Category: News

Current, event-driven reporting, announcements and industry developments.

  • Critical Red Hat Flaw Let Low-Privileged Tenants Seize Control of Managed Kubernetes Clusters

    Critical Red Hat Flaw Let Low-Privileged Tenants Seize Control of Managed Kubernetes Clusters

    A critical vulnerability in Red Hat Advanced Cluster Management for Kubernetes (RHACM) could let a low-privileged tenant on a central hub cluster seize administrative control of any Kubernetes cluster it manages, according to Red Hat’s own advisory on the flaw.

    An Unvalidated Annotation Opens the Door

    Tracked as CVE-2026-72526 and carrying a CVSS score of 9.9, the flaw sits in the multicloud-integrations component that RHACM uses to propagate applications from a central hub cluster to the individual managed, or “spoke,” clusters it oversees. The Application propagation controller processes an ocm-managed-cluster annotation on an Application custom resource without properly validating it, which means a tenant who only has permission to create Applications on the hub can direct that annotation at any managed cluster of their choosing, not just their own. Doing so forces ArgoCD on the targeted spoke cluster to synchronize manifests the attacker controls, resulting in arbitrary code execution or privilege escalation on a cluster the tenant was never authorized to touch.

    A Direct Route From Low Privilege to Cluster-Admin

    Because the underlying authorization check is missing entirely rather than merely weak, the flaw gives a low-privileged hub tenant a direct path to cluster-admin rights on infrastructure well outside their own environment, a significant multi-tenant isolation failure for organizations running shared RHACM hubs across business units or customers. Red Hat has published fixed component versions in its advisory and accompanying Bugzilla report; organizations running RHACM are advised to apply the update and confirm that the propagation controller correctly enforces tenant-scoped cluster authorization after upgrading, alongside reviewing who currently holds Application-creation permissions on their hub clusters.

  • Fileless Rootkit ‘PoisonedRefresh’ Found Hiding Web Shells in F5 BIG-IP Memory

    Fileless Rootkit ‘PoisonedRefresh’ Found Hiding Web Shells in F5 BIG-IP Memory

    Researchers at Sophos and ESET detailed a stealthy Linux rootkit, dubbed PoisonedRefresh, discovered on compromised F5 BIG-IP Access Policy Manager (APM) appliances, Help Net Security reported. The implant hooks Apache’s PHP module loader to inject a web shell directly into memory, never writing to disk, making it difficult to detect with conventional file-based scanning.

    The activity is tied to exploitation of CVE-2025-53521, a critical unauthenticated remote-code-execution flaw that F5 originally classified as a denial-of-service issue before reclassifying it. F5 has confirmed exploitation, and Shadowserver was tracking 795 internet-exposed vulnerable BIG-IP APM endpoints as of September 7, 2026. The findings were independently corroborated by BleepingComputer, SecurityAffairs and CybelAngel.

    Why it matters: F5 BIG-IP APM is widely deployed by government, financial and critical-infrastructure organizations to manage secure remote access. A memory-resident rootkit that survives file-based detection on this class of device represents a significant, hard-to-spot foothold inside networks that are supposed to be tightly controlled.

    Source: Help Net Security, September 9, 2026.

  • ShieldCrash PoC Bypasses Recent Microsoft Defender Patch, Grants SYSTEM Access

    ShieldCrash PoC Bypasses Recent Microsoft Defender Patch, Grants SYSTEM Access

    A security researcher known as Nightmare Eclipse released a proof-of-concept exploit dubbed ShieldCrash that bypasses Microsoft’s patch for an earlier Windows Defender privilege-escalation flaw, CVE-2026-69414 (nicknamed ShieldBreak), which had been patched only days earlier on Microsoft’s September 2026 Patch Tuesday, BleepingComputer reported. The bypass was independently corroborated by The Register and SecurityAffairs.

    According to the report, the ShieldCrash proof-of-concept allows arbitrary file reads with SYSTEM-level privileges on fully patched Windows 10, 11 and Server installations.

    Why it matters: Defender is the default endpoint-security product on most Windows deployments, including systems inside OT and critical-infrastructure environments. A public proof-of-concept that defeats a just-shipped patch for a SYSTEM-level flaw creates pressure for organizations to apply Microsoft’s next round of fixes quickly and to monitor for exploitation in the interim.

    Source: BleepingComputer, September 9, 2026.

  • CISA Warns of Actively Exploited Citrix NetScaler Authentication-Bypass Flaw

    CISA Warns of Actively Exploited Citrix NetScaler Authentication-Bypass Flaw

    CISA has added CVE-2026-19490, a CVSS 9.3 authentication-bypass vulnerability in Citrix NetScaler ADC and Gateway appliances configured as a gateway or AAA virtual server, to its Known Exploited Vulnerabilities (KEV) catalog, SecurityWeek reported. Exploitation in the wild has been confirmed since at least September 3, 2026.

    Citrix patched the flaw on August 19, 2026. Under Binding Operational Directive 26-04, federal civilian agencies have a three-day remediation window once a KEV entry is added. The exploitation has been independently corroborated by Rapid7, Belgium’s CCB, and security firm RedLegg.

    Why it matters: NetScaler ADC and Gateway appliances sit at the network perimeter of a huge number of enterprises and government agencies, frequently providing VPN and remote-access functionality. An authentication-bypass flaw at this layer is a direct path into internal networks — including those of critical-infrastructure operators — for any attacker who has not yet patched.

    Source: SecurityWeek, September 2026; CISA KEV catalog.

  • Convergint Enters Regulated Gaming Security Market With SSI Acquisition

    Convergint Enters Regulated Gaming Security Market With SSI Acquisition

    Global security integrator Convergint, which employs more than 11,000 people across 200-plus locations, has acquired Las Vegas-based Surveillance Systems Incorporated (SSI), a specialist surveillance integrator with more than two decades of experience serving the regulated gaming industry, SecurityInfoWatch reported. Financial terms were not disclosed.

    The acquisition gives Convergint an established foothold in casino and gaming security, a market with distinct regulatory and surveillance-compliance requirements that differ significantly from standard commercial video deployments.

    Why it matters: Gaming security has traditionally been served by specialist integrators due to state gaming-commission licensing and compliance requirements. A large national integrator entering the space directly — rather than partnering with a specialist — suggests larger players see enough scale in the sector to justify building in-house gaming expertise.

    Source: SecurityInfoWatch.com, September 9, 2026.

  • Security Industry Association Calls for Tighter Oversight of License Plate Readers

    Security Industry Association Calls for Tighter Oversight of License Plate Readers

    The Security Industry Association (SIA) issued a set of policy recommendations calling for stronger privacy safeguards, defined data-retention limits, and clearer misuse-accountability rules for automated license plate reader (ALPR) systems, SecurityInfoWatch reported.

    The recommendations arrive amid reporting, cited by SIW via Ars Technica and Secure Justice data, that 214 cities and counties have dropped Flock Safety contracts since 2021, including 93 in August 2026 alone. Flock has separately cut its default data-retention period from 30 to 7 days and added mandatory multi-factor authentication and misuse-detection auditing.

    Why it matters: ALPR technology has become one of the most contested categories in physical security, sitting at the intersection of law-enforcement utility and civil-liberties concern. SIA’s intervention signals that the industry’s own trade body sees a need for self-regulation ahead of likely state and municipal legislation.

    Source: SecurityInfoWatch.com, September 9, 2026.

  • Investment Firm Knox Lane Acquires Majority Stake in SAGE Integration

    Investment Firm Knox Lane Acquires Majority Stake in SAGE Integration

    Investment firm Knox Lane has acquired a majority stake in SAGE Integration Holdings, a national enterprise security systems integrator founded in 1988, SecurityInfoWatch reported. Financial terms of the transaction were not disclosed.

    SAGE said it plans to use the new capital to expand its technical workforce, accelerate technology deployment for enterprise clients, and continue an acquisition strategy that already added Vital Installs and sudoVision Consulting to the group in August 2026.

    Why it matters: The deal is the latest in a wave of private-equity-backed consolidation among security systems integrators, following similar recent moves by Convergint and other national players — a trend that is reshaping who designs and maintains access control, video and fire systems for large enterprise and institutional clients.

    Source: SecurityInfoWatch.com, September 9, 2026.

  • Veradigm Discloses Healthcare Data Breach After ‘The Gentlemen’ Ransomware Gang Claims Attack

    Veradigm Discloses Healthcare Data Breach After ‘The Gentlemen’ Ransomware Gang Claims Attack

    Veradigm (formerly Allscripts) disclosed in an SEC filing that an attacker used stolen third-party vendor credentials to access a limited customer-service API and copy patient data, including names and Social Security numbers, BleepingComputer reported. The company said clinical records were not affected.

    The ransomware group calling itself “The Gentlemen” claimed to hold 3.5 million patient records from the breach and threatened to leak the data absent a ransom negotiation.

    Why it matters: The breach follows a familiar pattern for healthcare-sector incidents: the initial compromise came through third-party vendor credentials rather than a direct attack on Veradigm’s own systems, underscoring why vendor and supply-chain credential hygiene remains one of the hardest problems in healthcare data security even at companies with mature internal security programs.

    Source: BleepingComputer, September 9, 2026, citing Veradigm’s SEC filing.

  • Mistral AI Raises €3 Billion in Largest-Ever European Tech Funding Round

    Mistral AI Raises €3 Billion in Largest-Ever European Tech Funding Round

    Paris-based Mistral AI has raised €3 billion (about $3.5 billion) in a Series D funding round led by Samsung Electronics, pushing its post-money valuation above €21 billion in what the company describes as the largest equity fundraising round ever completed by a European technology company.

    Valuation Nearly Doubles in a Year

    Samsung led the round alongside co-leads Scaleup Europe Fund, managed by EQT, and existing investor PSG Equity. New investors including Advent, funds managed by BlackRock, and the Grand Duchy of Luxembourg joined the round, while existing backers a16z, ASML, General Catalyst, Lightspeed, Nvidia and Salesforce Ventures also participated. The step up is steep: Mistral was valued at roughly €11.7 billion in 2025 after a €1.7 billion Series C led by ASML, meaning its valuation has nearly doubled in about a year. Founded three years ago, Mistral says it now operates in twenty countries and counts more than 125 large enterprises among its customers, including Airbus and HSBC.

    Funding a European Compute Buildout

    Mistral said the capital will fund frontier AI research, continued international growth, and an expanding European compute footprint. The company is already spending roughly €4 billion on data centers across France and Europe, including a facility outside Paris built around 13,800 Nvidia GB300 GPUs and a second, €1.2 billion facility under construction in Sweden, with a target of roughly 200 megawatts of combined European capacity by the end of 2027. Both Microsoft and Nvidia, which are investors in Mistral, are also involved in supplying compute capacity to the buildout. The round positions Mistral as Europe’s best-funded answer to US-based AI labs including OpenAI and Anthropic, though its roughly $4 billion in total funding to date remains well behind either rival.

  • Palladyne AI and FANUC America Partner to Bring ‘Physical AI’ to Industrial Robots

    Palladyne AI and FANUC America Partner to Bring ‘Physical AI’ to Industrial Robots

    Palladyne AI and FANUC America have announced a strategic collaboration to combine FANUC’s industrial robot portfolio with Palladyne AI’s physical AI software platform, aiming to make robotic automation easier to deploy and more adaptable across manufacturing, warehousing and logistics operations.

    Pairing Industrial Hardware With Adaptive Software

    The companies plan to integrate Palladyne IQ, Palladyne AI’s software platform, with FANUC’s industrial robots to focus on AI-driven motion planning, adaptive behavior, teleoperation, human-assisted learning, simulation and model training. Palladyne IQ is designed to help industrial robots better perceive and adapt to changing conditions on the floor, moving deployments beyond rigid, single-purpose programming toward systems that can support a broader range of tasks without extensive reprogramming. The collaboration also includes joint customer validation and standardized deployment workflows intended to make it easier for manufacturers, warehouse operators, logistics providers and system integrators to bring robotic systems into production.

    Targeting Labor and Flexibility Pressures

    Both companies frame the effort as a response to persistent labor shortages and pressure for greater operational flexibility across manufacturing and logistics, where reprogramming robots for new tasks has traditionally been slow and costly. The collaboration, announced September 8, 2026, is still in a development phase; no customer deployment results, success rates or production benchmarks have yet been disclosed. The partnership adds to a broader wave of manufacturers pairing established industrial robot hardware with newer physical AI software layers as factories and warehouses expand automated operations.