This briefing covers 15 cybersecurity and geopolitics
stories published around Sunday, September 27, 2026,
and 12 disclosed vulnerabilities
(CVE-2026-100833, CVE-2026-100835, CVE-2026-100840, CVE-2026-100843 and others).
Each entry links to the original reporting.
Washington and Beijing agreed to establish a bilateral mechanism for managing AI-related incidents, alongside continuing trade and military dialogue. The channel marks the first formal US-China AI risk coordination structure, setting a precedent for great-power AI crisis management.
The Lunex malware-as-a-service platform deploys a four-stage stealer against Ukrainian-speaking users via ClickFix-style fake Cloudflare CAPTCHAs, using a legitimate AMD driver to disable security monitoring before harvesting browser credentials.
Contrast versions 1.14.0โ1.23.0 contain CVE-2026-100833, where a bad rebase introduced an unverified `image_guest_pull` storage rule, enabling image substitution via Kata agent API access. Attackers with API access can silently swap container images, undermining confidential-computing supply-chain integrity.
CISA added CVE-2026-65660, an actively exploited Microsoft SharePoint flaw, to its Known Exploited Vulnerabilities catalog with a federal patching deadline of September 28. Active exploitation of SharePoint continues a persistent pattern of attackers targeting enterprise collaboration infrastructure for initial access.
heym before 0.0.91 carries CVE-2026-100864 (CVSS 8.8), allowing authenticated users to escape the expression sandbox via dunder attribute access and execute arbitrary Python commands as the backend process.
AzuraCast before 0.23.4 fails to sanitize Liquidsoap string interpolation in ConfigWriter, letting authenticated users with Media or Profile permissions inject and execute arbitrary code via CVE-2026-100857.
AzuraCast before 0.23.6 improperly migrated from a vulnerable string sanitizer, exposing the remote relay password field to nested Liquidsoap injection via CVE-2026-100856, enabling RCE and internal API key disclosure.
AzuraCast through 0.23.x fails to quote streamer usernames in Liquidsoap process.run calls, allowing authenticated station users to inject shell metacharacters and execute commands via CVE-2026-100852.
AzuraCast before 0.23.8 allows arbitrary DQL injection via the sortOrder API parameter in CVE-2026-100847 (CVSS 8.7), exposing user credentials and station configuration. Combined with three concurrent RCE vulnerabilities, the full AzuraCast attack surface now spans database exfiltration to OS-level code execution.
MONAI before 1.5.2 passes attacker-supplied .pkl files directly to pickle.loads in algo_from_pickle, enabling RCE via CVE-2026-100846 wherever the function processes untrusted input.
MONAI before 1.6.0 unconditionally sets allow_pickle=True in NumpyReader, letting attackers embed pickle payloads in .npy files for RCE via CVE-2026-100845 (CVSS 8.5).
MONAI versions before 1.6.0 contain a CVSS 8.5 RCE flaw in algo_from_pickle() via unsafe pickle.loads() deserialization, allowing arbitrary command execution via crafted files. Medical AI infrastructure running unpatched MONAI is directly exposed to supply-chain-style exploitation.
MONAI through 1.6.0 passes bundle _target_ values to arbitrary callables and $-expressions to Python eval() with no allow list, enabling RCE when victims load malicious bundles. Attackers can poison public model repositories to silently compromise medical AI pipelines at scale.
Contrast before 1.16.0 accepted valid TEE attestation reports regardless of originating hardware, allowing relay attackers to impersonate trusted enclaves across machines. The flaw undermines the foundational hardware-root-of-trust guarantee confidential computing deployments rely on.
Two unpatched RCE zero-days in Citrix NetScaler ADC and Gateway are under active exploitation as of September 26, with Citrix yet to confirm or patch either flaw. Administrators are pulling appliances offline, signaling attacker awareness outpaces vendor response on widely deployed network perimeter gear.