Security.io Daily Headlines — Friday, September 11, 2026
Five equally weighted developments: what happened and the leadership decision each creates.
Episode transcript
566 words · Sponsor after story threeThis is Max Vogal from Security.io with today’s Daily Headlines for Friday, September 11, 2026. Here are the top five security developments shaping today’s decisions—what happened, why each matters now, and the leadership action to consider.
EU product-security reporting clock starts today
What happened
Article 14 reporting under the EU Cyber Resilience Act applies from today. Covered manufacturers need a defensible process for recognising a reportable indication, submitting the 24-hour warning, enriching it within 72 hours and coordinating subsequent reports without compromising investigation or3.
The leadership decision
Security leaders should name the accountable CRA reporting executive and two deputies. Assign one accountable decision owner across product security, incident response and legal. A committee can advise, but it cannot be allowed to obscure when the organisation became aware or who authorised the early warning.
AdaptHealth breach scope reaches 4.1 million people
What happened
AdaptHealth’s earlier material-incident disclosure has been followed by reporting that 4,115,802 people were affected. The intrusion began with social engineering of a third-party contractor session and reached cloud applications containing patient, health-insurance and billing information.
The leadership decision
Security leaders should review contractor authentication methods and active cloud sessions. Treat contractor session compromise as an identity-control failure spanning every connected cloud service, not as a single disabled account. Assign identity engineering to reconstruct authentication, token, device and security-information changes across the affected period.
Check Point VPN flaws expose gateways and management servers
What happened
Check Point disclosed CVE-2026-85102 and CVE-2026-85103, two critical VPN certificate-processing vulnerabilities capable of unauthenticated remote code execution. CERT-EU now urges immediate hotfixing of affected perimeter and management appliances. Two unauthenticated code-execution paths affect Check Point gateway and management products, including end-of-support branches; CERT-EU’s new guidance prioritises perimeter remediation.
The leadership decision
Security leaders should inventory every affected Check Point appliance and release branch. Set remediation priority by placement, not CVSS alone. Internet-facing VPN gateways, Security Management Servers and appliances bridging sensitive network zones should precede internally isolated devices, while end-of-support exceptions require explicit executive acceptance.
LiteLLM defaults turn AI gateways into credential exposure paths
What happened
Wiz found 294 of 3,074 public LiteLLM instances in a point-in-time sample accepted the example master key or required no authentication. Older vulnerable versions could combine that access with container-level code execution and credential theft.
The leadership decision
Security leaders should discover every LiteLLM gateway across cloud and development accounts. Classify LiteLLM as a privileged AI control plane. Assign ownership for authentication, internet exposure, secret storage, provider access, logging, upgrades and Model Context Protocol connections rather than leaving responsibility with individual development teams.
Xinbi disruption changes sanctions and fraud-control priorities
What happened
Treasury designated Xinbi Guarantee and two supporting technology companies, while DOJ reported more than US$52 million restrained across marketplace and vendor wallets. The action creates immediate sanctions, payment-monitoring and fraud-intelligence work. On 26 March 2026, the United Kingdom had already sanctioned Xinbi under its Global Human Rights sanctions regime.
The leadership decision
Security leaders should load the new designations into authorised sanctions-screening systems. Assign sanctions operations, fraud intelligence and security monitoring separate but connected tasks. Screening determines legal handling, fraud teams examine victim and transaction behaviour, and threat intelligence tracks infrastructure changes without conflating suspicion with confirmed illegality.
That’s Security.io Daily Headlines for Friday, September 11, 2026. Full reporting, sources, executive actions and today’s comic are available in the complete edition at Security.io. I’m Max Vogal. Thanks for listening.