This day 02:09 06:09 10:10 14:01 18:01 22:01
Info  2026-09-16 10:10Z · last 4h · 18 findings · glm-5.2:cloud

Threat Brief — 2026-09-16 — Lifecycle cliffs and supply-chain churn

Executive summary. Two lifecycle deadlines dominate today's brief: Windows Server 2022 enters extended support next month, and roughly 1.5 billion Android devices will receive no further patches. Separately, a dispute in the Void Linux project triggered a maintainer abandoning 113 packages overnight—an AI-assisted text-authorship disagreement that spiralled into an unplanned supply-chain gap. On the defensive side, enterprises are increasingly demanding "store nothing" modes for AI tools, pushing data-retention policy into a core procurement requirement.

Top items

Themes

Lifecycle as attack surface. Both the Windows Server 2022 mainstream-support expiry and the Android end-of-life wave arrive simultaneously, creating a broad window where large fleets transition from "patched by default" to "patched only with effort." The unifying risk is not a single CVE but the accumulated exposure of devices that fall through the support cracks.

Maintainer fragility. The Void Linux incident joins a growing pattern of supply-chain disruption driven by individual maintainer decisions rather than external attack. When a single person's departure can orphan over a hundred packages, the resilience question shifts from vulnerability management to dependency architecture.

===

THREAT-TOPICS===

[{"slug":"windows-server-2022-mainstream-support-ends","headline":"Windows Server 2022 enters extended support next month","findingIds":[11995],"status":"new","development":""},{"slug":"android-1-5-billion-devices-no-patches","headline":"1.5 billion Android devices face end-of-life with no further patches","findingIds":[11990],"status":"new","development":""},{"slug":"void-linux-ai-orphaned-packages","headline":"Void Linux loses 113 packages overnight after maintainer walks away","findingIds":[11993],"status":"new","development":""},{"slug":"ai-store-nothing-corporate-demand","headline":"Enterprises demand store-nothing modes for AI data retention","findingIds":[11980],"status":"new","development":""}]

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db