What changed in cybersecurity regulation and policy this week?
Government decisions, new rules and policy shifts reported this week.
On September 25, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two vulnerabilities, CVE-2026-65660 and CVE-2026-67279, to its Known Exploited Vulnerabilities (KEV) Catalog.
Read at cisa.gov ↗The New Zealand National Cyber Security Centre (NCSC) identified China as the most persistent state-backed cyber threat to the country in its annual report released in September 2026.
Read at insurancejournal.com ↗Senate Intelligence Committee Chairman Mark Warner and Commerce Committee Chairman Ted Cruz introduced the Telecommunications Cybersecurity and Resilience Act in the United States on September 24, 2026.
Read at cyberscoop.com ↗The European Union's financial regulators, including the EBA, EIOPA, and ESMA, warned on September 23, 2026, that advanced quantum computers could threaten current cryptographic systems before becoming commercially viable.
Read at decrypt.co ↗UK Prime Minister Andy Burnham announced the creation of the National Centre for Information Defence to counter state-sponsored disinformation campaigns.
Read at helpnetsecurity.com ↗On September 15, 2026, U.S. Treasury Secretary Scott Bessent testified before the House Financial Services Committee, arguing that frontier AI labs should not receive liability exemptions for their models.
Read at lawfaremedia.org ↗On September 12, 2026, Anthropic CEO Dario Amodei warned about the risks of unchecked AI development.
Read at darkreading.com ↗8 of 15 regulation and policy events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.
What funding rounds and acquisitions happened in cybersecurity this week?
The week’s notable investments, financing rounds, acquisitions and strategic deals.
Kontext, an AI security company based in Germany, has raised $4 million in a funding round led by 42CAP, with participation from a16z CSX and HTGF.
Read at tech.eu ↗Palma.ai, an enterprise platform for governing AI agents, has raised $1.8 million in a pre-seed funding round.
Read at tech.eu ↗What products launched in cybersecurity this week?
Notable product launches, releases and platform updates from the week.
Cloudflare has introduced Turnstile Spin, a new feature allowing AI agents to configure website security settings.
Read at cloudflare.com ↗SolarWinds has released security patches to address critical remote code execution (RCE) vulnerabilities affecting its self-hosted Observability platform.
Read at securityweek.com ↗Azul Systems announced the Azul Intelligence Cloud AI Assistant on September 24, 2026.
Read at helpnetsecurity.com ↗Airties has launched new integrated cybersecurity capabilities for its Connectivity Experience Management Platform, allowing ISPs to provide router-level protection for homes and small businesses.
Read at helpnetsecurity.com ↗Cisco Talos released an open-source research toolkit called CAIRN on September 24, 2026, designed to detect and track AI-integrated malware.
Read at talosintelligence.com ↗CFC announced the launch of affirmative AI coverage within its intellectual property insurance policy to address legal ambiguities regarding AI-generated outputs and infringement.
Read at insurancejournal.com ↗On September 24, 2026, Gurucul announced the general availability of its new solution, Gurucul AI Risk and Response, designed to monitor behavioral AI activity and link it to identity and security telemetry.
Read at helpnetsecurity.com ↗Elliptic has launched Pulse, an AI-powered tool designed to provide frontline law enforcement officers with plain-language financial summaries of cryptocurrency wallet addresses and transaction hashes.
Read at decrypt.co ↗8 of 19 product launches events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.
What court rulings and legal actions hit cybersecurity this week?
Court rulings, filings and legal actions reported this week.
U.S. Army soldier Cameron John Wagenius was sentenced to 70 months in federal prison on September 25, 2026, in Seattle for hacking telecommunications companies including AT&T and Verizon.
Read at krebsonsecurity.com ↗A Brooklyn court sentenced 23-year-old Ronald Spektor to a prison term of four to 12 years.
Read at theblock.co ↗The U.S. Department of Justice has charged Lee Reiber, CEO of Oxygen Forensics, and Russian national Oleg Davydov with conspiracy to commit wire fraud for allegedly concealing the company's Russian ownership.
Read at cyberscoop.com ↗Employees of Archer-Daniels-Midland filed a class action lawsuit on September 21, 2026, following a data breach by the cybercriminal group Qilin.
Read at courthousenews.com ↗Security researcher Paulos Yibelo discovered a CSRF vulnerability dubbed 'Click2Shell' in WordPress Core versions 7.1.0 and earlier, which allows unauthenticated remote code execution.
Read at bleepingcomputer.com ↗What research was published in cybersecurity this week?
New research findings and studies published this week.
Researchers are exploring three methods to protect Bitcoin from potential future quantum computing threats, known as Q-Day.
Read at decrypt.co ↗A survey conducted by Cybersecurity Dive in September 2026 reveals that businesses are increasingly adopting AI for cybersecurity purposes.
Read at cybersecuritydive.com ↗Research by Conifers analyzed 14,652 threat detections and found that 47% of them in the average organization require attention due to logic bugs, missing telemetry, or configuration errors.
Read at helpnetsecurity.com ↗The ENISA Threat Landscape 2026 report, covering the period from January 1 to December 31, 2025, identifies a rise in cyber threats across Europe, including cybercrime, state-linked activity, and vulnerability exploitation.
Read at helpnetsecurity.com ↗Researchers from Graz University of Technology discovered decades-old security vulnerabilities in file notification subsystems across Android, Linux, macOS, and Windows.
Read at theregister.com ↗Researchers led by Nadia Heninger from the University of California at San Diego have developed a new method to forge RSA digital signatures without factoring the private key.
Read at arstechnica.com ↗Cisco Talos researchers identified a new autonomous malware implant named CLOSEDQUORUM that utilizes a panel of four LLMs (DeepSeek, Qwen, Mistral, and Google Gemini) to execute command and control operations without human intervention.
Read at talosintelligence.com ↗Cisco Talos researchers have released an open-source framework called CAIRN to identify and analyze AI-integrated malware.
Read at wired.com ↗8 of 25 research events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.
What incidents and outages hit cybersecurity this week?
Incidents, outages and safety events reported this week.
OpenAI, Anthropic, and various security researchers are currently investigating tens of thousands of security incidents involving frontier AI models.
Read at techmeme.com ↗Cryptocurrency exchange Bitget reported a theft of $351.6 million from its hot and warm wallets, discovered on the evening of September 24, 2026.
Read at bleepingcomputer.com ↗The Federal Bureau of Investigation (FBI) is investigating claims by the hacker group ShinyHunters that they breached bureau systems and stole data belonging to thousands of current and former employees.
Read at insurancejournal.com ↗The hacking group ShinyHunters claims to have breached the FBI, stealing sensitive data on thousands of agents and job applicants.
Read at techcrunch.com ↗The hacking group ShinyHunters compromised the FBI's jobs portal, fbijobs.gov, exposing personal information of approximately 5,000 individuals, including members of the Remote Operations Unit.
Read at gizmodo.com ↗Security researcher Patrick Wardle discovered a zero-day vulnerability in Meta's new AI assistant, Muse, on macOS.
Read at arstechnica.com ↗Microsoft's Digital Crimes Unit, in coordination with law enforcement and partners like SpyCloud, disrupted the EvilTokens phishing-as-a-service platform.
Read at bleepingcomputer.com ↗A Chinese-speaking threat actor exploited the CVE-2026-7273 vulnerability in Zyxel GS1900 switches, compromising 996 devices across 48 countries.
Read at helpnetsecurity.com ↗8 of 59 incidents and safety events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.
What partnerships were announced in cybersecurity this week?
Partnerships, integrations and joint projects announced this week.
Socure announced on September 25, 2026, that its RiskOS platform is now integrated into Circle's Arc blockchain.
Read at finextra.com ↗The Blueprint Alliance, led by Okta, has been formed to address the security risks posed by rogue and shadow AI agents.
Read at zdnet.com ↗OpenAI is extending its Daybreak program to the Government of Ukraine.
Read at openai.com ↗OpenAI announced it will provide its AI cyber defense system, Daybreak, and the GPT-5.6 Sol model to the Ukrainian government at no cost.
Read at techmeme.com ↗OpenAI has entered into an agreement to provide Ukraine with access to its advanced GPT 5.6 Sol artificial intelligence model.
Read at bbc.co.uk ↗On September 23, 2026, Brooklyn-based company Qunnect announced its ongoing collaboration with U.S. government agencies, including DARPA, In-Q-Tel, and the Air Force Research Laboratory, to develop quantum networking security solutions.
Read at hpcwire.com ↗6 of 7 partnerships events are listed; the rest were ranked lower by importance and multi-source corroboration and are not shown.