September 2026 is not full CE compliance. It is the first continuous, enforceable duty to detect and report actively exploited vulnerabilities.
Latest news
Latest cybersecurity dispatches
Fresh reporting on active vulnerabilities, security patches, incident response, and threat research for defenders.
Accenture confirms an isolated Azure DevOps breach after 35GB of source code, PATs, keys and credentials were listed for sale—raising major supply-chain risk for clients.
Authorization gaps, hard-coded secrets and invented package names are reaching production repositories faster than human review can absorb them.
Service accounts, CI/CD runners, workload certificates and AI-agent principals form a sprawl traditional joiner-mover-leaver programs never governed.
*A conceptual view of Jenkins as the high-privilege control plane of the software factory—and of plugins as the supply-chain links that can break it.*
Microsoft and CISA confirmed exploitation on 14 July 2026 and shipped same-day patches. SharePoint Online is unaffected; self-hosted farms need action now.
Roughly triple June's previous record, the release is led by CVE-2026-50518, an unauthenticated Windows DHCP Server RCE rated Exploitation More Likely.
Patched in the record July 2026 Patch Tuesday, the flaw puts finance, supply-chain and operations systems at risk wherever ERP login endpoints remain reachable.