CISO Risk Intel Brief: Edge Zero-Days, Identity Residual Risk, and Q4 Control Priorities
This briefing covers two distinct horizons. The past week (23–30 September 2026) is a cluster of material, actively exploited edge and enterprise-application flaws, plus confirmed identity and third-party incidents. The past month (31 August–30 September 2026) shows those events as part of a faster pattern: perimeter appliances as the preferred initial-access class, build systems as ransomware feedstock, non-human identity as a wipe and extortion primitive, and overlapping EU and U.S.