Image: img.helpnetsecurity.com · rights & removal
Week in review: FortiBleed is still active, Patch Tuesday forecast
Reporting by Help Net SecurityRead the original at helpnetsecurity.com
Executive Summary
Facts Only
* Drew McCombs balances the roles of CTO and CISO by scheduling security work into every sprint.
* The MAKERphone 2.0 is a DIY 4G phone with plug-in hardware for MicroPython or Arduino C++ programming.
* RemoveMacAI is a command-line tool to turn off Apple Intelligence on macOS 27 and delete downloaded AI models.
* Ann Barron-DiCamillo, U.S. Bank CISO, notes the security role has grown to include fraud, resilience, third-party risk, and AI governance.
* Yusuf Fujii designed audits and penalties for AI analysis of street camera footage, adding independent record-keeping and spot checks.
* Ivan Milenkovic explains how security leaders can build an economic model for security decisions by starting with loss scenarios.
* ESET researchers traced changes to MATCHBOIL, a downloader used by UAC-0099 to plant spying tools on Windows machines in Ukraine.
* Modat and NCSC-NL found 8,547 internet-facing systems at wind/solar parks across 35 EU countries should not be public.
* Microsoft released an out-of-band update for Exchange Server fixing CVE-2026-96940.
* CISA added CVE-2026-88779 to the Known Exploited Vulnerabilities catalog due to a NetScaler flaw.
* SonicWall patched four vulnerabilities, including CVE-2026-102255 in SMA 1000 appliances.
* Attackers attempted to exploit Atlassian flaw CVE-2026-21589.
* Cybercriminals use fake discounts on social media for phishing and stealing payment details via kits like Milk Dragon.
* A data breach at Denmark’s CPR exposed personal information of 8.8 million people.
* Dell issued a patch for vulnerability CVE-2026-86360 in Dell System Update allowing root privileges.
* The FBI seized domains used by Flax Typhoon hacking tools, linked to Chinese state-sponsored hackers.
* NVIDIA's DCGM Exporter had a flaw (CVE-2026-47483) allowing unauthenticated attackers to crash GPU monitoring.
* IBM and Red Hat fixed over 400 vulnerabilities in Java libraries via Lightwell.
* GitHub announced an AI detector to prevent credential uploads.
* The OpenSSH team released version 10.6 with a post-quantum signature algorithm.
Full Take
The narrative suggests a systemic friction between accelerating technological advancement—particularly in the realm of generative AI and autonomous operations—and the slower, more structured requirements of security governance and risk management. The emphasis on economic modeling for security decisions points to a necessary shift from purely compliance-based mandates to demonstrable risk quantification, which requires new metrics that must be integrated into business strategy rather than treated as separate overhead. Furthermore, the proliferation of AI-generated content—from malicious payloads like MATCHBOIL to automated Wikipedia edits by rogue agents—demonstrates that the security landscape is being profoundly reshaped by adversarial systems operating at scale and speed. The tension between human oversight (as seen in the debates over autonomous IT operations) and machine capability is central; when complexity increases, the points of failure shift from technical vulnerabilities alone to the governance gaps surrounding AI deployment and operational boundaries. This implies that cognitive sovereignty depends not just on patching known flaws but on establishing new principles for human approval over automated decision-making and ensuring that risk assessment is equally weighted across legal, technological, and business domains.
BRIDGE QUESTIONS:
What mechanisms are necessary to ensure that economic models for security decisions translate directly into enforceable, standardized controls across diverse organizational structures?
How can the focus on AI agent capabilities be balanced with the imperative for human accountability in critical infrastructure and data handling environments?
If attackers are leveraging autonomous agents and AI tools for reconnaissance and exploitation, what new principles of defense must be prioritized beyond traditional perimeter and endpoint security measures?
From the original · Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Three questions a hospital CISO should ask a healthcare fintech vendor In this Help Net Security interview, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles. Security work is scheduled into every sprint, and issues touching patient data or funds disbursement come first.Read the full story at helpnetsecurity.com
Sentinel — Human
This text functions as a heavily curated news digest covering cybersecurity, AI ethics, and technology updates, exhibiting characteristics of human editorial selection rather than raw synthetic output.
