top of page

THE CYBER BRIEF - ISSUE 49

Ralph Labarta
7 hours ago
3 min read

T H I S I S S U E - S P O T L I G H T


Vendors Release Record Number of Patches


  •  CVE disclosures in 2026 are running roughly 50% above 2025's record pace.

  • 48,185 CVEs were published in 2025, up 20.6% after a record 38% jump in 2024 (40,009 CVEs). For comparison, all of 2023 finished at 28,817.

  • Disclosures doubled during 2026, from 5,045 in January to 10,740 in August. September saw 10,889 CVEs, up 152.1% on the same month last year.

  • Microsoft September 2026 Patch Tuesday fixed a record 974 CVEs, versus 570 in July, 400 in August, 200 in June, 120 in May and 164 in April. Microsoft has patched 2,760 CVEs year to date, versus 1,139 in all of 2025 and 492 in 2016. The jump followed Microsoft's July warning that its use of agentic AI tools to find zero-days would drive a surge in updates.

  • Vendor CVE volume leaderboard: Linux, Google, Microsoft, Oracle, Redhat, IBM, Apache, Adobe, Apple, Openclaw, Mozilla, Siemens, Dell, Code Projects, Nvidia.

https://socradar.io/free-tools/cve-radar/how-it-works

Treasury's Scott Bessent says No Liability Exemptions for AI Labs


  • Treasury Secretary Scott Bessent told the House Financial Services Committee that Congress should not grant frontier AI labs the liability exemptions they are seeking, arguing that holding creators liable is the best safety guarantee.

  • His remarks followed Anthropic CEO Dario Amodei's essay calling for a slowdown in model development, a plan backed by OpenAI's Sam Altman and xAI's Elon Musk and rejected by President Trump; Amodei's plan sought a narrow federal waiver for certain safety conversations.

  • Treasury and CISA jointly oversee Gold Eagle, a clearinghouse that coordinates vulnerability scanning, validation and patch distribution, and Treasury has met with AI labs and banks on safety since the July Hugging Face cyberattack.

https://fedscoop.com/treasury-scott-bessent-ai-labs-liability-exemptions/

US almost Boarded Chinese Ship over Hallucinated AI Arms Report


  • CNN’s report said the analyst in question used a chatbot to analyze intelligence reports regarding the Chinese ship’s manifest, leading to the near-disastrous result.

  • The Department of Defense in January rolled out an “AI acceleration strategy” that sought to “make all appropriate data available across federated IT systems for AI exploitation, including mission systems across every service and component.”

  • The reported near miss comes as extinction-level warnings from AI researchers have led to a newly prominent national conversation on AI safety, including calls for regulation and coordinated research “pacing” from leading frontier AI labs

https://arstechnica.com/ai/2026/09/report-us-almost-boarded-chinese-ship-over-hallucinated-ai-arms-report/

Cisco Alerts Customers to Second Actively Exploited Zero-day in as Many Days


  • CVE-2026-76460 is a maximum-severity (10.0) authentication bypass in a Cisco Identity Services Engine (ISE) API that lets a remote attacker take full control of the device. It was exploited before Cisco patched it.

  • CISA added the flaw to its Known Exploited Vulnerabilities catalog. Cisco found it during a technical support case, published indicators of compromise, and said no workarounds exist.

  • The disclosure came two days after CVE-2026-76461, an exploited zero-day in Cisco Secure Email Gateway. VulnCheck and Cisco both say the two flaws are unrelated despite their consecutive CVE numbers.


https://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/

This newsletter is intended for informational purposes only. The content reflects publicly available information and general industry trends as of the date of publication and may not reflect the most current regulatory developments. Newsletter may contain links to vendor supported content which does not represent endorsement or promotion of products or services. Nothing herein constitutes legal, compliance, or professional advice, and should not be relied upon as such.


 
 
 

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.

© 2026 Techmar, LLC

bottom of page