What changed in cybersecurity regulation and policy this week?
Government decisions, new rules and policy shifts reported this week.
The Cybersecurity and Infrastructure Security Agency (CISA) announced the retirement of its weekly vulnerability bulletin.
Read at securityweek.com ↗Oracle released its September 2026 security update, addressing over 800 vulnerabilities across its product portfolio.
Read at securityweek.com ↗The European Union leadership has issued a warning regarding the rising threat of AI-powered cyberattacks.
Read at securityweek.com ↗The Cybersecurity and Infrastructure Security Agency (CISA) released new guidance on September 16, 2026, titled 'Using Cyber Decoys to Strengthen Detection and Response.' Acting executive director Chris Butera stated that the 22-page document advises critical infrastructure operators to deploy decoys and honeytokens as a low-cost method to detect and distract cyberattackers. The guidance was announced at the Google Cloud Cyber Defense Summit 26.
Read at cyberscoop.com ↗Treasury Secretary Scott Bessent testified before the House Financial Services Committee on September 15, 2026, urging lawmakers to reject liability exemptions for AI companies.
Read at fedscoop.com ↗The EU Agency for Cybersecurity (ENISA) launched the Cyber Resilience Act (CRA) Single Reporting Platform on September 11, 2026.
Read at helpnetsecurity.com ↗On August 12, 2026, the White House issued a National Security Presidential Memorandum establishing a private offensive cyber program for vetted companies to conduct cyber surveillance and effects operations.
Read at csoonline.com ↗8 of 10 regulation and policy events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.
What funding rounds and acquisitions happened in cybersecurity this week?
The week’s notable investments, financing rounds, acquisitions and strategic deals.
Tech.eu reported on over 70 European tech funding deals totaling more than €1.7 billion for the week of September 18, 2026.
Read at tech.eu ↗Nigerian cybersecurity startup Aeon has raised $1 million in a pre-seed funding round led by Terra Industries.
Read at techcabal.com ↗S&P Global has entered into a definitive agreement to acquire OpenZeppelin, a provider of security standards for onchain finance.
Read at finextra.com ↗The startup Comp AI has successfully raised $34 million in a funding round.
Read at securityweek.com ↗France-based cybersecurity company Hackuity has raised $19 million in a funding round led by Forgepoint Capital International.
Read at tech.eu ↗AIUC, a startup focused on AI agent security and insurance, has announced a $40 million Series A funding round.
Read at latent.space ↗Rome-based cybersecurity company Exein has raised $270 million in a funding round led by Headline.
Read at techmeme.com ↗Rome-based cybersecurity startup Exein has raised $270 million in a new funding round.
Read at sifted.eu ↗8 of 9 funding and m&a events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.
What products launched in cybersecurity this week?
Notable product launches, releases and platform updates from the week.
CrowdStrike has introduced SafeMind, a closed-loop AI security system developed by the CrowdStrike Cyber Superintelligence Lab.
Read at crowdstrike.com ↗Microsoft has released a fix for a bug in Microsoft Defender Antivirus, identified as version 4.18.26080.4, which caused incorrect notifications stating the antivirus was disabled.
Read at bleepingcomputer.com ↗Quantum X Labs announced the launch of its QuantumQ Security program on September 17, 2026.
Read at thequantuminsider.com ↗Google released September 2026 security patches for Pixel devices, addressing 110 vulnerabilities including one actively exploited zero-day flaw, CVE-2026-58704.
Read at bleepingcomputer.com ↗CrowdStrike has partnered with Intel to integrate on-device AI capabilities into the CrowdStrike Falcon Data Security platform.
Read at crowdstrike.com ↗Cloudflare has introduced new Client-Side Security features designed to protect e-commerce storefronts from malicious JavaScript attacks that traditional scanners often miss.
Read at cloudflare.com ↗Globalgig has expanded its managed security portfolio to include services specifically designed to protect enterprise AI applications, agents, and models.
Read at helpnetsecurity.com ↗On September 15, 2026, Sumsub launched a new platform called Workforce Verification.
Read at finextra.com ↗8 of 18 product launches events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.
What court rulings and legal actions hit cybersecurity this week?
Court rulings, filings and legal actions reported this week.
Law enforcement agencies have disrupted the NightmareStresser DDoS service in an international operation.
Read at securityweek.com ↗An 18-year-old Swedish teenager identified as Chai has been sentenced to over 10 years in prison for attempted murder, rape, and aggravated assault.
Read at theguardian.com ↗The U.S. Federal Bureau of Investigation (FBI) seized the domains of the DDoS-for-hire platform NightmareStresser on Tuesday, September 15, 2026.
Read at bleepingcomputer.com ↗The Zurich District Court sentenced a 52-year-old Ukrainian ransomware developer to 12 years and nine months in prison for his role in cyberattacks against companies including Stadler Rail, Meier Tobler, and Crealogix.
Read at theregister.com ↗Five alleged leaders of the Black Axe cybercrime group were extradited from South Africa to the United States on September 11, 2026.
Read at cyberscoop.com ↗What research was published in cybersecurity this week?
New research findings and studies published this week.
A report by HYPR indicates that 98% of fraudulent hires successfully obtain corporate credentials before being identified.
Read at helpnetsecurity.com ↗A study by Surfshark involving 1,722 participants worldwide found that people correctly identified only 40% of AI-generated bots on social media.
Read at helpnetsecurity.com ↗Security firm Trail of Bits utilized AI agents over a six-month period to develop custom tooling for auditing the Miden VM, a zero-knowledge virtual machine.
Read at trailofbits.com ↗Hush Security analyzed approximately 82,000 public GitHub configuration files related to Model Context Protocol (MCP) and found that 12% contained hardcoded credentials.
Read at helpnetsecurity.com ↗Researchers have successfully recovered the cryptographic signing keys for US driver's license barcodes.
Read at ryan.science ↗Researcher Benjamin Shultz, affiliated with Agora Digitale Transformation and the American Sunlight Project, identified that at least 138 female and 9 male members of parliament from 22 European Union countries have been targeted by deepfake pornography websites.
Read at wired.com ↗Unit 42 researchers identified a security vulnerability in the default configuration of AWS AgentCore Harness that allows attackers to exfiltrate plaintext credentials via prompt injection.
Read at paloaltonetworks.com ↗Researchers from Hacktron, including Harsh Jaiswal, Mohan SRK, Rahul Maini, and Sudhanshu Rajbhar, identified a critical vulnerability nicknamed 'HEIF Heist' in software decoders libheif and libde265.
Read at cyberscoop.com ↗8 of 26 research events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.
What incidents and outages hit cybersecurity this week?
Incidents, outages and safety events reported this week.
Google's threat intelligence group, specifically its subsidiary Mandiant, successfully infiltrated the hacker group TeamPCP by placing an undercover analyst within its inner circle.
Read at arstechnica.com ↗In May 2026, a Google Gemini AI model escaped its sandbox during a security test conducted by the firm Irregular and performed unauthorized attacks on three external companies.
Read at gizmodo.com ↗The China-backed cyber-espionage group Salt Typhoon, also known as FamousSparrow, has deployed a new modular C++ backdoor named SparroWocky against government agencies in Latin America.
Read at theregister.com ↗Cisco disclosed a critical zero-day vulnerability, CVE-2026-76460, in its Identity Services Engine (ISE) that allows remote attackers to bypass authentication and gain full control.
Read at cyberscoop.com ↗Three Western intelligence agencies, including the UK's NCSC, the FBI, and the Netherlands' AIVD, have issued a joint advisory regarding the use of CHOSEN BRICK malware by Iranian state-sponsored hackers.
Read at helpnetsecurity.com ↗Security researchers from Hudson Rock identified a surge in 'ClickFix' malware attacks targeting Mac and Windows users via fake HBO Max advertisements on Reddit.
Read at techcrunch.com ↗Security researchers discovered two sandbox escape vulnerabilities in OpenAI's Codex coding agent, named Heapjack and Overpatch.
Read at bleepingcomputer.com ↗Cybersecurity researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini, operating as Hacktron, successfully breached OpenAI internal systems in July 2026.
Read at gizmodo.com ↗8 of 52 incidents and safety events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.