Enterprise Cybersecurity IntelligenceMonday

An enterprise cybersecurity intelligence company.For security and technology leaders.

Security.io Intelligence

What changed, why it matters,
and how it evolved.

Security.io Daily Headlines · 5 minutes

Security.io Daily Headlines — Monday, September 28, 2026

Five equally weighted developments: what happened and the leadership decision each creates.

Audio briefing

Listen to today’s episode

Listen to the edition’s five developments and leadership decisions.

Episode transcript

5 developments · Executive decision context

This is Max Vogal from Security.io with today’s Daily Headlines for Monday, September 28, 2026. Here are the top five security developments shaping today’s decisions—what happened, why each matters now, and the leadership action to consider.

01
Headline 1

Kiteworks lifts weekend shutdown, but restart is not closure

What happened

Kiteworks lifted its weekend shutdown recommendation on Sunday and said hosted systems were operating normally. The company still reports no indication of compromise, but has not published a CVE, exploit description or indicators. Kiteworks said release 9.5.1 addresses all vulnerabilities known to the company and remains the recommended release.

The leadership decision

Security leaders should reconcile every Kiteworks deployment against the CMDB and vendor account records. The CISO and CIO should treat restart as a deployment-level risk decision, not a blanket consequence of the vendor lifting its recommendation. Assign separate owners for availability restoration and compromise assessment.

Full reporting and sources →
02
Headline 2

SharePoint KEV addition turns patching into a compromise hunt

What happened

Previdian observed a two-stage SharePoint exploitation attempt and published hunt-ready artefacts before CISA added CVE-2026-65660 to KEV. Apply the fixed builds, review anonymous access and search for the published requests, webshell path, loader names and hashes.

The leadership decision

Security leaders should identify every on-premises SharePoint server and its external exposure. Direct vulnerability management to provide more than a patch-compliance percentage. The decision record should connect each SharePoint instance to its build, internet exposure, anonymous-access configuration, update history, log retention and hunt result.

Full reporting and sources →
03
Headline 3

DMDC breach tests whether personnel-data controls extend to file shares

What happened

Reporting based on a DMDC notification says unauthorised users accessed unencrypted personnel information between October 2025 and July 2026. The potential population may be approximately four million, but DoD has not confirmed that estimate. The precise population, product, vulnerability and responsible actor remain unconfirmed.

The leadership decision

Security leaders should find unencrypted personnel exports and file shares outside approved systems of record. Assign the data-protection owner to produce a repository-level view of workforce information, including exports, file shares, analytics staging areas and legacy collaboration stores. Require evidence of encryption, access approval, monitoring and retention for each location.

Full reporting and sources →
04
Headline 4

SalesBleed reframes agent permissions as privileged access

What happened

Zenity demonstrated that Salesforce Agentforce could be influenced by malicious CRM content and use a Slack write action without confirmation or clear invoker attribution. Salesforce remediated the reported paths before disclosure. On June 1, 2026, Zenity Labs reported the Agentforce findings to Salesforce.

The leadership decision

Security leaders should inventory agents that process externally supplied records. Treat enterprise agents as privileged identities with delegated tools, not as user-interface features. Assign the AI platform owner to document the agent’s input sources, run-as identity, accessible objects, subagents, actions, approval controls and communication destinations.

Full reporting and sources →
05
Headline 5

WSO2 KEV listing forces an API control-plane review

What happened

CISA added CVE-2026-5430 to KEV on Friday after the WSO2 JWT authentication-bypass advisory had been public since May. Affected API-control components require precise update-level verification and a separate review for unauthorised administrative access. The flaw can bypass JWT authentication and expose administrative control.

The leadership decision

Security leaders should inventory every affected WSO2 component and owner. Require application and platform owners to reconcile WSO2 deployments against network, cloud and software inventories, including dormant nodes and disaster-recovery instances. The update decision must use the product-specific levels in the advisory, not a generic assertion that the environment is current.

Full reporting and sources →

That’s Security.io Daily Headlines for Monday, September 28, 2026. Full reporting, sources, executive actions and today’s comic are available in the complete edition at Security.io. I’m Max Vogal. Thanks for listening.