LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
patch

New infosec products of the week: September 11, 2026

Here’s a look at the most interesting products from the past week, featuring releases from Akeyless, Orchid Security, Scytale, and Securin. Securin Platform helps security teams prove when attack paths are closed Securin has announced the general availability of the Securin Platform, an AI-native Preemptive Exposure Management platform designed to answer three questions security teams struggle wit

zeroday.news ·

Several cybersecurity vendors have announced new product releases this week, focusing on areas such as AI agent security, exposure management, and third-party risk. These new offerings aim to address evolving threats and operational challenges faced by security teams.

Akeyless has introduced Akeyless Agentic Runtime Authority, a real-time identity control layer specifically designed for AI agent actions. This new capability builds upon Akeyless SecretlessAI, which functions as a credential protection layer by preventing credentials from being directly embedded within AI agents and instead brokers their access to enterprise systems. The Runtime Authority adds an additional layer of control by enforcing intent-based access control, thereby restricting the specific actions AI agents can perform even after gaining access.

Orchid Security has also launched new features targeting AI agent risk, including identity drift detection and application-level kill switches. The company highlights that AI agents can quickly exceed their initial privilege levels by exploiting existing identity debt within an enterprise, such as hard-coded credentials, orphaned accounts, unmanaged authentication paths, and excessive permissions, without necessarily "breaking" security controls. These new AI readiness controls are intended to facilitate AI adoption while maintaining governance.

In the realm of exposure management, Securin announced the general availability of its AI-native Preemptive Exposure Management platform. This platform is designed to help security teams answer critical questions regarding exploitable attack paths, prioritization of fixes, and the effectiveness of implemented remediations. It integrates attack surface discovery, vulnerability and threat intelligence, vulnerability management, offensive validation, and remediation into a unified, continuous workflow.

Scytale has expanded its vendor risk management offerings with new AI-powered third-party risk management (TPRM) capabilities within its Vendors module. This enhancement aims to transform vendor risk management from periodic reviews into a continuously updated risk intelligence engine, providing security and GRC teams with a current view of their entire vendor ecosystem. Scytale's AI GRC platform automates vendor discovery, risk scoring, and evidence collection across various compliance frameworks.

patchai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.