Category: News

Current, event-driven reporting, announcements and industry developments.

  • Anthropic Says Accounts in Houthi-Held Yemen Used Claude to Pursue Weapons Programs

    Anthropic Says Accounts in Houthi-Held Yemen Used Claude to Pursue Weapons Programs

    Anthropic’s newest threat-intelligence report, covered by the Associated Press and SecurityWeek, says accounts operating from Houthi-controlled northern Yemen used its Claude Code tool to pursue three separate weapons-development programs, including work toward a hypersonic-glide multi-variant missile design. A field test of a guided rocket associated with the effort reportedly failed.

    Anthropic said the accounts involved have been banned and that, per its assessment, no operational weapon was fielded as a result of this activity.

    Why it matters: The disclosure is one of the more concrete public examples yet of state or non-state actors attempting to use general-purpose AI coding tools to accelerate weapons development, and underscores why AI providers’ own threat-intelligence and account-enforcement programs are increasingly functioning as a frontline layer of defense-relevant security — alongside, not instead of, traditional export-control and nonproliferation controls.

    Source: Associated Press via SecurityWeek, September 11, 2026.

  • AI Agents and Machine Identities Are Now a Leading Initial-Access Vector, Report Finds

    AI Agents and Machine Identities Are Now a Leading Initial-Access Vector, Report Finds

    SpyCloud’s 2026 Identity Threat Report, based on a survey of 750 organizations and covered by SecurityInfoWatch, found that non-human identities — AI agents, service accounts, and API keys — were the leading initial-access vector in 31% of identity-related security incidents.

    The report found a significant confidence gap: 95% of surveyed organizations believe they have adequate visibility into their AI agents and non-human identities, but only 36% actually monitor those identities in practice.

    Why it matters: As enterprises deploy AI agents with their own credentials and permissions across more systems, the attack surface represented by non-human identities is growing faster than most organizations’ identity-governance programs, creating a widening gap between perceived and actual security posture — a pattern directly relevant to any critical-infrastructure operator now integrating AI agents into operational workflows.

    Source: SecurityInfoWatch.com, September 11, 2026, citing SpyCloud’s 2026 Identity Threat Report.

  • Defense Manufacturer Mach Industries Raises $600 Million Series C

    Defense Manufacturer Mach Industries Raises $600 Million Series C

    Huntington Beach, California-based defense manufacturer Mach Industries raised a $600 million Series C funding round led by Ribbit Capital and Sequoia, valuing the company at $3.7 billion, Crunchbase News reported. Mach develops unmanned aircraft, long-range weapons systems and propulsion technology.

    The company said the funding will go toward building infrastructure to produce defense systems at scale, part of a broader wave of venture capital flowing into defense-technology manufacturing in 2026.

    Why it matters: The scale of the round — among the largest for a pure defense-hardware manufacturer this year — reflects a broader shift in venture investment toward physical defense manufacturing capacity rather than purely software-based defense-tech, a trend with downstream implications for the unmanned-systems and counter-UAS markets this publication tracks closely.

    Source: Crunchbase News, September 11, 2026.

  • GitLab Critical Path-Traversal Flaw Exploited One Day After Disclosure

    GitLab Critical Path-Traversal Flaw Exploited One Day After Disclosure

    Security firm WatchTowr observed in-the-wild exploitation of CVE-2026-85706, a maximum-severity (CVSS 10) path-traversal vulnerability in GitLab Community and Enterprise Edition, just one day after GitLab released a patch, SecurityWeek reported. The flaw allows unauthenticated attackers to read arbitrary files from an affected server.

    The same GitLab release also patched a second critical vulnerability, CVE-2026-87719, an insecure-deserialization flaw in GitLab’s GraphQL implementation.

    Why it matters: A one-day gap between patch release and confirmed exploitation leaves almost no window for organizations to apply updates before attackers act, underscoring why source-code and DevOps infrastructure — not just perimeter network gear — needs to be included in any organization’s emergency-patching runbook.

    Source: SecurityWeek, September 11, 2026.

  • DHS Opens $440.7 Million Governmentwide Competition for Biometric Capture Devices

    DHS Opens $440.7 Million Governmentwide Competition for Biometric Capture Devices

    The Department of Homeland Security has opened bidding on a five-year, $440.7 million multiple-award IDIQ contract (solicitation 70RDA126R00000001) to standardize procurement of biometric capture devices — fingerprint, facial, iris, palmprint and multimodal systems — across DHS components and other federal agencies including the Departments of State and Justice, Washington Technology reported.

    The contract vehicle is intended to replace fragmented, one-off purchasing historically used by DHS’s Office of Biometric Identity Management. Proposals are due September 18, 2026.

    Why it matters: A single large, standardized federal contract vehicle for biometric hardware procurement gives vendors a much larger and more predictable addressable market than the agency-by-agency purchasing it replaces, and is likely to influence which biometric hardware standards and interoperability requirements become de facto norms across other government biometric deployments.

    Source: Washington Technology, September 11, 2026, corroborated by FedScoop and ID Tech Wire.

  • Check Point Patches Critical VPN Vulnerabilities in Security Gateway and Spark Firewall

    Check Point Patches Critical VPN Vulnerabilities in Security Gateway and Spark Firewall

    Check Point has patched two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a CVSS score of 9.8, in the VPN functionality of its Security Gateway and Spark Firewall products, SecurityWeek reported. The flaws stem from a certificate-validation issue and an ASN.1 heap overflow bug that together could allow unauthenticated remote code execution.

    Check Point said its own researchers discovered both vulnerabilities internally, and the company has not confirmed any in-the-wild exploitation to date. Fixes are available in versions R82.10, R82, and R81.20.

    Why it matters: VPN gateways sit at the network perimeter for a large share of enterprise and critical-infrastructure networks, making unauthenticated RCE flaws in this class of product a high-priority patch item regardless of whether active exploitation has been observed yet — the same category of flaw was exploited in the wild within days at other vendors this quarter.

    Source: SecurityWeek, September 11, 2026.

  • Microsoft Plans to More Than Triple Data Center Capacity to 38GW by 2032

    Microsoft Plans to More Than Triple Data Center Capacity to 38GW by 2032

    Microsoft plans to grow its global data center capacity from roughly 12GW today to more than 38GW by 2032, Bloomberg reported, a figure that would exceed peak electricity demand in New York state. The company said compute shortages had forced it to turn away AI and cloud business in recent months.

    Why it matters: The planned expansion underscores how AI compute demand is now a first-order driver of data center and power-grid planning among hyperscalers. Editorial note: the source article is behind Bloomberg’s paywall; this summary reflects only the publicly accessible headline and lede, and should be treated as preliminary pending fuller reporting.

    Source: Bloomberg, September 10, 2026.

  • Lawsuit Tests Whether AI Gun-Detection Vendors Can Be Held Liable When Systems Miss a Threat

    Lawsuit Tests Whether AI Gun-Detection Vendors Can Be Held Liable When Systems Miss a Threat

    A legal analysis published by SecurityInfoWatch examines a lawsuit, filed May 1, 2026, by a survivor of the January 2025 shooting at Antioch High School in Nashville against AI weapons-detection vendor Omnilert and installer System Integrations. The suit alleges the AI gun-detection system deployed at the school failed to flag the shooter’s weapon.

    The SIW analysis frames the case as an early test of whether weapons-detection vendors can be held legally liable when a system’s marketed detection capabilities do not perform as claimed in a real-world incident — a question the physical security industry has largely not had to confront in court until now.

    Why it matters: As AI-based weapons detection is adopted more widely in schools and other public facilities, this case and others like it will likely shape how vendors market detection-accuracy claims, how procurement contracts allocate liability, and how buyers evaluate performance guarantees — regardless of the case’s eventual outcome.

    Source: SecurityInfoWatch.com, September 10, 2026.

  • CISA Updates Advisory on Critical Flaws in ST Engineering iDirect Satellite Terminals

    CISA Updates Advisory on Critical Flaws in ST Engineering iDirect Satellite Terminals

    CISA issued Update A to advisory ICSA-26-183-01, covering four vulnerabilities in ST Engineering iDirect iQ-series satellite (VSAT) terminals, with CVSS scores up to 8.8 and one flaw rated 9.4 on the CVSS 4.0 scale. The advisory was originally released July 2, 2026.

    The flaws include missing authentication on REST API endpoints that expose device identity and cryptographic material, a cross-site request forgery vulnerability that can trigger a remote reboot or denial of service, a local privilege-escalation path via a factory-default low-privilege account, and exposure of password hashes. CISA lists Communications, Defense Industrial Base, Energy, Government and Transportation as affected sectors.

    Why it matters: VSAT terminals from vendors like ST Engineering iDirect provide connectivity for maritime vessels, remote energy sites, and defense operations where terrestrial networks are unavailable. Authentication bypasses on internet-facing satellite terminal management interfaces are a persistent, underappreciated risk category for organizations with remote or offshore infrastructure.

    Source: CISA ICS Advisory ICSA-26-183-01 (Update A), September 10, 2026.

  • CISA Advisory: Hard-Coded Cryptographic Key Found in AVEVA Pipeline Integrity Monitor

    CISA Advisory: Hard-Coded Cryptographic Key Found in AVEVA Pipeline Integrity Monitor

    CISA published advisory ICSA-26-253-01 describing four vulnerabilities in AVEVA Pipeline Integrity Monitor, with CVSS scores up to 8.4 (CVE-2026-81821 through CVE-2026-81824). The flaws include a hard-coded cryptographic key, use of a broken or risky cryptographic algorithm, missing authorization checks, and a stored cross-site scripting vulnerability.

    According to CISA, successful exploitation could allow an attacker to disclose sensitive project data, brute-force password hashes, or execute arbitrary code in a victim’s browser session. The advisory identifies the Critical Manufacturing sector as affected. AVEVA has released a fix in the 2025 SP1 P2 release.

    Why it matters: Pipeline integrity monitoring software is used to track the structural and operational health of oil, gas and other pipeline infrastructure. Vulnerabilities that expose project data or credential material in this class of software are a direct concern for critical-infrastructure operators, even where exploitation requires network access rather than being remotely trivial.

    Source: CISA ICS Advisory ICSA-26-253-01, September 10, 2026.