Summary
In week 39 of 2026 (Sept. 21–28), security events declined week over week to 16 advisories and 23 incidents affecting about 13.2 million known individuals. The largest was a ransomware attack that halted trading on the Nepal Stock Exchange (8 million exposed). Third-party compromise and unauthorized access were the leading causes. Finance is the most-hit sector. Actively exploited zero-days in Check Point, Citrix, F5, SharePoint and WordPress.
Take Action:
Patch the actively exploited systems ASAP (Citrix NetScaler ADC and Gateway, Check Point gateways and management servers, VeloCloud Orchestrator, on-prem SharePoint, Zyxel GS1900 switches and WordPress). As usual, block internet access to their admin and management interfaces so only trusted internal IPs can reach them. Update Chrome and if you manage GitLab, reset your incoming email token and remove any "email to project" addresses you've posted publicly, because anyone who has that address can act as you.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)