confirmed real, 1,596 reports reached maintainers, 1,451 were acknowledged, 97 fixes shipped and 88 advisories were published. But the finding buried under the volume is the one that matters for anyone consuming this data downstream. Of the 27 CVEs assigned out of that work, Claude Mythos overstated severity in 13 cases &mdash; it rated eight of them Critical, where independent scoring left just one Critical overall. Machine-generated findings do not merely arrive faster than humans can review them; where they are scored automatically, they arrive with a systematic upward bias in exactly the field your prioritisation pipeline sorts on.<\/p>\n<p>Contrast Security&rsquo;s AppSec Overflow 2026 report, built on telemetry from hundreds of thousands of production applications and APIs, supplies the reliability half. Run against an identical codebase, AI scanners agreed with one another on 5% of findings. Worse, a single scanner reproduced only 17% of its own findings when run three times &mdash; so this is a non-determinism problem before it is a vendor-disagreement problem, and it means &ldquo;we re-ran the scan and it&rsquo;s clean&rdquo; is not evidence of anything. The economics are the part to take to a budget meeting: scanning a two-million-line codebase with AI tools cost roughly $315 in API charges, and triaging what came back cost roughly $128,000. Discovery is now approximately free and verification is not, which is the whole shape of the year. The report&rsquo;s supporting figures fill in the operational picture &mdash; applications average 106 vulnerability findings each, 22 of them high or critical; the average remediation rate is 3.4 vulnerabilities per application per month; average critical fix time is 92 days; applications see an average 42 confirmed viable exploit attempts a month, though attack volume is heavily skewed, with more than 60% of applications seeing fewer than 3,000 attacks monthly while more than 25% absorb 30,000 or more; and the report&rsquo;s Zero Day Clock tracked more than 83,000 CVEs. One number in there is directly actionable: 82% of the CVEs on CISA&rsquo;s KEV list carried an EPSS score of 90% or higher, which is a strong argument for using EPSS as a leading indicator rather than as a tiebreaker. David Lindner, Contrast&rsquo;s CISO, gives the summary: &ldquo;AI is not going to triage its way out of this problem.&rdquo; His CTO, Jeff Williams, gives the sharper version: &ldquo;AI ended that race, and defenders lost it.&rdquo;<\/p>\n<p>Dark Reading&rsquo;s news analysis by Alexander Culafi puts the same curve on the disclosure side, where bug bounty platforms report submissions doubling year over year and critical vulnerabilities sitting in backlogs up thirty-fold. The people quoted are the ones who would know if it were noise &mdash; Aaron Portnoy, chief product officer at Mindgard and the founder of Pwn2Own; Katie Moussouris of Luta Security; Kara Sprague, CEO of HackerOne; Casey Ellis, president of Disclose.io; and Dave Gerry, CEO of Bugcrowd &mdash; and the question the piece puts to vendors is whether their disclosure processes were ever built for this rate of intake. Two of the week&rsquo;s remaining pieces answer it from opposite directions. Help Net Security&rsquo;s read of a CISA review makes the case for eliminating whole vulnerability classes rather than grinding through instances of them, which is the only strategy in this issue whose cost does not scale with the discovery rate. And Dr. Joye Purser, Global Field CISO at Cohesity, gives the tactical version in an interview on what to do when KEV, EPSS and CVSS point in different directions: her hierarchy is &ldquo;active exploitation first, then exploit likelihood, then technical severity,&rdquo; adjusted for asset exposure and business context, with a 24 to 72 hour remediation target for internet-exposed critical vulnerabilities. Read her ordering against the Claude Mythos severity finding above and the logic is obvious &mdash; the field most inflated by automated scoring is the one she ranks last. The Register&rsquo;s foundational piece rounds the theme out by arguing that if you are not already turning AI offence on your own systems, your adversaries are doing it for you.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/04\/echo-claude-mythos-vulnerability-findings\/\">Help Net Security (Echo&rsquo;s analysis of Claude Mythos findings)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/08\/31\/contrast-security-ai-appsec-tools-security-findings-report\/\">Help Net Security (AI AppSec tools agree on 5% of findings)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/ai-ending-era-hidden-vulnerabilities-are-vendors-ready\">Dark Reading (AI is ending the era of hidden vulnerabilities)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/01\/cisa-on-eliminating-recurring-security-weaknesses\/\">Help Net Security (CISA on eliminating vulnerability classes)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/08\/31\/joye-purser-cohesity-kev-epss-cvss-conflicts\/\">Help Net Security (Joye Purser on KEV, EPSS and CVSS conflicts)<\/a> &middot; <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/22\/if-youre-not-using-ai-to-attack-your-own-systems\/5291346\">The Register (using AI to attack your own systems)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>5. Agents in production: Figma&rsquo;s numbers, CrowdStrike&rsquo;s launch, and the feed nobody wants to own<\/h4>\n<p class=\"meta\">InfoQ &middot; CSO Online &middot; Help Net Security &middot; VentureBeat &middot; August 30 &ndash; September 6, 2026<\/p>\n<p>The most useful item here is the least promoted. InfoQ&rsquo;s piece is a summary of Figma&rsquo;s own engineering blog posts &mdash; not a conference talk, not a vendor case study &mdash; describing an alert-triage agent built on Claude Opus and wired into Panther SIEM, AWS Bedrock Knowledge Bases, Amazon Kendra, Tines and a Snowflake-based investigation tool. Brad Girardeau, security engineering manager at Figma, and Matthew Sullivan, formerly a Figma security engineer and now at Nition, are the named voices. The numbers are Figma&rsquo;s own and should be read as such, but they are specific enough to argue with: 70% faster resolution on complex alerts, 20% fewer on-call pages, more than 100 previously unknown vulnerabilities found including two critical flaws that traditional tooling missed, 80% code-reviewer precision within a month of deployment, 30% better detection of known bug classes, and 50% fewer instances of certain coding errors. The shape of that list is the lesson. The wins are in triage throughput and reviewer coverage &mdash; the two places where the constraint has always been analyst hours rather than analyst skill &mdash; and the integration list is entirely off-the-shelf. Nothing in it requires a frontier lab partnership; it requires a SIEM with a queryable API and someone willing to own the prompt.<\/p>\n<p>CrowdStrike&rsquo;s Fal.Con announcement is the other end of the same market. The company launched a model-harness system called SafeMind, an offensive model named Red Tempest, a defensive frontier-class model named Blue Solano, and a trusted-access programme called Project QuiltWorks, all run out of a newly created Cyber Superintelligence Lab headed by Dr. Bartley Richardson, previously of Nvidia, with Nvidia as partner. George Kurtz calls it the &ldquo;first complete agentic system for cybersecurity,&rdquo; and his framing of why it exists is the honest part: &ldquo;The real gap that I saw was that the attackers had frontier AI and the defenders didn&rsquo;t.&rdquo; No pricing was given, which is the detail to press on in the first meeting. F5&rsquo;s announcement the following day is worth more attention than its headline gives it. The reporting fronts faster virtual patching, but the release gives at least equal weight to newly added anomaly detection and agentic threat intelligence across F5 WAF for Distributed Cloud and F5 WAF for BIG-IP; F5&rsquo;s own framing is &ldquo;innovations to block frontier AI-driven threats.&rdquo; For anyone sitting on the patch backlog described earlier in this issue, virtual patching is the headline feature but anomaly detection is the one that keeps working when the signature does not exist yet.<\/p>\n<p>The counterweight comes from someone who actually runs an ingestion pipeline. Ankit Kumar Honey, senior engineering manager at GitHub, writes from operating Dependabot&rsquo;s malware detection across more than 30 million repositories and eight package ecosystems, and his figure &mdash; roughly 18 new malicious npm packages a day &mdash; is the kind of number that reframes what a &ldquo;feed&rdquo; is. His argument is that subscribing to threat intelligence is trivial and operating it is not: someone has to own schema drift, false-positive rates, retraction handling and the blast radius of an automated block. His warning is the line to put above the integration ticket: treat it as a checkbox &ldquo;and sooner or later you will automate someone else&rsquo;s worst day into your own.&rdquo; VentureBeat&rsquo;s piece supplies the same caution one layer up, on agents that authenticate perfectly well and then drift, expose data or get their memory poisoned &mdash; a reminder that in an agentic SOC the authentication event is the beginning of the monitoring problem rather than the end of it.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.infoq.com\/news\/2026\/09\/figma-security-agents\/\">InfoQ (how Figma uses AI agents for security)<\/a> &middot; <a href=\"https:\/\/www.csoonline.com\/article\/4217135\/crowdstrike-launches-cyber-frontier-ai-models-agentic-security-system.html\">CSO Online (CrowdStrike frontier AI models and agentic security system)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/02\/f5-waf-anomaly-detection-ai-threats\/\">Help Net Security (F5 WAF anomaly detection and virtual patching)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/03\/github-threat-intelligence-feed-ingestion\/\">Help Net Security (ingesting malware intel at scale)<\/a> &middot; <a href=\"https:\/\/venturebeat.com\/security\/ai-agents-that-pass-authentication-can-still-drift-expose-data-or-get-memory-poisoned\">VentureBeat (agents that pass authentication and still drift)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>6. A billion dollars of access, a hundred signatures, and money moving into AI runtime security<\/h4>\n<p class=\"meta\">Cybersecurity Dive &middot; The Register &middot; SecurityWeek &middot; Infosecurity Magazine &middot; Dark Reading &middot; September 2&ndash;4, 2026<\/p>\n<p>OpenAI&rsquo;s $1 billion commitment is not a cheque, and the distinction changes what you should expect from it. The programme is called &ldquo;Daybreak for Frontline Defenders,&rdquo; it is structured as a six-month pilot with broader rollout planned, and the billion is subsidised access and training rather than cash. The intended recipients are the organisations that have never had a security budget worth the name: water and power utilities, municipal and local government, community banks, healthcare organisations, and open-source maintainers. Brian Calkin, chief technology and innovation officer at the Center for Internet Security, gives the reason it matters at that tier &mdash; &ldquo;That is a serious problem for state and local governments because they run the systems communities depend on every day&rdquo; &mdash; and Errol Weiss, chief security officer at Health-ISAC, supplies the healthcare view. For a SOC in a large enterprise the direct relevance is limited, but the second-order effect is not: a meaningful fraction of your third-party risk lives in exactly those categories, and subsidised tooling at a municipal water authority is a supply-chain improvement whether or not anyone books it as one.<\/p>\n<p>The Register&rsquo;s piece from the previous week covers the related but separate initiative, and its headline gives no clue what the story is: it is coverage of an open letter coordinated by OpenAI and signed by more than 100 technology companies warning about AI-enabled cyber threats. The signatory list is the point &mdash; OpenAI, Anthropic, Google, Microsoft, Cloudflare, CrowdStrike, Fortinet, Palo Alto Networks, AWS, IBM, Oracle and Cisco, plus banks and consultancies &mdash; and the letter&rsquo;s claim is that &ldquo;we have a limited window to strengthen cyber defenses,&rdquo; with attacks set to become &ldquo;far more widespread and sophisticated.&rdquo; The Register declines to take it at face value, and its closing observation deserves repeating in any meeting where the letter is cited as consensus: when more than 100 companies agree that status quo security will not be enough, it is worth remembering that many of them have been selling that status quo for years. Both things can be true. The letter is a useful lever for a budget conversation and a poor substitute for evidence.<\/p>\n<p>The rest of the week&rsquo;s market news points the same way. SecurityWeek reports a new funding round for HiddenLayer, aimed squarely at AI runtime security &mdash; the layer that watches models and agents while they are executing rather than scanning them before deployment, which is precisely the gap the agent-drift and memory-poisoning coverage keeps describing. Infosecurity Magazine reports that CREST has onboarded its first cohort for AI-enabled pentesting accreditation, which is the institutional half of the same story: if AI-assisted offensive testing is going to be bought as a service, someone has to define what competence looks like, and an accreditation scheme is the mechanism procurement teams already know how to use. And Dark Reading&rsquo;s conversation with Rick Holland on securing AI agents covers the practitioner ground underneath all of it &mdash; data, identity and trust, in that order, which is roughly the order in which agent deployments go wrong.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.cybersecuritydive.com\/news\/openai-pledges-1-billion-resources-cyber-defenders\/829676\/\">Cybersecurity Dive (OpenAI $1B for frontline defenders)<\/a> &middot; <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/28\/industry-that-built-the-problem-offers-to-sell-you-the-solution\/5293207\">The Register (the OpenAI-coordinated open letter)<\/a> &middot; <a href=\"https:\/\/www.securityweek.com\/hiddenlayer-raises-100-million-for-ai-runtime-security\/\">SecurityWeek (HiddenLayer funding for AI runtime security)<\/a> &middot; <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/crest-first-cohort-ai-pentesting\/\">Infosecurity Magazine (CREST AI-enabled pentesting accreditation)<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/securing-ai-agents-rick-holland-on-data-identity-and-trust\">Dark Reading (Rick Holland on securing AI agents)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>7. When the control is the incident<\/h4>\n<p class=\"meta\">Help Net Security &middot; CSO Online &middot; BleepingComputer &middot; SC Media &middot; August 31 &ndash; September 4, 2026<\/p>\n<p>Beginning in October 2026, Microsoft will switch memory integrity on automatically for eligible Windows devices, and where it is not already running, Virtualization-based Security will be enabled to support it. The security case is not in dispute. The operational sting is in the delivery mechanism: the change arrives through the normal quality-update channel, which means it lands on your estate without passing through a change-request process on the admin side. Eligibility is decided by Windows itself, assessed against hardware capability, driver and application compatibility, and performance headroom &mdash; so the population that flips is determined by a vendor heuristic rather than by your inventory. Two details take some of the edge off. Devices where memory integrity has already been explicitly disabled will not be turned on by the rollout &mdash; Peter Waxman, group program manager at Microsoft, is explicit that &ldquo;existing administrator and user decisions and policies remain in effect. This means that devices where memory integrity has already been disabled won&rsquo;t be automatically changed by this rollout&rdquo; &mdash; and once memory integrity is enabled, hotpatch updates no longer require a reboot, which is a real reduction in change-window pressure for anyone running the hotpatch channel. The action item is to find out now which of your devices Windows considers eligible, and to have an answer ready for the driver-compatibility calls that will arrive in October.<\/p>\n<p>The two Defender stories in this cluster are separate incidents four days apart, and they fail in different ways. The first, reported by CSO Online on 31 August, is a Windows bug that falsely notifies users that Microsoft Defender Antivirus is turned off, while the product is in fact fully functional and every setting shows it active. The alerts appear at startup and intermittently afterwards, and the affected list spans Windows 11 version 26H1 and Windows Server 2025 down to Windows 10 Enterprise LTSC 2016 and Windows Server 2012; no KB number is given in the advisory. The security consequence is not the alert but the habit it builds. Disabling endpoint protection is a standard precursor to ransomware detonation, and the &ldquo;Defender is off&rdquo; notification is precisely the signal a user is supposed to escalate. Train a population to dismiss it for weeks and you have degraded a detection channel that costs nothing to run and cannot be replaced by tooling.<\/p>\n<p>The second is unrelated in cause and closer to home for the SOC queue. On 2 September, Microsoft Defender for Office 365 Safe Links began flagging legitimate Google Search links as malicious, showing &ldquo;Opening this website might not be safe&rdquo; at time-of-click verification. Microsoft acknowledged the issue at 10:30 UTC that day, attributed it to &ldquo;an inaccurate security classification,&rdquo; and warned administrators to expect related alerts in Microsoft Sentinel and the Defender portal &mdash; which is the part that costs analyst hours, because a Safe Links verdict does not stay in the user&rsquo;s browser, it generates incidents. The fix was declared &ldquo;successfully resolved&rdquo; on 3 September, with residual impact while the mitigation propagated. Worth checking whether any detection rules or SOAR playbooks fired on those verdicts during the window, and whether anything auto-remediated on the strength of them. SC Media closes the cluster from the attacker&rsquo;s side, reporting Microsoft&rsquo;s warning that ASCII smuggling challenges email phishing filters &mdash; a reminder that the same gateway generating false positives this week has a real evasion problem to solve as well.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/03\/windows-memory-integrity-update\/\">Help Net Security (Windows memory integrity auto-enablement)<\/a> &middot; <a href=\"https:\/\/www.csoonline.com\/article\/4216607\/windows-bug-incorrectly-tells-users-that-microsoft-defender-antivirus-is-turned-off-2.html\">CSO Online (false Defender Antivirus disabled notification)<\/a> &middot; <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/microsoft-defender-flags-legitimate-google-search-links-as-malicious\/\">BleepingComputer (Defender for Office 365 Safe Links false positives)<\/a> &middot; <a href=\"https:\/\/www.scworld.com\/news\/ascii-smuggling-challenges-email-phishing-filters-microsoft-warns\">SC Media (ASCII smuggling and email phishing filters)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>8. Patching was never the whole job<\/h4>\n<p class=\"meta\">The Register &middot; BleepingComputer &middot; Network World &middot; Cybersecurity Dive &middot; August 25 &ndash; September 3, 2026<\/p>\n<p>The Register&rsquo;s headline counts the 1,449 security patches Oracle shipped in its late-July dump, and the point of the count is that none of them would have helped. There is no Oracle product flaw in this incident and no CVE attached to it. The intrusion begins with SQL injection against a public-facing web application backed by an Oracle database; from there the attackers uploaded Java source code directly into the database and used it to deploy a toolkit called &ldquo;khunt.&rdquo; Every step after the initial injection runs on functionality that was working exactly as designed &mdash; Java compilation left enabled in a production database, and an application-tier input-handling failure that no vendor patch addresses. Huntress raised the alert. Craig Savage of Spinnaker Support supplies the trend line: &ldquo;We&rsquo;re starting to see more and more of this: these cybercrime gangs now know about these products.&rdquo; Read against the rest of this issue, it is the necessary corrective. Six of the eight clusters above are about the patch queue and the machinery for prioritising it; this one is about the fact that a fully patched estate with Java enabled in the database tier and an unparameterised query in front of it is still a compromise waiting for someone with a scanner.<\/p>\n<p>Three shorter items close the issue on the identity and readiness side. BleepingComputer works through what to actually do when an employee&rsquo;s password turns up in an infostealer log &mdash; a scenario that has quietly become one of the most common initial-access paths and one of the least proceduralised responses in most SOCs, because it starts with intelligence from outside the perimeter rather than an alert from inside it. Network World reports Tailscale expanding from VPN into a broader connectivity platform, which is worth tracking for the boring operational reason that the access layer determines what your identity controls actually cover, and every expansion of it is a scope change for the team that monitors it. And Cybersecurity Dive covers CISA&rsquo;s account of two red-team engagements that produced very different results, and the security hurdles that explain the gap. That is the one to circulate to leadership: it is the closest thing available to a controlled comparison of what actually determines whether an organisation detects an intrusion, and it costs nothing but the reading time.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/25\/you-couldve-applied-all-1449-oracle-patches-and-still-been-hit-by-this-attack\/5292335\">The Register (SQL injection, Java in the database and the khunt toolkit)<\/a> &middot; <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/your-employees-password-appeared-in-an-infostealer-log-now-what\/\">BleepingComputer (responding to credentials in an infostealer log)<\/a> &middot; <a href=\"https:\/\/www.networkworld.com\/article\/4215616\/tailscale-expands-from-vpn-into-a-full-connectivity-platform.html\">Network World (Tailscale expands beyond VPN)<\/a> &middot; <a href=\"https:\/\/www.cybersecuritydive.com\/news\/cisa-red-team-exercises-lessons-cloud-soc\/828733\/\">Cybersecurity Dive (CISA on two red-team engagements)<\/a><\/p>\n<\/p><\/div>\n<p>            <!-- Calls to action --><\/p>\n<h2>Calls to action<\/h2>\n<p>Six things worth doing in the next week, drawn directly from this issue:<\/p>\n<ul style=\"font-size:14.5px;line-height:1.6;color:#1f2937;padding-left:20px;margin:0 0 14px 0;\">\n<li><strong>Scan yourself for CVE-2026-62911 before someone else does.<\/strong> The fix has been available since 11 August and nearly 22,000 servers still have not taken it. Confirm every Exchange 2016 and 2019 instance you own &mdash; including the ones running under Extended Security Updates and the ones nobody has logged into since a migration stalled &mdash; and check them against the NCSC-NL advisory, because public exploit code is already circulating.<\/li>\n<li><strong>Put Kestra, LiteLLM and Starlette on the asset inventory today.<\/strong> Three of the seven KEV additions on 2 September sit in AI and workflow-orchestration infrastructure, with deadlines of 5 and 16 September under BOD 26-04. Find out who deployed them, who patches them, and whether anything in your monitoring treats them as the control plane they are rather than as an application.<\/li>\n<li><strong>Block TCP 43210 and 43211 at the infrastructure ACL.<\/strong> CVE-2026-20212 gives unauthenticated root on ten Nexus 9000 models through ports reachable in the default Layer 3 VRF, and there is mitigation but no permanent fix. Cisco&rsquo;s iACL guidance is the whole remedy available right now; apply it and then schedule the IOS XR update release separately.<\/li>\n<li><strong>Patch the analyst bench.<\/strong> CVE-2026-59346 and CVE-2026-59347 are VM escapes through the VMXNET3 adapter in Workstation and Fusion 25H2 and 26H1, fixed only in 26H1u1 with no workarounds. The machines most exposed to this are the ones your own team uses to detonate samples.<\/li>\n<li><strong>Re-baseline your triage cost, not your scan coverage.<\/strong> Contrast&rsquo;s split &mdash; roughly $315 to scan two million lines, roughly $128,000 to triage the output &mdash; is the number to reproduce internally. Measure what one AI-generated finding costs your team to close out, then decide how many scanners you can afford to run, rather than the other way round.<\/li>\n<li><strong>Audit what fired during the Safe Links window.<\/strong> Defender for Office 365 misclassified Google Search links between 2 and 3 September and generated alerts in Sentinel and the Defender portal. Check whether any detection rule, playbook or auto-remediation acted on those verdicts, and whether any user-reported phishing volume during that window is still sitting unreviewed in the queue.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<p>        <!-- Footer --><\/p>\n<tr>\n<td class=\"footer\">\n<p class=\"brand\">Security Operations Weekly<\/p>\n<p>A weekly intelligence bulletin from Security Radar LLC.<br \/>\n            Curated by Paul Davis &middot; <a href=\"mailto:paul.davis@security-radar.com\">paul.davis@security-radar.com<\/a><\/p>\n<p>&copy; 2026 Security Radar LLC. All rights reserved.<\/p>\n<p>Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.<\/p>\n<p>*|LIST:ADDRESS|*<\/p>\n<p><a href=\"*|ARCHIVE|*\">View this email in your browser<\/a> &middot; <a href=\"*|UNSUB|*\">Unsubscribe<\/a><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>September 6, 2026 &middot; Weekly Edition Security Operations Weekly A heavy patch week, and the numbers underneath it are the story. Nearly 22,000 Exchange servers were still exposed three weeks after Microsoft shipped the fix. Cisco ran an internal review of IOS XR and found so much that it bundled&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[38],"tags":[],"class_list":["post-5843","post","type-post","status-publish","format-standard","hentry","category-security-operations"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5843","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5843"}],"version-history":[{"count":1,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5843\/revisions"}],"predecessor-version":[{"id":5845,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5843\/revisions\/5845"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5843"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5843"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5843"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}