Security.io Daily Headlines — Wednesday, September 23, 2026
Five equally weighted developments: what happened and the leadership decision each creates.
Listen to today’s episode
Listen to the edition’s five developments and leadership decisions.
Episode transcript
5 developments · Executive decision contextThis is Max Vogal from Security.io with today’s Daily Headlines for Wednesday, September 23, 2026. Here are the top five security developments shaping today’s decisions—what happened, why each matters now, and the leadership action to consider.
Check Point management zero-day requires compromise hunting, not patch-only closure
What happened
Confirmed exploitation against privileged Check Point gateway and management infrastructure makes patch-only closure indefensible. Check Point has confirmed exploitation of two pre-authentication flaws across gateway and management products, including a newly fixed CVSS 9.8 management-server zero-day.
The leadership decision
Security leaders should assign infrastructure owners to reconcile Check Point assets against affected versions and fixed hotfix levels. Run this as a potential control-plane incident, not a routine vulnerability ticket. The security-management environment governs policy and records administrative activity; evidence collection must therefore precede changes that could overwrite logs, remove artefacts or impair later reconstruction.
EvilTokens disruption opens a narrow window for identity clean-up
What happened
A court-authorised disruption removed core EvilTokens infrastructure after a campaign affecting thousands of enterprises. Microsoft and partners disrupted EvilTokens after linking the device-code phishing service to more than 12,000 compromised inboxes. On September 22, 2026, Microsoft disclosed a court-authorised disruption that followed arrests of two men on September 11, 2026.
The leadership decision
Security leaders should disable device-code authentication wherever no documented business requirement exists. Use the disruption as a hunting trigger, not a declaration that exposure has ended. Identity engineering should define the legitimate device-code population, while the SOC searches for authentication, token, device and mailbox events that fall outside it.
Boston Scientific publishes final forensic scope after material disruption
What happened
The final forensic summary materially narrows the known Boston Scientific incident scope while leaving a significant operational and financial consequence on record. Boston Scientific has published CrowdStrike’s final investigation scope after a cyber incident disrupted global manufacturing, order processing and shipping.
The leadership decision
Security leaders should update supplier-risk records with the final forensic scope and its stated limitations. Accept the report as material new evidence, but preserve the distinction between a commissioned forensic conclusion and independent assurance. Record which systems were examined, which conclusions were negative findings and which technical details were not disclosed.
Miljödata ruling raises the evidence bar for supplier security
What happened
A new Swedish regulatory decision turns an older supplier breach into current guidance on what defensible security evidence must show: controlled software installation, continuous monitoring and risk-appropriate protection for sensitive personal data. Sweden’s privacy regulator has fined HR and workplace-systems provider Miljödata after an intrusion affecting 2.2 million people.
The leadership decision
Security leaders should identify processors holding national identifiers, health, employment or child-related information. Convert the ruling into an assurance test rather than circulating it as regulatory news. Supplier owners should obtain artefacts showing software approval, integrity checking, change validation, logging, monitoring coverage and incident escalation for systems processing sensitive personal data.
TrustSink shows why external MFA providers need control-plane monitoring
What happened
TrustSink is a laboratory post-compromise technique, not confirmed active exploitation. New reporting has operationalised Varonis research showing how a compromised Global Administrator or Authentication Policy Administrator can register a rogue external MFA provider that captures replacement passwords inside a normal Microsoft Entra sign-in.
The leadership decision
Security leaders should inventory every configured External Authentication Method provider and assigned group. Treat authentication-provider configuration as a privileged control plane. Require named ownership, approval, time-bounded administrative access and monitoring for every external provider, application, key, consent grant and user-group assignment.
That’s Security.io Daily Headlines for Wednesday, September 23, 2026. Full reporting, sources, executive actions and today’s comic are available in the complete edition at Security.io. I’m Max Vogal. Thanks for listening.