Security.io Daily Headlines — Thursday, September 24, 2026
Five equally weighted developments: what happened and the leadership decision each creates.
Listen to today’s episode
Listen to the edition’s five developments and leadership decisions.
Episode transcript
5 developments · Executive decision contextThis is Max Vogal from Security.io with today’s Daily Headlines for Thursday, September 24, 2026. Here are the top five security developments shaping today’s decisions—what happened, why each matters now, and the leadership action to consider.
F5 BIG-IP APM OAuth zero-day demands patching and compromise assessment
What happened
F5 reported active exploitation of CVE-2026-94127, a critical BIG-IP APM heap-based buffer overflow affecting virtual servers that combine an APM access policy with an OAuth profile. On September 22, 2026, the Canadian Centre for Cyber Security said F5 had reported active exploitation of CVE-2026-94127 and published fixed hotfix releases.
The leadership decision
Security leaders should inventory BIG-IP APM virtual servers and flag those combining an access policy with an OAuth profile. Assign network engineering to produce a configuration-level exposure list, not a procurement or CMDB list of every F5 device. Run incident response in parallel with remediation.
Astrana Health discloses material cyber incident after phone spoofing
What happened
Astrana Health filed an Item 1.05 Form 8-K after determining that a social-engineering-driven incident was material because of the potentially sensitive data involved. The investigation into the nature, scope and impact remains open. The company said it intends to make required notifications, including to affected patients, based on its findings.
The leadership decision
Security leaders should brief incident, privacy, legal and payer-relations owners on the SEC filing. Treat phone-number spoofing and personnel impersonation as an identity-control failure path, not only a user-awareness issue. Preserve the evidence needed to reconstruct calls, authentication and subsequent system activity.
EvilTokens disruption exposes a faster device-code phishing-to-fraud cycle
What happened
Microsoft and partners disrupted EvilTokens after linking the service to more than 12,000 compromised inboxes across over 10,000 organisations. Microsoft's disruption of EvilTokens documents an industrialised device-code phishing service that combined token theft, mailbox analysis, target selection and fraud preparation across more than 10,000 organisations.
The leadership decision
Security leaders should block device-code flow except for documented resource accounts and approved devices. Assign the identity owner to enumerate every legitimate dependency on device-code flow and block it by default through Conditional Access. Exceptions should be limited to named resource accounts and devices, with an owner, business purpose, expiry date and monitoring requirement.
FBIJobs.gov compromise claim leaves breach origin and PII impact unresolved
What happened
The FBI acknowledged an investigation into claims that FBIJobs.gov was compromised and employee PII affected. It said the point of breach remains undetermined between a third-party provider and its own enterprise. The FBI said the point of breach remained undetermined between a third-party provider and the FBI enterprise.
The leadership decision
Security leaders should identify every recruitment and applicant portal operated by a third party. Assign the third-party risk owner to produce a data-flow and responsibility map for recruitment platforms, including stored data classes, administrative identities, integrations, retention, logging and incident-evidence commitments.
Non-expiring GitHub App keys turn forgotten leaks into live supply-chain paths
What happened
GitGuardian's new measurement shows that a documented GitHub design property—private keys remain valid until manually revoked—has left hundreds of publicly exposed App credentials operational. Research found 474 still-valid GitHub App private keys among 4,802 tested exposures, including credentials with repository-write, workflow, runner and organisation-administration permissions.
The leadership decision
Security leaders should enumerate all GitHub Apps, installations, permissions and private-key fingerprints. Assign application security or developer-platform engineering to build a complete GitHub App register across enterprise organisations. Record the App owner, publisher, installations, repositories, permissions, key fingerprints, storage location, last rotation and business dependency.
That’s Security.io Daily Headlines for Thursday, September 24, 2026. Full reporting, sources, executive actions and today’s comic are available in the complete edition at Security.io. I’m Max Vogal. Thanks for listening.