 |
Weekly insights Week ending 27 September 2026 |
|
Hello there,
Here is our round-up of the past week in information security, privacy, and AI governance, grouped by region. |
This week at a glance
Attackers are exploiting flaws in Citrix NetScaler and Check Point VPNs, so patch now if you use either. PCI SSC has published new key management and secure software standards, and in the UK the ICO has become the Information Commission.
|
|
Top stories |
|
Asia-Pacific · Global
Australian Federal Police arrest two men in Perth over the TeamPCP hacking spree that compromised open source tools to steal credentials from over 1,000 organisations. Read more
|
Global |
|
Threat and vulnerability intelligence
Six actively exploited vulnerabilities this week, plus two campaigns to watch.
Actively exploited: patch now
| ● | Citrix NetScaler ADC and Gateway (CVE-2026-88771, CVE-2026-88772) Upgrade to 14.1-73.37 or 13.1-64.23, then check for signs of compromise. |
| ● | Check Point Security Gateway and Management (CVE-2026-85102, CVE-2026-93616) Apply the Jumbo Hotfix for your branch. |
| ● | WordPress core (CVE-2026-87902) Update to WordPress 7.1.2 or the patched release for your branch. |
| ● | Microsoft SharePoint Server (CVE-2026-65660) Install the August 2026 security updates. |
| ● | MikroTik RouterOS (CVE-2026-67279, CVE-2026-86060) Upgrade to the latest RouterOS 6.49 or 7.x build. |
| ● | Apple iOS, iPadOS, and macOS (CVE-2026-86950) Update to iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, or macOS Sequoia 15.8.1. |
Also watch: attacks on unpatched Oracle PeopleSoft, and ClickFix attacks delivered through malicious custom GPTs.
|
|
|
|
Standards updates
The PCI Security Standards Council has published a new Key Management and Operations Standard, Secure Software Lifecycle Standard v2.0, and guidance on AI systems. Read more
|
UK |
|
Legal and regulatory updates
The Information Commissioner’s Office is replaced by a board-led Information Commission under the Data (Use and Access) Act 2025. Read more
|
Europe |
|
Legal and regulatory updates
The EDPB has adopted Guidelines 04/2026 on administrative fines, replacing the 2017 guidelines, and finalised its DSA–GDPR guidelines. Read more
|
Need help acting on any of this?
We help organisations with information and cyber security, privacy, and AI governance, including ISO/IEC 27001, ISO/IEC 42001, and Cyber Essentials. Get in touch for a pragmatic, no-obligation conversation.
|
|
| See all our insights on our website |
| Want urgent alerts too? We can also email you straight away when a critical vulnerability is being actively exploited in a widely used product (usually no more than a few a month). Sign up again with the same email and tick “Also email me urgent alerts”. |
This email is for general information only. It is not legal advice or a monitored threat intelligence service.
This is a sample issue. Subscribers receive it every Monday, and every email includes links to change preferences or unsubscribe. Privacy notice
Taylor Baines Ltd, registered in England and Wales, company number 07272922. Registered office: 203 London Road, Hadleigh, Benfleet, Essex, SS7 2RD, UK.
|