Funding grants for new research into AI and teen development
OpenAI launched a $5 million grant program funding independent research on generative AI's effects on teen development, well-being, and safety.
OpenAI opened applications for a $5 million grant program supporting independent research into how generative AI affects teen development, well-being, and safety. The program was announced via the OpenAI newsroom on 2026-09-08.
CVE-2026-73470: Apache Syncope: Delegating users can grant unowned Roles
Apache Syncope CVE-2026-73470 lets delegated users grant roles they do not own via crafted delegations.
Apache Syncope disclosed CVE-2026-73470, an improper privilege management vulnerability rated important. Delegations can be created or updated so that delegated users are able to grant roles they do not own, breaking ownership constraints. The flaw affects syncope-core-provisioning-java in versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Users are advised to upgrade to the latest fixed releases.
New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access
Researcher Nightmare Eclipse released 'ShieldCrash', a zero-day exploit for Microsoft Defender that grants attackers SYSTEM-level access.
An anonymous researcher known as Nightmare Eclipse published a zero-day exploit for Microsoft Defender, dubbed 'ShieldCrash', that yields SYSTEM-level access. The release came immediately after Microsoft rolled out its September 2026 Patch Tuesday security updates. No CVE identifier has been assigned publicly and no in-the-wild exploitation has been reported yet. Microsoft Defender ships by default on Windows, so potential exposure is broad until Microsoft patches the flaw.
ZDI-26-629: Microsoft Azure Entra ID OAuth Device Code Grant Information Disclosure Vulnerability
Zero Day Initiative disclosed an unauthenticated information disclosure vulnerability (CVSS 5.8) in Microsoft Azure Entra ID's OAuth device code grant flow.
ZDI published advisory ZDI-26-629 describing an information disclosure vulnerability in Microsoft Azure Entra ID related to the OAuth device code grant. Remote attackers can disclose sensitive information without authentication. ZDI assigned a CVSS 3.1 score of 5.8; no CVE identifier is listed in the advisory text.
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft details Teams IT-support impersonation campaigns deploying Node.js implants, AD reconnaissance, and WinRM lateral movement toward domain controllers.
Microsoft Threat Intelligence describes a human-operated campaign where attackers impersonate IT/helpdesk staff via Microsoft Teams external collaboration, talk users into granting remote sessions, and use RMM tools for interactive access. During the session they run PowerShell to silently install a malicious MSI that stages a portable Node.js runtime and obfuscated JavaScript implant for C2, executing follow-on payloads via rundll32. Operators then perform host and Active Directory reconnaissance, capture desktop screenshots, and pivot via WinRM on port 5985 to domain controllers and certificate authorities. The hands-on-keyboard chain, which can precede data theft and ransomware, blends into normal operations by relying on Teams, Quick Assist, msiexec, and Node.js; Microsoft shares hunting and mitigation guidance.
FBI raises alarm over deceptive phishing campaign targeting prominent people
The FBI warns of an ongoing OAuth consent phishing campaign granting attackers persistent access to high-profile victims' cloud accounts without passwords.
The FBI says attackers impersonate government officials, journalists and event coordinators on commercial messaging apps to trick prominent individuals, their families and acquaintances into authorizing malicious OAuth applications on Microsoft or Google cloud services. Once approved, attackers gain persistent access to emails, files and other sensitive data; the access survives password changes and bypasses MFA, and can only be revoked by invalidating the OAuth token in security settings. The campaign has been tracked since late 2025, and the FBI advises independently verifying senders and granting access only to trusted applications.
IAM Compliance Requirements and Best Practices
A guide maps IAM compliance requirements across SOX, PCI DSS, HIPAA, ISO 27001 and NIST 800-53, urging verified enforcement over documented policies.
The guide argues IAM compliance requires demonstrating that access controls are enforced at runtime, not merely documented, highlighting gaps between policy intent and application-layer execution. It maps recurring requirements across SOX ITGCs, PCI DSS v4.0, HIPAA, ISO/IEC 27001:2022, NIST SP 800-53 and GDPR, covering least privilege, separation of duties, access certification and audit trails. It recommends continuous, evidence-backed verification and application-layer telemetry instead of relying on identity provider logs or quarterly access reviews.