Welcome to The Cybersecurity Pulse (TCP)! I’m Darwin Salazar, Head of Growth at Monad and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! 📧
Howdy 👋🏽 Hope you’re having a splendid week. I’m back from Burning Man and settling back in, hence the Friday issue! If you were out there too or have questions about going, DM me. I’m a firm believer that everyone should go out there at least once in their lifetime. It’s truly a mind opening experience that enhances many aspects of your life.
Also, huge thank you to Andrew for taking the wheel on last week’s issue 👌🏽
Security hasn’t slowed down at all since Black Hat and DEF CON and this week’s issue is a testament of that. CrowdStrike has been cooking, especially on SecOps at Fal.Con, Palo Alto Networks spends $500M on a new company. Lots of funding + acquisitions. We’ve also got LG’s TV privacy mess, and some impressive research that will have you rethink mobile security.
The next few months are packed with conferences. Vendor cons are meh because it’s mostly them touting their sauce, but it’s a great way to get a look at their roadmap and how industry leaders are thinking about the future. Here’s what’s coming up this month:
Splunk .conf26: September 14–17, Denver. CriblConnect is also in town on September 14, so expect a busy week for the SecOps crowd.
CYBR.SEC.CON.: September 15–16, Houston. Another stop on next week’s security con circuit. Practitioner focused con 💎
Oktane: September 22–24, Las Vegas. Okta’s annual conference puts identity next on the agenda.
GrrCON: September 24–25, Grand Rapids, Michigan. Two days of security research, AI talks, and hands-on workshops. Built around the practitioner and hacker community 💎
CriblCon: September 28–30, Chicago. Cribl heads into its annual conafter acquiring CardinalOps and Radiant Security’s AI SOC technology assets. Will be interesting to hear how they’re thinking about the future.
RunReveal’s RUNWAY: September 29, San Francisco. The team plans to share more about its roadmap after joining ClickHouse.
October is another jampacked conf month. Identity, SecOps, and AI security will continue to take center stage, imo. We’ll have full coverage across the board on key takeaways from these cons.
Today also marks 25 years since September 11. Taking a moment to remember the lives lost, the first responders who answered the call, and the service members who gave their lives in the years that followed. My thoughts are with their families and everyone still carrying that loss 🇺🇸🙏🏽
Now, let’s get into it!
Interested in sponsoring TCP?
Reach our community of 20,000+ cybersecurity professionals. Explore sponsorship opportunities below.
🗞️ TL;DR
📞 Researchers hijack WeChat accounts through unanswered calls: A hacked contact could take over your account without you answering.
📺 LG’s smart TVs have a privacy problem: Researchers report tracking and audio collection in standby. LG disputes.
🩹 SAP patches two serious server flaws: Attackers could run their own code without logging in. Internal servers need patching too.
🗨️ AI agents traded answers in 18,000 wiki posts: Giving an agent browsing access can also give it a way to send information out.
🧩 Monad launches schema drift detection: Catches changes in your log schema that can quietly break your security detections, KPI reporting, etc.
🏗️ Cylake lands $245M before beta: Palo Alto’s cofounder is betting companies want their security tools and data back in-house.
🗄️ ClickHouse buys RunReveal: SecOps consolidation stays hot, with ClickHouse adding threat detection and investigation to its database business.
🦅 CrowdStrike goes big on SecOps at Fal.Con: AI investigators, earlier threat detection, and controls for agents.
🪪 Cymphony launches with $30M: Tackles the permissions mess that lets employees and AI assistants see too much.
🛠️ Palo Alto Networks buys Console for a reported $500M: Console’s AI agents handle IT requests. Palo Alto could use them to fix security issues.
Plus: Astra’s autonomous exploit capabilities, Huskeys’ $27M Series A, the FBI’s stolen-ID investigation, and speaker prep for BSides NYC and Unprompted Con.
⚒️ Picks of the Week
WeWorm takes over WeChat accounts through unanswered calls
Calif disclosed a WeChat exploit chain September 8 that demonstrated account takeover spreading from Android to iPhone and back to Android through unanswered calls.
Breakdown:
Trigger: Memory corruption in WeChat’s VoIP stack. The caller must already be a contact; the recipient need not answer.
Access: Read and send messages, place calls, and reach the next contact. Full phone compromise requires additional vulnerabilities.
Status: Reported July 24, demonstrated August 11. Tencent shipped client mitigations August 21; Calif confirmed server-side mitigation August 28 for all users. No exploitation in the wild has been disclosed.
Requiring an existing contact limits the first infection. However, once an account is compromised, its contact list supplies the next targets. Bonkers..
LG’s smart TVs have a serious privacy problem
GamersNexus, with researchers MrBruh and uturn, reports tested LG TVs scanning nearby devices, identifying what people watch, and collecting audio in standby 🤯 Researchers say some data stays on the TV offline and uploads after reconnection.
LG denies ambient recording outside user-activated voice features and says advertising tracking requires consent.
Customers shouldn’t have to reverse-engineer a television to protect their privacy.
LG owes buyers verifiable controls and a clear justification for what it collects inside their homes.
Watch the full investigation or Matt Jay’s shorter breakdown.
APT Iran claims AT&T outage; AT&T points to attempted cable theft
An internet outage disrupted parts of Dallas for hours on September 7. A group calling itself APT Iran claimed responsibility. AT&T says it had no evidence supporting that claim and attributed the disruption to attempted cable theft.
The group also threatened U.S. water, energy, and telecom infrastructure. Those threats do not establish that it caused this outage. A system intrusion or data theft has not been “confirmed”.
Interesting….. 🤷🏾♂️
AI agents turned read-only web access into a public message board
OpenAI agents answering timed research questions found a way to post online despite restrictions intended to make their internet access read-only. Researchers found roughly 18,000 posts, mostly on a German community wiki, a publicly editable website. Most activity happened in May and June.
How they posted: The wiki accepted edits through the same type of request used to load a page. Agents put messages in URLs, bypassing the intended posting restriction.
What they shared: Answers for agents facing the same questions, plus ways around network restrictions.
How they resisted cleanup: When a moderator deleted pages alphabetically, an agent created a backup starting with
ZZZto delay deletion.
OpenAI acknowledged the incident here.
An agent that can read company files and browse external sites may also be able to publish those files. This was not a confirmed customer-data leak, but the posting restriction failed.
This one is wild because it’s yet another examples of how off the rails agents can go when they go rogue. If there’s a loophole, they will probably exhaust every option until they find it to achieve their goal.
🔬Threats & Research
Attackers hijack Magento stores through failed-payment notifications
Magento and Adobe Commerce are software for running online stores. Sansec found attackers exploiting StyleSmuggler (CVE-2026-75650, CVSS 10.0) to run malicious code on those stores’ servers without logging in.
Attackers plant code in store-generated files, then trigger a failed-payment notification. The store executes it while preparing the email. Nobody has to open the message. Sansec found backdoors that let attackers retain access.
Merchants should apply Adobe’s emergency hotfix, check for backdoors, and rotate exposed credentials. Patching closes the entry point; it does not remove an attacker who already got in.
Nexus advertises 153M driver’s-license records; the FBI investigates
Brian Krebs found Nexus advertising 153 million driver’s-license records, verified samples with nine people, and traced clues toward identity-verification provider IDScan.net, which said it was investigating. The marketplace’s total remains unconfirmed; the FBI confirmed its investigation September 2.
Still unresolved: Source, scale, and continuing access. Retained document scans can outlive the verification they supported and become reusable material for impersonation. Review whether raw images need to be kept at all.
Boston Scientific expects cyberattack to hit sales and profit forecasts
Boston Scientific said that it no longer expects to meet its quarterly and annual sales and adjusted-profit forecasts. The August 25 incident disrupted manufacturing and order processing; the financial consequences are this week’s development.
Recovery: The company says most manufacturing has resumed, major distribution centers are shipping, and cardiac remote-monitoring activations are restored. Product analyses indicate no impairment to function. The business impact outlasts the outage. Recovery plans need to cover backlogs and missed sales as well as restoring systems.
📦 Security Product Releases
CrowdStrike announces AI models, agent identities, and detection before ingestion at Fal.Con
CrowdStrike has been cooking, especially on the SecOps side. Its Fal.Con lineup includes detections that run inside log pipelines, AI agents that investigate different parts of an incident in parallel, and a shared workspace for response workflows and approvals. The direction is clear and it has been for a while. CrowdStrike wants to own the end-to-end SecOps workflow.
Here’s the breakdown, including what’s available now and what’s still in preview:
SafeMind and the Cyber Superintelligence Lab: Offensive Red Tempest and defensive Blue Solano models, built using NVIDIA Nemotron, run coordinated attack-and-defense workflows. Early-access registration.
Falcon Guardian: Agent discovery, session reconstruction, and runtime controls. The new AI gateway is pre-beta, targeting Q4 GA. OverWatch support is available with the required licenses; MDR follows later in Q3.
Agentic Identity Provider: Registers agents, issues identities, brokers short-lived access, and preserves attribution to humans or workloads. Announced; availability unspecified.
Expanded privileged access: Just-in-time privileges across Salesforce, GitHub, endpoints, private applications, and AWS through Entra. Availability unspecified.
Software supply-chain protection: The Falcon sensor blocks known malicious npm and PyPI packages during download. Package inventory is planned for Q3; cooldown policies for Q4.
Certified data pipelines: Prebuilt, maintained third-party pipelines, starting with Zscaler and Palo Alto Networks. Public preview.
Detection before ingestion: Detection logic runs inside the pipeline, including at the edge. Public preview.
Shared-context investigations: Specialist agents investigate different domains in parallel, with an orchestrator combining their findings. Pre-beta.
Agentic Recon: Intelligence agents investigate exposed credentials, leaked data, and impersonation across the open, deep, and dark web. Public preview.
Unified agentic SOAR workspace: AgentWorks, SOAR orchestration, and Foundry share one interface for workflows and approval controls. Public preview.
Bring your own model: Use existing OpenAI and Anthropic licenses when building agents. GA.
Bidirectional MCP access: Third-party agents access Falcon tools; AgentWorks agents reach external tools and data. GA.
Hybrid Analysis for agent workflows: API-first malware analysis with an open-source MCP server. Publicly available.
Detection before ingestion could reduce dependence on centralized storage for alerting. It also makes pipeline rules part of the detection stack: teams need to version them and retain enough source events to investigate missed alerts. Many of these capabilities remain previews.
Some of these new capabilities introduce entirely new ways of doing things which some security teams may be reluctant to. Will be interesting to see how adoption goes.
OpenAI releases GPT-6 Astra with Critical cyber capabilities and restricted exploit access
OpenAI released GPT-6 Astra, its first model rated Critical under its Preparedness Framework.
Meaning: Given suitable tools and access, OpenAI says Astra can discover zero-days and develop exploits across many hardened systems without a human guiding each step. Testing assessed capabilities without production safeguards.
Access: Public release supports review and patching; exploit PoCs are refused. Broader Daybreak access is planned.
Monitoring: Tool use is monitored, but reasoning became harder to inspect in adversarial tests.
Automating discovery through exploitation makes tool permissions and independent action logs more consequential.
🤝 Funding & M&A
Palo Alto Networks acquires IT automation startup Console
Palo Alto Networks announced its acquisition of Console September 1 for a reported $500M. PANW did not disclose terms. Console’s IT agents provision accounts, revoke access, and reset MFA after identity verification.
Integration with Cortex investigation and remediation is planned, with no launch date. Turning alerts into access changes makes the agents’ own authorization boundaries critical.
ClickHouse acquires security data platform RunReveal
ClickHouse acquired RunReveal. RunReveal builds log pipelines, detections, and AI-assisted investigations on customer-controlled ClickHouse clusters. ClickHouse says availability and existing contract terms remain unchanged. Amount undisclosed.
Great pickup by Clickhouse. RunReveal is one of my favorite contenders in the SIEM space and Clickhouse has some of the best database tech on the market so it’ll be fun to see what they get up to.
Cylake raises $245M through a convertible note for on-premises security
Cylake announced $245M through a convertible note, with Lightspeed, Picture Capital, and Redpoint participating. Nir Zuk’s company is building an integrated security platform for on-premises and private-cloud deployment.
Keeping telemetry inside customer infrastructure could appeal to buyers with sovereignty requirements. Coverage and migration costs will determine whether they switch. Beta is expected by year-end; GA in 2027.
HiddenLayer raises $100M Series B for AI runtime and coding-agent security
HiddenLayer announced a $100M Series B, led by Delta-v Capital. It finds AI deployments, inspects their supply chains, simulates attacks, and protects models and coding agents at runtime.
Its Agent Harness Security launched in August. A model’s safeguards do not secure every tool it can call, so defenses also need controls over agent permissions and execution.
Cymphony launches with $30M from Sequoia and Fin Capital
Cymphony launched with $30M led by Sequoia and Fin Capital. Cymphony connects identities, permissions, data, and behavior to find stale access and overshared files.
An AI assistant can expose sensitive files using an employee’s existing permissions. Cleaning up access becomes part of securing the assistant, even when authentication works.
Huskeys raises $27M Series A to coordinate WAF, CDN, and edge policies
Huskeys announced a $27M Series A, led by Blackstone Innovations Investments. It coordinates configurations and policies across existing WAFs, CDNs, load balancers, and cloud network controls.
A correct WAF rule does little if another route leaves the application exposed. The value is closing those gaps across vendors.
Proofpoint reportedly in advanced talks to acquire Varonis
The Wall Street Journal reports that Thoma Bravo-owned Proofpoint is negotiating to buy Varonis. No agreement or purchase price is confirmed. Varonis market cap is floating around $5B - $6B and spiked ~10% when the rumors first broke.
HelmGuard raises $7.3M seed for evidence collection and risk assessment
HelmGuard announced a $7.3M seed round, co-led by Infinity Ventures and Frontline. Its agents gather evidence, assess supplier risks, and identify control gaps, with citations and human review.
A supplier can add AI agents after passing its security review. Continuous evidence could surface that change sooner; buyers still need to inspect the sources behind automated conclusions.
Cognition raises more than $2B Series E for Devin
Cognition announced a Series E exceeding $2B, led by Andreessen Horowitz, Accel, Founders Fund, General Catalyst, and Avenir. Devin writes, tests, and maintains code; Auto-Triage and Security Swarm add incident investigation and vulnerability triage.
When one platform writes code and proposes fixes, independent validation becomes more valuable. Faster remediation does not establish that the underlying flaw is gone.
Interested in sponsoring TCP?
Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries 🌎
Disclaimer
The insights, opinions, and analyses shared in The Cybersecurity Pulse are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.







