2026-09-30
Review the tracked stories and available summary evidence for the archived period shown.
Population: stories the tracker first saw on this Coordinated Universal Time (UTC) calendar day; publisher date is used only if first-tracked time is unavailable and remains on each item.
- cloud saas
Post-quantum website certificates from Cloudflare are scheduled for early 2027
Cloudflare plans to launch a public certificate authority (CA) that will issue both conventional and post-quantum digital certificates. The company will roll out production issuance of Merkle Tree Certificates (MTCs), a post-quantum certificate type, in the first quarter of 2027. Cloudflare cites concentration risk in the current CA ecosystem as motivation to diversify certificate issuers.
Why it matters: Website operators and security teams should monitor this development as an alternative CA option for post-quantum-ready transport layer security, with production availability expected in Q1 2027.
- ai security
Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development
Trump announced that major technology firms have signed an accord to self-regulate artificial intelligence (AI) development through four voluntary steps. The agreement leaves room for future government regulation while establishing baseline commitments for the signing companies.
Why it matters: Organizations developing or deploying AI systems should monitor the accord's voluntary commitments to understand industry baseline expectations and prepare for potential future regulatory requirements.
- breaches incidents
Data breach incident targets prisoner medical records at 2 Mass. jails
A cybersecurity incident at Computer Systems Integrated Inc. has compromised the electronic health record system serving Suffolk County's two Massachusetts jails, exposing prisoner medical records and health data. The system provider confirmed the breach on Thursday and stated it is investigating the incident.
Why it matters: Correctional facilities, healthcare providers using this EHR platform, and incarcerated individuals affected by the breach should determine what personal health information was accessed and whether notification and credit monitoring are warranted.
- cloud saas
Microsoft is rolling out Linux container support to WSL
Microsoft has made WSL Containers generally available, enabling Linux container support within Windows Subsystem for Linux. The feature extends WSL functionality beyond traditional Linux distribution execution to container workloads.
Why it matters: Development teams using Windows can now run containerized applications natively without separate container runtimes, simplifying local development workflows and reducing platform-specific setup overhead.
- threat intel
Phishing Abuses RMM Tools for Persistent Access
In July 2026, Microsoft Defender Experts discovered phishing campaigns distributing legitimate but masqueraded MSP360 Remote Monitoring and Management (RMM) software v2.5.0.67 through social engineering lures including meeting invitations, PDF themes, and software update prompts. After installation, threat actors used the RMM agent to deploy ConnectWise ScreenConnect as a secondary remote access channel, then staged additional utilities with credential-access and information-gathering capabilities. The attack chain demonstrates how legitimate administrative tools can be chained together to establish persistent access and execute post-compromise operations while evading detection.
Why it matters: Organizations across multiple industries face phishing campaigns distributing trojanized RMM installers; security teams must restrict unapproved remote management software, enforce multifactor authentication (MFA) on approved RMM platforms, and investigate unauthorized RMM installations to reset compromised credentials and prevent lateral movement.