Wire digest (2026-09-18): Critical CVSS 9.8 libheif flaw disclosed; Virginia governor creates AI task force and tightens data center oversight
This batch contains two unrelated stories: Wordfence Argus disclosed a critical CVSS 9.8 vulnerability in libheif, a library widely used to process iPhone HEIC photos on servers, while Virginia Gov. Spanberger signed Executive Order 22 creating an AI task…
The two reports in this batch cover separate topics and are presented side by side rather than merged. First, Wordfence's Argus team disclosed a critical CVSS 9.8 vulnerability in libheif, the open-source library many servers use to process HEIC images from iPhones. Researchers demonstrated protected-file disclosure and code execution on a specific WordPress deployment; exploitation is described as target-specific, with no in-the-wild attacks reported and no CVE identifier listed in the announcement. The related 'HEIF Heist' research shows image-parsing exploits can be adapted to real-world systems. Second, Virginia Gov. Abigail Spanberger issued Executive Order 22, which bans executive branch officials from signing NDAs on data center projects, requires expedited noise regulations, mandates a review of data center backup-generation operations, and establishes an AI task force to evaluate workforce displacement, data privacy risks, and how existing law applies to AI harms. Spanberger also unveiled a Data Center Accountability Framework that would eliminate by-right approvals, remove some state subsidies, and add environmental guardrails. The move follows similar executive actions by governors in California (Newsom), New York (Hochul), and Texas (Abbott) as states act amid congressional inaction; the Piedmont Environmental Council criticized the order for not addressing existing projects. The two reports do not overlap, so no factual conflicts exist between sources.
- Wordfence Argus disclosed a critical vulnerability rated CVSS 9.8 in libheif, an open-source library used by many servers to process HEIC images from iPhones (Wordfence, 2026-09-18)
- Researchers demonstrated protected-file disclosure and code execution on a specific WordPress deployment; no CVE identifier was listed in the announcement (Wordfence)
- Exploitation is described as target-specific; no in-the-wild exploitation is reported (Wordfence)
- The 'HEIF Heist' research demonstrates that image-parsing exploits can be adapted to real-world systems (Wordfence)
- Virginia Gov. Abigail Spanberger issued Executive Order 22, banning executive branch officials from signing NDAs on data center projects (The Verge · AI, 2026-09-18)
- Executive Order 22 requires expedited noise regulations, a review of data center backup-generation operations, and establishes an AI task force to assess workforce displacement, data privacy risks, and how existing law applies to AI harms…
- A separate Data Center Accountability Framework would eliminate by-right approvals, remove some state subsidies, and add environmental guardrails (The Verge · AI)
- The Virginia action follows similar executive orders by Govs. Newsom (California), Hochul (New York), and Abbott (Texas), as states act while Congress has been slow on AI and data center policy (The Verge · AI)
Coverage timelineoldest first · each row is one article
- · 8d agoWordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server
Wordfence· 58
Wordfence Argus disclosed a critical CVSS 9.8 flaw in libheif enabling protected-file disclosure and code execution on vulnerable server deployments.
- · 8d agoVirginia governor creates an AI task force and moves to restrain data centers
The Verge · AI· 45
Virginia Gov. Spanberger's Executive Order 22 creates an AI task force, bans data center NDAs, and moves to curb data center approvals.