CVE-2026-35273, CVE-2026-88771, CVE-2026-88772
Get tomorrow's brief in your inbox
Today: The SEC charged Zoe Financial for failing to disclose conflicts of interest to clients. A New Mexico jury found Meta violated consumer protection laws nearly 44 million times by lying about data privacy practices, potentially costing the company billions in penalties. The Trump administration asked the Supreme Court to block lower court orders on transgender inmate healthcare policy and third-country deportations.
SEC Charges Zoe Financial for Failure to Disclose Conflict of Interest
The Securities and Exchange Commission charged New York-based investment adviser Zoe Financial Inc. for failing to fully and fairly disclose material facts concerning conflicts of interest to its clients and prospective clients. The charges were settled, though specific penalty amounts were not disclosed in the article summary.
ShinyHunters Exploiting Oracle PeopleSoft Vulnerability (CVE-2026-35273)
The ShinyHunters hacking group has resumed exploitation of CVE-2026-35273, a vulnerability in Oracle PeopleSoft disclosed in June 2026. Mandiant reports the group adapted to published defensive guidance and is now targeting organizations that implemented workarounds but did not patch the vulnerability. The campaign has expanded globally, deploying web shells on dozens of systems across higher education, technology, IT services, healthcare, agriculture, transportation, and government sectors. ShinyHunters recently claimed credit for breaching the FBI's jobs site through this vulnerability.
Citrix NetScaler Zero-Day Vulnerabilities Exploited (CVE-2026-88771, CVE-2026-88772)
CISA confirmed threat actors are actively exploiting two zero-day vulnerabilities in Citrix NetScaler application delivery controllers and Gateway devices globally. CVE-2026-88771 and CVE-2026-88772 both carry severity scores of 9.5/10. Citrix has released patches for these and six additional vulnerabilities. Federal agencies have until Wednesday to patch the two exploited vulnerabilities and conduct forensic triage on any systems using the products.
Former US Soldier Sentenced for Hacking Telecommunications Companies
Cameron John Wagenius, 22, was sentenced to 70 months in federal prison and ordered to pay nearly $295,000 in restitution for hacking into telecommunications companies while serving as an active duty Army soldier. Between April 2023 and December 2024, Wagenius and co-conspirators breached at least 10 organizations using a tool he created called "SSH Brute," stealing hundreds of thousands of sensitive business and customer records including call detail records and personally identifiable information. He attempted to extort organizations for at least $1 million in ransoms and contacted what he believed was a foreign military intelligence service to sell stolen data.
Cyberattack on Polish Healthcare Software Provider Qbusoft
Hackers exploited an SQL injection vulnerability in Qbusoft's Medyc medical records platform in August 2026, stealing patient names, national identification numbers, home addresses, phone numbers, email addresses, and potentially medical records including hospital treatment records and discharge summaries. The breach affected patients treated between July 2024 and August 2026. Poland's Digital Affairs Minister Krzysztof Gawkowski criticized Qbusoft for failing to initially report the incident to CERT Polska or the national healthcare incident response team. Poland's data protection authority has ordered an audit of the company.
Meta Found Liable for 44 Million Consumer Protection Violations
A New Mexico jury found Facebook violated the state's Unfair Practices Act nearly 44 million times by misleading consumers about data privacy practices. The jury determined Facebook willfully deceived consumers by claiming they controlled how their information was shared, that Facebook did not buy or sell user data to advertisers, and that the company did not profit from misinformation or hate speech. Facebook also lied about its investigation into third-party applications following the Cambridge Analytica scandal, failing to honor promises to investigate apps, conduct forensic audits, and alert affected users. Each violation carries up to $5,000 in civil penalties under New Mexico law, potentially costing Meta billions. A judge will determine final damages in the coming weeks.
Levoit Air Purifier Class Action Settlement ($15 Million)
Vesync, maker of Levoit air purifiers, agreed to a $15 million class action settlement to resolve false advertising claims. Specific details about the alleged misrepresentations were not provided in the article summary.
Summit Medical Data Breach Class Action Settlement
Summit Medical Group agreed to a class action settlement to resolve claims that a data breach compromised sensitive patient information. Settlement terms were not disclosed in the article summary.
Abbott Spinal Cord Stimulator Lawsuit
A Pennsylvania woman filed a lawsuit against Abbott Laboratories and Abbott Medical alleging defective spinal cord stimulation devices caused worsening pain, neurological injuries, and other health complications. The case adds to growing litigation over implantable medical device safety.
Ninth Circuit Requires Specific Evidence for Arbitration Based on Internet Contracts
In Rushing v. Williams-Sonoma, Inc., 2026 WL 2731408 (9th Cir. Sept. 16, 2026), the Ninth Circuit held that defendants seeking to compel arbitration based on internet contracts must tie visual evidence of arbitration disclosures to specific class members, not merely submit exemplar screenshots. This decision raises the evidentiary bar for defendants attempting to enforce arbitration provisions through online terms of service.
Delaware Court Highlights Risks of AI-Generated Board Meeting Transcripts
In ATG Capital Opportunities Fund LP v. Lane, the Delaware Court of Chancery relied on AI-generated transcripts of board meetings alongside official minutes when analyzing whether a board improperly rejected an activist investor's director nomination. The AI-generated transcripts contained additional context about board objectives and decision-making that was absent from official minutes. The court also cited ChatGPT exchanges in Fortis Advisors, LLC v. Krafton, Inc., 354 A.3d 906 (Del. Ch. Mar. 16, 2026), where a CEO's conversations with ChatGPT about avoiding contractual obligations became evidence of pretextual terminations.
ALPR False Positive Leads to Uninsured Motorist Citation Despite Valid Insurance
A Georgia student was ticketed twice for driving without insurance despite presenting valid insurance cards to officers, because Flock Safety ALPR systems flagged her vehicle as uninsured. Officers refused to verify insurance through their own systems and relied solely on the automated alert. The incident demonstrates law enforcement's increasing reliance on automated systems over traditional forms of proof.
EFF Challenges San Francisco Police Drone Expansion
The San Francisco Police Department has expanded drone use beyond its documented policy, deploying drones over 3,500 times in the first five months of 2026, up from 350 deployments in 2024. SFPD's proposed policy would allow drones as an extension of patrol abilities, potentially enabling general surveillance including of First Amendment-protected activity. The department violated California's AB 481 by purchasing drones without required approval from the Board of Supervisors before retroactively seeking authorization. The Electronic Frontier Foundation and over 40 organizations submitted comments to the Police Commission opposing the policy's lack of safeguards.
Supreme Court Activity on Third-Country Removals and Transgender Inmate Healthcare
The Trump administration asked the Supreme Court to pause lower court orders in two cases. First, a Massachusetts federal judge prohibited DHS from deporting immigrants to countries not identified in their removal orders without written notice, meaningful opportunity to challenge removal, and at least 15 days to seek reopening of immigration proceedings. Second, a D.C. federal judge blocked the Federal Bureau of Prisons from enforcing a February 2026 policy prohibiting transgender inmates from obtaining gender-transition surgeries, hormone therapy, and social accommodations. The administration argued the orders interfere with prison administrators' expert judgment and deprive the government of essential removal tools.
Justice Alito Recuses from Climate Change Case
Justice Samuel Alito will not participate in Suncor Energy Inc. v. County Commissioners of Boulder County, a case involving state-level tort claims holding oil and gas companies financially liable for their role in climate change. The Supreme Court provided no explanation for the last-minute recusal one week before oral arguments scheduled for October 5, 2026. Left-leaning watchdog groups had urged investigation of Alito's participation citing his substantial holdings in oil and gas companies.
Oracle PeopleSoft Users: Apply the June 10, 2026 patch for CVE-2026-35273 immediately. Workarounds are insufficient. Review database logs for unauthorized queries about HR, payroll, and records. Prepare incident response plans for potential extortion.
Citrix NetScaler Users: Federal agencies must patch CVE-2026-88771 and CVE-2026-88772 and complete forensic triage by Wednesday. All organizations must apply Citrix patches immediately and review systems for compromise indicators.
Healthcare Data Security: Verify medical records platform vendors have patched SQL injection vulnerabilities. Ensure vendors have incident response procedures that comply with CERT and sector-specific reporting requirements.
Consumer Privacy Representations: Review all public-facing privacy statements, policies, and marketing materials for accuracy. Ensure claims about data control, third-party sharing, and security practices can be substantiated and match actual practices.
AI Tools in Corporate Governance: Establish retention policies and controls for AI-generated meeting transcripts, recordings, and summaries. Recognize these records are discoverable in litigation. Review AI-generated records for accuracy before retention.