Threat and vulnerability round-up: week ending 30 September 2026
Citrix NetScaler and Check Point VPN flaws under active attack, a WordPress core fix, a SharePoint exploit, and an Apple zero-day.
Insights that apply internationally, including most vulnerabilities, threats, and international standards.
Citrix NetScaler and Check Point VPN flaws under active attack, a WordPress core fix, a SharePoint exploit, and an Apple zero-day.
The PCI Security Standards Council has published a new Key Management and Operations Standard, Secure Software Lifecycle Standard v2.0, and guidance on AI systems.
NIST has published the initial public draft of SP 800-82 Rev. 4, its guide to operational technology security, for comment until 30 November 2026.
Australian Federal Police arrest two men in Perth over the TeamPCP hacking spree that compromised open source tools to steal credentials from over 1,000 organisations.
ISO and IEC publish the second edition of ISO/IEC 27017, updating cloud security controls to align with ISO/IEC 27002:2022.
ShinyHunters claims a breach of Instructure’s Canvas platform, affecting nearly 9,000 schools and universities, then defaces login pages during exams.
Anthropic says its Claude Mythos Preview model can find serious software flaws at scale and gives access only to selected defenders through Project Glasswing.
A pro-Iran group claims a destructive attack on Stryker that wiped tens of thousands of company devices and disrupted operations worldwide.
Ofcom opens a formal Online Safety Act investigation into X after its Grok AI tool was used to create sexualised images of real people, including children.
The three-year transition to ISO/IEC 27001:2022 has ended; certificates against the 2013 edition are no longer valid.
The revised ISO/IEC 27701 can now be implemented and certified independently of ISO/IEC 27001.
ISO and IEC publish the third edition of ISO/IEC 27018, aligned to ISO/IEC 27002:2022, for protecting PII in public clouds.