ZeroHour

Search: “developers”

11 stories in the last 24h

AI agent authorization risks remain a gap in new NIST-CISA token security guidance

NIST and CISA release IR 8587 guidance on securing signed tokens, but AI agent authorization and delegation risks remain out of scope.

NIST, with CISA support, published 'Protecting Tokens and Assertions from Forgery, Theft, and Misuse' (NIST IR 8587), recommending continuous monitoring and tighter token lifecycle controls for SSO and API access. The guidance does not yet fully address AI agent identity, delegation chains, or prompt injection steering agents with valid tokens, and NIST says new or expanded standards are needed. Experts recommend treating AI agents as low-trust non-human identities, maintaining agent inventories, expiring credentials after task completion, and requiring human approval for high-risk actions. The report references shared-signal mechanisms like CAEP and RISC, and follows a May incident where a CISA contractor GitHub repository exposed AWS and GitHub tokens.

CSO Online · 10h agoAdvisory

watchOS 27.2 beta (24S5086l)

Apple released watchOS 27.2 beta build 24S5086l to developers for testing.

Apple has published watchOS 27.2 beta build 24S5086l on its developer release portal. The listing provides download access and release notes for the pre-release update. No security content or vulnerability details are included in the notice.

Apple software releases · 9h agoAdvisory

macOS 27.2 beta (26B5086k)

Apple released macOS 27.2 beta build 26B5086k to developers for testing.

Apple has published macOS 27.2 beta build 26B5086k on its developer release portal with downloads and release notes. The notice contains no security advisories or CVE information.

Apple software releases · 9h agoAdvisory

iOS 27.2 beta (24B5084k)

Apple released iOS 27.2 beta build 24B5084k to developers for testing.

Apple has published iOS 27.2 beta build 24B5084k on its developer release portal. The listing includes download access and release notes but discloses no security fixes or CVEs.

Apple software releases · 9h agoAdvisory 2 sources

visionOS 27.2 beta (24N5088l)

Apple seeded visionOS 27.2 beta build 24N5088l to developers with no security details disclosed in the release listing.

Apple released visionOS 27.2 beta (build 24N5088l) to developers on September 16, 2026, per its software release listing. The listing contains only download links and a pointer to release notes, with no security content or vulnerability details. It is a routine developer beta with no reported exploitable issues.

Apple software releases · 9h agoAdvisory

Xcode 27.2 beta (27B5019j)

Apple released Xcode 27.2 beta build 27B5019j to developers for testing.

Apple has published Xcode 27.2 beta build 27B5019j on its developer release portal, with downloads and release notes available. The notice contains no security advisories or CVE information.

Apple software releases · 9h agoAdvisory

tvOS 27.2 beta (24K5088l)

Apple seeded tvOS 27.2 beta build 24K5088l to developers with no security details disclosed in the release listing.

Apple released tvOS 27.2 beta (build 24K5088l) to developers on September 16, 2026, per its software release listing. The listing contains only download links and a pointer to release notes, with no security content or vulnerability details. It is a routine developer beta with no reported exploitable issues.

Apple software releases · 9h agoAdvisory

CISA and NIST Issue Guidance to Protect Cloud Identity Tokens

CISA and NIST published Interagency Report 8587 with voluntary guidance to harden cloud identity tokens against theft, forgery, and lateral movement.

CISA and NIST released NIST Interagency Report 8587 on September 15 with final voluntary guidance for federal agencies, cloud providers, and their customers on protecting SSO, federation, and API tokens. Requirements include one-hour maximum token lifetimes, 90-day signing key rotation for high-impact systems, hardware-backed key storage, explicit audience fields, and keeping tokens out of logs. The guidance was motivated by the 2020 ADFS compromise where forged SAML assertions bypassed MFA, and an incident where a leaked consumer signing key enabled token forgery and theft of 60,000+ emails from one agency. Nearly 250 public comments shaped the text, with input from Google, Microsoft, Okta, AWS, Oracle, IBM, HashiCorp, Wiz, and the OpenID Foundation via the Joint Cyber Defense Collaborative.

Infosecurity Magazine · 12h agoAdvisory

Oracle Critical Security Update – 673 Vulnerabilities Patched Across Product Families

Oracle's September 2026 Critical Patch Update ships 673 patches across 17 product families, including 100+ critical and 240+ remotely exploitable flaws.

Oracle's September 2026 Critical Security Patch Update ships 673 patches covering 672 unique CVEs, with more than 130 additional CVEs resolved through bundled fixes, pushing the effective total past 800. Over 100 flaws are critical severity and more than 240 are remotely exploitable without authentication. Oracle E-Business Suite received 159 fixes, Fusion Middleware 153 (78 unauthenticated and network-exploitable), and Hyperion 102. No in-the-wild exploitation of these specific flaws is reported, but Oracle cites CISA's earlier 72-hour remediation order for actively exploited CVE-2026-21962 (CVSS 10.0).

Cyber Security Newsupdated · 6h agofirst · 13h agoAdvisory 3 sourcesCVE-2026-21962

Using Cyber Decoys to Strengthen Detection and Response

CISA released guidance on cyber decoys—tripwires, breadcrumbs, honeytokens—to help defenders detect adversaries using valid credentials and living-off-the-land techniques.

CISA published guidance to help defensive teams of varying maturity plan and implement cyber decoys—assets that mimic legitimate systems, accounts, or data, such as tripwires, breadcrumbs, and honeytokens—to detect adversaries using legitimate credentials and living-off-the-land techniques. The guidance frames decoys as complementing Zero Trust by producing high-fidelity alerts, reducing alert fatigue, and exposing post-compromise activity like discovery, lateral movement, and data access. It maps decoy operations to the MITRE Engage and MITRE ATT&CK frameworks with low-complexity implementation steps.

CISA Advisories · 14h agoAdvisory

NIST and CISA finalize playbook to stop token theft and forgery

NIST and CISA finalized NIST IR 8587, a playbook helping federal agencies and cloud providers defend identity tokens against theft and forgery.

The finalized NIST IR 8587 guidance covers protecting token signing keys, verifying tokens, lifetimes, revocation, session management, and dividing security responsibilities between cloud providers and customers. It cites an incident in which foreign actors forged tokens with a stolen commercial signing key to steal more than 60,000 emails from one government agency. It also recommends extending token protections to AI agents and preparing identity systems for a future post-quantum cryptography transition.

Help Net Security · 18h agoAdvisory 2 sources