Sober Thoughts. Drunk Posts.

Another “Newsletter” Day, Another Parade of Things We Will Patch After It’s Too Late

Another “Newsletter” Day, Another Parade of Things We Will Patch After It’s Too Late

Another zero-day patched just in time for nobody to notice. That is the theme of this “Security News Newsletter – Wednesday, September 23, 2026” thing you probably glanced at between meetings where someone asked why security “does not feel proactive.” Sure. I’m sure. Pour yourself a drink (scotch if you have it, rum if you have poor governance), because today’s crop of stories reads like a greatest hits album for modern chaos: AI-powered crime, exploited infrastructure, and yet another reminder that IT culture still treats patching like a suggestion.

The Big Mood: Exploited Means “Already In”

Some headlines are annoying because they’re vague. These are annoying because they’re specific. The standout theme is exploited zero-days and critical flaws showing up where you least want them: edge-facing, authentication-adjacent, and otherwise positioned to turn “brief outage” into “unplanned incident response budget increase.”

For example, the newsletter includes Critical F5 BIG-IP Vulnerability Exploited as Zero-Day. The phrase “unauthenticated attackers” plus “remote code execution” is the kind of combo that makes you wonder how many times an attacker has to tap the glass before leadership stops demanding “visibility” and starts demanding “patching.” If you’re waiting for the vendor to “release guidance,” congratulations, you’re practicing customer support as a security control.

AI: The Upgrade That Keeps Getting Misused

Then there’s the AI storyline. Not the “transforming the enterprise” kind. The “the attackers now scale faster and target better” kind. The newsletter calls out AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft, describing an attack chain where AI is used to write social engineering messages and help decide targets.

So yes, attackers are getting better at what humans have always been bad at: identifying deception under time pressure. Meanwhile, defenders are still wrestling with the same tired problems – patch cadence, asset inventory, MFA enforcement that somehow is “in progress,” and alert fatigue so severe it’s basically a career path at this point. AI is not the threat. Human process failure is the threat. AI just turns the failure mode into an assembly line.

OT and the Eternal Asset Inventory Problem

The newsletter also includes a Honeywell piece: OT Security Teams Embrace AI, but Autonomy Still Rare. The stats about incomplete OT asset inventories are depressingly familiar: “mature” programs, but not complete visibility. That’s like saying you have a fire extinguisher “strategically placed” while you do not know where the building is.

So What Should You Do, Besides Read More?

If your action plan for exploited vulnerabilities is “forward the link,” you’re doing threat modeling for the attacker’s calendar. Start where the boring controls live: patch exploited paths quickly, validate exposure on internet-facing systems, tighten access around management and orchestration, and treat inventory gaps as incidents waiting to happen. Vendors will keep shipping advisories. Attackers will keep weaponizing what’s reachable. The only variable you control is whether you respond with discipline or with vibes.

Read the original source article here: Security News Newsletter – Wednesday, September 23, 2026

Tags :
Sober Thoughts. Drunk Posts.
Share This :