Weekly briefing · 7–14 Sept 2026

This week in cyber security

7 incidents were disclosed in the last seven days. The largest is McKesson, with 6,404,340 records affected. CISA added 5 flaws to its list of those used in attacks. On the compliance side, a Federal Communications Commission rule takes effect on 29 September 2026.

Top 5 incidents

  1. 1
  2. 2
  3. 3
  4. 4
    McKesson: a data breach

    6,404,340 recordsHave I Been Pwned · 10 Sept

  5. 5
    Chess.com (2026): a data breach

    4,653,212 recordsHave I Been Pwned · 13 Sept

Top 5 exploited vulnerabilities

  1. 1
    Cisco Asyncos

    CVE-2026-76461· added 14 Sept

    9.8Critical
  2. 2
    ConnectWise ScreenConnect

    CVE-2026-84869· added 11 Sept

    9.9Critical
  3. 3
    Gitlab

    CVE-2026-85706· added 11 Sept

    10.0Critical
  4. 4
    MikroTik RouterOS

    CVE-2026-86060· added 10 Sept

    9.8Critical
  5. 5
    Citrix NetScaler

    CVE-2026-19490· added 9 Sept

    9.8Critical

Compliance

Get this briefing every Monday

Free. Subscribers also get the technical details for their IT team: what happened, what CISA or the regulator says to do and by when, and the official records. Unsubscribe in one click.

We send the briefing and nothing else. Unsubscribe in one click.

Earlier weeks

About this briefing

7
Incidents disclosed this week
5
Flaws newly used in attacks
377
Stories reviewed
2
Weekly briefings published