Enterprise Cybersecurity IntelligenceThursday

An enterprise cybersecurity intelligence company.For security and technology leaders.

Security.io Intelligence

What changed, why it matters,
and how it evolved.

Security.io Daily Headlines · 5 minutes

Security.io Daily Headlines — Thursday, September 24, 2026

Five equally weighted developments: what happened and the leadership decision each creates.

Audio briefing

Listen to today’s episode

Listen to the edition’s five developments and leadership decisions.

Episode transcript

5 developments · Executive decision context

This is Max Vogal from Security.io with today’s Daily Headlines for Thursday, September 24, 2026. Here are the top five security developments shaping today’s decisions—what happened, why each matters now, and the leadership action to consider.

01
Headline 1

F5 BIG-IP APM OAuth zero-day demands patching and compromise assessment

What happened

F5 reported active exploitation of CVE-2026-94127, a critical BIG-IP APM heap-based buffer overflow affecting virtual servers that combine an APM access policy with an OAuth profile. On September 22, 2026, the Canadian Centre for Cyber Security said F5 had reported active exploitation of CVE-2026-94127 and published fixed hotfix releases.

The leadership decision

Security leaders should inventory BIG-IP APM virtual servers and flag those combining an access policy with an OAuth profile. Assign network engineering to produce a configuration-level exposure list, not a procurement or CMDB list of every F5 device. Run incident response in parallel with remediation.

Full reporting and sources →
02
Headline 2

Astrana Health discloses material cyber incident after phone spoofing

What happened

Astrana Health filed an Item 1.05 Form 8-K after determining that a social-engineering-driven incident was material because of the potentially sensitive data involved. The investigation into the nature, scope and impact remains open. The company said it intends to make required notifications, including to affected patients, based on its findings.

The leadership decision

Security leaders should brief incident, privacy, legal and payer-relations owners on the SEC filing. Treat phone-number spoofing and personnel impersonation as an identity-control failure path, not only a user-awareness issue. Preserve the evidence needed to reconstruct calls, authentication and subsequent system activity.

Full reporting and sources →
03
Headline 3

EvilTokens disruption exposes a faster device-code phishing-to-fraud cycle

What happened

Microsoft and partners disrupted EvilTokens after linking the service to more than 12,000 compromised inboxes across over 10,000 organisations. Microsoft's disruption of EvilTokens documents an industrialised device-code phishing service that combined token theft, mailbox analysis, target selection and fraud preparation across more than 10,000 organisations.

The leadership decision

Security leaders should block device-code flow except for documented resource accounts and approved devices. Assign the identity owner to enumerate every legitimate dependency on device-code flow and block it by default through Conditional Access. Exceptions should be limited to named resource accounts and devices, with an owner, business purpose, expiry date and monitoring requirement.

Full reporting and sources →
04
Headline 4

FBIJobs.gov compromise claim leaves breach origin and PII impact unresolved

What happened

The FBI acknowledged an investigation into claims that FBIJobs.gov was compromised and employee PII affected. It said the point of breach remains undetermined between a third-party provider and its own enterprise. The FBI said the point of breach remained undetermined between a third-party provider and the FBI enterprise.

The leadership decision

Security leaders should identify every recruitment and applicant portal operated by a third party. Assign the third-party risk owner to produce a data-flow and responsibility map for recruitment platforms, including stored data classes, administrative identities, integrations, retention, logging and incident-evidence commitments.

Full reporting and sources →
05
Headline 5

Non-expiring GitHub App keys turn forgotten leaks into live supply-chain paths

What happened

GitGuardian's new measurement shows that a documented GitHub design property—private keys remain valid until manually revoked—has left hundreds of publicly exposed App credentials operational. Research found 474 still-valid GitHub App private keys among 4,802 tested exposures, including credentials with repository-write, workflow, runner and organisation-administration permissions.

The leadership decision

Security leaders should enumerate all GitHub Apps, installations, permissions and private-key fingerprints. Assign application security or developer-platform engineering to build a complete GitHub App register across enterprise organisations. Record the App owner, publisher, installations, repositories, permissions, key fingerprints, storage location, last rotation and business dependency.

Full reporting and sources →

That’s Security.io Daily Headlines for Thursday, September 24, 2026. Full reporting, sources, executive actions and today’s comic are available in the complete edition at Security.io. I’m Max Vogal. Thanks for listening.