Security.io Daily Headlines — Monday, September 28, 2026
Five equally weighted developments: what happened and the leadership decision each creates.
Listen to today’s episode
Listen to the edition’s five developments and leadership decisions.
Episode transcript
5 developments · Executive decision contextThis is Max Vogal from Security.io with today’s Daily Headlines for Monday, September 28, 2026. Here are the top five security developments shaping today’s decisions—what happened, why each matters now, and the leadership action to consider.
Kiteworks lifts weekend shutdown, but restart is not closure
What happened
Kiteworks lifted its weekend shutdown recommendation on Sunday and said hosted systems were operating normally. The company still reports no indication of compromise, but has not published a CVE, exploit description or indicators. Kiteworks said release 9.5.1 addresses all vulnerabilities known to the company and remains the recommended release.
The leadership decision
Security leaders should reconcile every Kiteworks deployment against the CMDB and vendor account records. The CISO and CIO should treat restart as a deployment-level risk decision, not a blanket consequence of the vendor lifting its recommendation. Assign separate owners for availability restoration and compromise assessment.
SharePoint KEV addition turns patching into a compromise hunt
What happened
Previdian observed a two-stage SharePoint exploitation attempt and published hunt-ready artefacts before CISA added CVE-2026-65660 to KEV. Apply the fixed builds, review anonymous access and search for the published requests, webshell path, loader names and hashes.
The leadership decision
Security leaders should identify every on-premises SharePoint server and its external exposure. Direct vulnerability management to provide more than a patch-compliance percentage. The decision record should connect each SharePoint instance to its build, internet exposure, anonymous-access configuration, update history, log retention and hunt result.
DMDC breach tests whether personnel-data controls extend to file shares
What happened
Reporting based on a DMDC notification says unauthorised users accessed unencrypted personnel information between October 2025 and July 2026. The potential population may be approximately four million, but DoD has not confirmed that estimate. The precise population, product, vulnerability and responsible actor remain unconfirmed.
The leadership decision
Security leaders should find unencrypted personnel exports and file shares outside approved systems of record. Assign the data-protection owner to produce a repository-level view of workforce information, including exports, file shares, analytics staging areas and legacy collaboration stores. Require evidence of encryption, access approval, monitoring and retention for each location.
SalesBleed reframes agent permissions as privileged access
What happened
Zenity demonstrated that Salesforce Agentforce could be influenced by malicious CRM content and use a Slack write action without confirmation or clear invoker attribution. Salesforce remediated the reported paths before disclosure. On June 1, 2026, Zenity Labs reported the Agentforce findings to Salesforce.
The leadership decision
Security leaders should inventory agents that process externally supplied records. Treat enterprise agents as privileged identities with delegated tools, not as user-interface features. Assign the AI platform owner to document the agent’s input sources, run-as identity, accessible objects, subagents, actions, approval controls and communication destinations.
WSO2 KEV listing forces an API control-plane review
What happened
CISA added CVE-2026-5430 to KEV on Friday after the WSO2 JWT authentication-bypass advisory had been public since May. Affected API-control components require precise update-level verification and a separate review for unauthorised administrative access. The flaw can bypass JWT authentication and expose administrative control.
The leadership decision
Security leaders should inventory every affected WSO2 component and owner. Require application and platform owners to reconcile WSO2 deployments against network, cloud and software inventories, including dormant nodes and disaster-recovery instances. The update decision must use the product-specific levels in the advisory, not a generic assertion that the environment is current.
That’s Security.io Daily Headlines for Monday, September 28, 2026. Full reporting, sources, executive actions and today’s comic are available in the complete edition at Security.io. I’m Max Vogal. Thanks for listening.