Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Sep 29, 2026·4m

Cyber Security News for September 29 2026 - Daily DefSec Brief

Show notes

1. Exploited Apple flaw fixed for older releases — CVE-2026-86950 — Fixed: 26.7.1 · 15.8.1 — Do: Update iPhones and Macs still on older releases — https://support.apple.com/en-us/149229

2. Featured Chrome ad blocker is spyware — Do: Remove Poper Blocker and allowlist Chrome extensions — https://www.darkreading.com/application-security/chrome-store-poper-blocker-spyware-downloaded-millions

3. A webpage can run code through OpenCode — Fixed: 1.18.22 — Do: Upgrade OpenCode on every developer machine — https://github.com/anomalyco/opencode/security/advisories/GHSA-632h-h47v-g4x4

4. 16,326 Supabase databases readable by anyone — Do: Turn on row-level security for every Supabase table — https://www.upguard.com/blog/everything-everywhere-systemic-data-exposure-in-supabase-apps

5. MCP Python SDK leaks OAuth secrets — Fixed: 1.30.0 or 2.2.0 — Do: Upgrade the MCP Python SDK, rotate client secrets — https://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-qx49-fqc8-xw99

6. NeedyMantis keeps access after the break-in — Do: Hunt NeedyMantis sideloading, block its domain — https://www.microsoft.com/en-us/security/blog/2026/09/28/needymantis-unpacking-a-post-compromise-malware-family-used-in-targeted-operations/

7. Authlib accepts JWS with no signatures — CVE-2026-96760 — Do: Reject empty-signature JWS before Authlib sees it — https://kb.cert.org/vuls/id/762428

8. Old branded QR codes can be taken over — Do: Delete DNS records pointing at abandoned QR services — https://cyberinsider.com/hackers-can-hijack-qr-code-domains-to-redirect-users-to-phishing-sites/