
Cyber Security News for September 30 2026 - Daily DefSec Brief
Show notes
1. A password reset led to Kubernetes credentials — Do: Alert on sign-in methods added after resets — https://www.microsoft.com/en-us/security/blog/2026/09/29/beyond-source-code-a-path-to-the-keys-to-the-kingdom/
2. A package name runs commands in AWS AgentCore — CVE-2026-12530, CVE-2026-16796 — Fixed: 1.18.1 — Do: Upgrade the Bedrock AgentCore Python SDK — https://aws.amazon.com/security/security-bulletins/2026-065-aws/
3. An Octopus project edit runs code on the server — CVE-2026-101169 — Fixed: 2026.1.11781 · 2026.2.13441 · 2026.3.15829 — Do: Upgrade self-hosted Octopus Server — https://advisories.octopus.com/post/2026/sa2026-10/
4. OpenSSL DTLS leaks heap memory to a peer — CVE-2026-84782 — Fixed: 4.0.3 · 3.6.5 · 3.5.9 · 3.4.8 · 3.0.23 — Do: Update OpenSSL wherever DTLS is in use — https://openssl-library.org/news/vulnerabilities/
5. Stolen passwords opened France's tax portals — Do: Require MFA on every staff and partner portal — https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html
6. Windows gets built-in Linux containers — Do: Set the WSL containers policy in Intune — https://blogs.windows.com/windowsdeveloper/2026/09/29/wsl-containers-now-generally-available/
7. Coding agents post private screenshots publicly — Do: Stop coding agents from creating public repos — https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies