2026-09-22
Review the tracked stories and available summary evidence for the archived period shown.
Population: stories the tracker first saw on this Coordinated Universal Time (UTC) calendar day; publisher date is used only if first-tracked time is unavailable and remains on each item.
- ai security
US Proposes AI Incident Alert System in Talks With China, Bessent Says
The US is proposing an artificial intelligence (AI) incident alert system as part of discussions with China, according to Treasury Secretary Bessent. The proposal reflects ongoing diplomatic efforts to establish coordination mechanisms around AI safety and security between the two nations.
Why it matters: Security practitioners need to monitor emerging US-China agreements on AI incident reporting, as new international protocols could affect incident disclosure requirements, response timelines, and compliance obligations for organizations operating across both jurisdictions.
- vulnerabilitiesCVE-2026-93712
CVE-2026-93712: Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler
Dancer2 versions 2.1.0 through 2.1.x contain a path traversal vulnerability that allows serving files outside the designated public directory via relative path segments in the File route handler. The vulnerability is resolved in version 2.2.0.
Why it matters: Developers and operators running Dancer2 2.1.x on publicly accessible systems risk unauthorized file disclosure, including sensitive application and system files, and should upgrade immediately to version 2.2.0 or later.
- vulnerabilitiesCVE-2026-93711
CVE-2026-93711: Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array
Dancer2 versions prior to 2.2.0 for Perl fail to strip carriage return (CR) and line feed (LF) characters from response header names in the headers_to_array function. This allows attackers to inject arbitrary headers into HTTP responses, potentially leading to cache poisoning, cross-site scripting (XSS), or other header manipulation attacks. The CPAN Security Group disclosed the vulnerability as CVE-2026-93711.
Why it matters: Perl developers using Dancer2 web framework versions before 2.2.0 are exposed to header injection attacks that could compromise application behavior and user security; immediate upgrade to 2.2.0 or later is required.
- vulnerabilitiesCVE-2026-93710
CVE-2026-93710: Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler halts the response in compile_hooks
A vulnerability in Dancer2 versions 2.0.0 through 2.1.x allows route dispatch to continue after a dying hook is refused when the exception handler halts the response in compile_hooks. This logic error can cause unexpected behavior in request handling.
Why it matters: Developers using Dancer2 for Perl web applications should upgrade to version 2.2.0 or later to prevent potential logic bypass in route handling.
- vulnerabilitiesCVE-2026-93709
CVE-2026-93709: Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler
Dancer2, a Perl web framework, contains a vulnerability in its AutoPage handler that allows serving layout files as pages when path variants bypass the guard mechanism. Affected versions are before 2.2.0. The issue enables unintended access to protected template content through alternate path spellings.
Why it matters: Developers using Dancer2 before version 2.2.0 should upgrade immediately to prevent attackers from accessing layout files and potentially sensitive templating logic through path manipulation.
- threat intelCVE-2026-76460CVE-2026-76461
21st September – Threat Intelligence Report
A weekly threat intelligence roundup covering government and supply chain breaches, active exploitation of critical vulnerabilities in Cisco and Check Point products, and multiple campaigns from state-aligned and cybercriminal groups targeting government, technology, and financial sectors. Artificial intelligence (AI) threats include new attack techniques like BragJack against AI-enabled browsers and the discovery of Luciferus, an uncensored AI service for malware creation. Major patch releases from Oracle, Cisco, ISC, and Check Point address hundreds of flaws, including actively exploited remote code execution vulnerabilities.
Why it matters: Government and critical infrastructure operators must assess exposure from the Japan breach and oil tanker attacks, which demonstrate virtual private network (VPN) and onboard system targeting; Brevo and Gyazo customers should evaluate risk from compromised credentials and session tokens; organizations running Cisco ISE, Check Point Management Servers, Oracle products, or BIND 9 DNS services require immediate patching for actively exploited critical flaws; teams managing AI-enabled systems face new hijacking and jailbreak risks; enterprises with Microsoft 365 deployments need detection for GhostCode device-code phishing; security teams should brief executives on WaterPlum's $15 million cryptocurrency theft from 7,000 wallets targeting IT professionals.