France’s cybersecurity agency ANSSI says it will stop certifying security products that don’t use quantum-resistant encryption, beginning in 2027. The policy effectively pressures government bodies and critical operators to phase out older cryptographic systems and buy only quantum-safe options by 2030.
For security teams, the practical takeaway is that crypto modernization is no longer “sometime later”—procurement and system lifecycles should be aligned to a post-quantum transition plan now, including data retention and key-management updates.
Source: Schneier Blog
Bad Epoll (CVE-2026-46242) Enables Root Access on Linux and Android
A newly disclosed Linux kernel vulnerability, “Bad Epoll” (CVE-2026-46242), allows local attackers with no special privileges to gain full root access on affected Linux systems and Android devices. The flaw’s impact is high because it is a privilege escalation that can turn a foothold into complete system compromise.
Organizations should prioritize patch validation across Linux fleets and Android devices, and review local access exposure (e.g., service permissions, container boundary assumptions, and untrusted code execution paths) while updates roll out.
Source: Security Affairs
ClamAV Releases Patches for Seven Scanner Bugs Dating Back Two Decades
Cisco Talos’ ClamAV project released two patch versions (1.5.3 and 1.4.5) that close seven security flaws affecting the scanning engine. Most issues are tied to executable parsing and unpacking logic, plus smaller hardening changes.
Because ClamAV is commonly embedded in mail gateways, file upload checks, and endpoint workflows, defenders should treat this as an “infrastructure component” update—not just an antivirus refresh—and ensure scanning pipelines are actually running the patched versions.
Source: Help Net Security
OAuth + Guest Accounts + Weak MFA Drive Unmanaged SaaS Risk
A new SaaS security report highlights how OAuth connections, long-lived guest accounts, and weak MFA contribute to excessive exposure in cloud environments. Guest accounts made up 69% of monitored SaaS accounts in 2025, outnumbering licensed users and increasing by more than 1.9 million year over year.
The key lesson is that “SaaS access hygiene” is not just user provisioning—it’s lifecycle management of OAuth grants and guest identities, including periodic access reviews and MFA enforcement for every authentication path.
Source: Help Net Security
Device Code Phishing via Microsoft Websites Targets OAuth Smart-Device Flows
SecureList details a “Device Code Phishing” attack that abuses OAuth 2.0 Device Authorization Grant flows, which were originally intended for devices like Smart TVs, printers, and IoT. Attackers are increasingly weaponizing the flow today, turning it into a convincing authentication trap.
Organizations should tighten OAuth client monitoring, review sign-in anomaly detection for device-code patterns, and educate users on the specific risks of device authorization approvals—especially where “checking the URL isn’t enough.”
Source: SecureList
AI Agent Security: Governance Gaps and “Stale” OAuth Grants Can Become Incidents
One analysis describes how AI agent incidents can become business events: the question isn’t just whether data was exfiltrated, but whether money moved, who owned the agent, and why it still had access. A scenario cited by the article attributes failure to an employee leaving while an OAuth grant remained active.
To reduce blast radius, teams should map agent permissions to business impact, enforce least-privilege OAuth grants, and implement automated deprovisioning and periodic review of agent integrations (especially for finance-adjacent tools).
Source: Help Net Security
TrojPix: Air-Gapped Data Exfiltration Using Video Cable Emissions
Researchers describe “TrojPix,” a technique that can leak data from air-gapped systems by modulating on-screen pixels so the connected video cable emits a faint, decodable radio signal. The approach is designed to work without a network connection and is difficult to detect using conventional perimeter controls.
While it requires malware already running on the target, it underscores a broader shift: defenders must consider side-channel leakage in high-assurance environments and tighten monitoring around compromised endpoints, display integrity, and nearby receivers.
Source: The Hacker News
You May Also Be Interested In...
The Future of Payment Fraud Could Be Automated