Cyber One Solutions logo.
Get Support

Security & Compliance Brief

Archive

Previous Briefs

Security Advisory

This Week's Top 5 Security Developments: Cisco's Maximum-Severity ISE Bypass and a Critical Email Gateway Flaw

Cisco disclosed a maximum-severity authentication bypass in Identity Services Engine and a critical SQL injection in Secure Email Gateway, both under confirmed active exploitation in the same week, while CISA added a year-old Linux kernel flaw and a backup-software privilege escalation to its Known Exploited Vulnerabilities catalog. Here are the top five verified developments for small and mid-size businesses, ranked by severity, exploitation evidence, and urgency.

Security Advisory

This Week's Top 5 Security Developments: A Record Patch Tuesday and Four New CISA KEV Warnings

CISA added six newly exploited vulnerabilities across Cisco, Fortinet, Citrix, and MikroTik to its Known Exploited Vulnerabilities catalog this week, while Microsoft shipped its largest Patch Tuesday on record with two actively exploited Windows zero-days. Here are the top five verified developments for small and mid-size businesses, ranked by severity, exploitation evidence, and urgency.

FTC Safeguards Rule / GLBA

A Chrome Zero-Day Under Active Attack Is a Test of Whether Your Patch Program Covers Browsers

CISA added CVE-2026-85046, a high-severity type confusion flaw in the V8 engine behind Chrome and every other Chromium-based browser, to its Known Exploited Vulnerabilities catalog on September 4, 2026, after Google confirmed active exploitation. It is the sixth actively exploited Chrome zero-day patched in 2026.

HIPAA Security Rule

A Critical Business Phone System Flaw Is Under Active Attack, and It Tests Your HIPAA Network Segmentation

CISA added CVE-2026-9586, an unauthenticated SQL injection flaw in the Sangoma Switchvox business phone system, to its Known Exploited Vulnerabilities catalog on September 2, 2026, after honeypots caught attackers deploying reverse shells. Roughly 4,000 Switchvox systems are reachable from the open internet, according to Shodan.

FTC Safeguards Rule / GLBA

A Citrix NetScaler Flaw Citrix Called "Denial of Service" Is Now Confirmed Root RCE Under Active Attack

CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog on August 26, 2026, confirming active exploitation of a Citrix NetScaler root RCE flaw.

CMMC

CMMC Phase 2 Is Suspended, Not Gone: What Defense Contractors Still Owe Under Phase 1

The Pentagon paused CMMC Phase 2 certification on July 13, 2026, and comment on its reform review closed August 14. Phase 1 and DFARS duties never stopped.

Texas Data Privacy and Security Act

TRAIGA Is Now in Effect: What Texas's New AI Law Means for Your TDPSA Compliance Obligations

The Texas Responsible AI Governance Act took effect January 1, 2026, giving the Attorney General a second privacy statute to enforce against Texas businesses that develop or deploy AI systems.

SOC 2

A Critical N-able N-central Bypass Is Exactly What SOC 2 Vendor Oversight Is Supposed to Catch

Attackers exploited an authentication bypass in the N-able N-central remote monitoring platform to seize admin control of MSP servers and reach client networks. For SOC 2-scoped service organizations, and the businesses that rely on them, it is a live test of vendor and subservice oversight.

Security Advisory

PCI DSS Payment Page Script Rules Are in Effect: A Real Checkout Skimming Attack Shows Why They Exist

PCI DSS Requirements 6.4.3 and 11.6.1 for payment page scripts are in effect, and a real WooCommerce skimming attack shows exactly why they exist.

HIPAA Security Rule

A Critical Check Point Firewall Management Bypass Tests Your HIPAA Access Control Safeguards

A critical Check Point SmartConsole flaw under active exploitation lets attackers seize firewall admin control. Patch now and review HIPAA access controls.

Cyber Insurance Readiness

A Critical SonicWall VPN Zero-Day Is Exactly What Your Cyber Insurance Application Already Asks About

Two actively exploited SonicWall SMA 1000 flaws can expose credentials and MFA secrets. Businesses using the appliance should confirm exposure, patch quickly, review logs, and keep proof for cyber-insurance reviews.

FTC Safeguards Rule / GLBA

A Federal Router-Hygiene Advisory Is a Test of Your FTC Safeguards and HIPAA Network Controls

CISA, the NSA, and the FBI urged businesses to harden their routers against Russian state actors. The fixes they name are controls that FTC Safeguards and HIPAA already require you to have and document.

CMMC

Update: CMMC Phase 2's November 10, 2026 Start Was Suspended, but Self-Assessment Obligations Remain

Update, August 23, 2026: The Department of Defense suspended this Phase 2 start date on July 13, 2026. Phase 1 self-assessment and DFARS obligations described below remain active regardless.

HIPAA Security Rule

A CISA-Confirmed SharePoint Exploit Is a Preview of Your Next HIPAA Risk Analysis Finding

CISA added an actively exploited SharePoint Server flaw to its Known Exploited Vulnerabilities catalog on July 1, 2026. For HIPAA-covered and FTC Safeguards-covered businesses, the real story is what unpatched, internet-facing software says about your documented vulnerability management program.

HIPAA Security Rule

OCR Keeps Settling Ransomware Cases Over One Missing Document: The Risk Analysis

Four ransomware settlements totaling $1.165 million, and every one cites the same missing document: an accurate and thorough risk analysis. While the proposed HIPAA Security Rule update sits unfinalized, OCR is enforcing the current rule, and mid-size healthcare businesses and their vendors are the ones paying.

About this brief

What you will find in the Security & Compliance Brief.

This section is original analysis, not a news rewrite. Each week we rank the most significant verified developments in the security and compliance landscape and explain what they mean for the obligations that drive managed IT and cybersecurity decisions.

The top verified developments, ranked every week.

Every Sunday we rank the three to ten most significant verified developments of the past week, drawn from sources such as CISA, HHS OCR, the FTC, and

NIST and cross-checked across independent reporting, by relevance, evidence of exploitation, business impact, and urgency.

Compliance-first framing.

Every brief ties back to a specific obligation: the FTC Safeguards Rule, HIPAA Security Rule, CMMC, PCI DSS, SOC 2, the Texas Data Privacy and Security Act, or cyber-insurance underwriting requirements.

The goal is practical guidance you can act on, not alarmist headlines.

Built for commercial decision-makers.

This is written for owners and operators evaluating their own compliance exposure, not for a security operations audience. If you want deeper technical guidance, visit our main blog; if you want a quick, current compliance angle, this is the place to start.

Common Questions

Frequently Asked Questions

How often is the Security & Compliance Brief published?

We publish every Sunday, ranking the three to ten most significant verified developments in the security and compliance landscape from the preceding week rather than covering just one story.

How is this different from the Blog and News pages?

The Blog covers long-form guides and best practices, and News covers company updates and individual advisories.

The Security & Compliance Brief is a weekly ranked digest: the most significant verified developments from the past week, each tied to an obligation such as HIPAA, the FTC Safeguards Rule, or CMMC.

Does this apply to my business if I am not in a regulated industry?

Most of our commercial clients are covered by at least one framework in this series, whether through HIPAA, the FTC Safeguards Rule, a cyber-insurance policy, or a client contract that requires SOC 2 or CMMC.

If you are unsure which obligations apply to you, contact our team for a review.