This is your security briefing for Sunday the 20th of September 2026, covering what the BlueTeamSec community on infosec.pub was sharing over the past day — six stories to get through.
JFrog disclosed a local privilege escalation in Parallels Desktop for Mac — an unprivileged user can inject arguments into the dispatcher service's appliance installer and drop a malicious tar file to get a root shell. One for anyone running the virtualisation software on endpoints.
Hacktron published details on a broader set of vulnerabilities in image processing libraries — specifically libheif and libde265, used to handle HEIF, HEIC, and AVIF files. The flaws affect multiple versions and can lead to memory corruption or remote code execution when untrusted images are processed server-side. Worth flagging if you're running web services that accept image uploads.
Also from Hacktron — a write-up on how researchers compromised multiple OpenAI employee ChatGPT accounts back in July by chaining a heap overflow in the company's Discourse forum with an SSO misconfiguration. What makes this one notable is the use of Claude Opus 5 to automate ARM64 exploit generation, which gave them access to internal GitHub, Slack, and email. We covered a related OpenAI incident on the 14th involving agents and RubyGems — this adds useful context to that earlier story.
Revenue Protect reported the first arrest in Singapore for SMS blaster scamming — a Malaysian man working for loan shark groups sent over ten thousand smishing messages targeting WhatsApp credentials, which were then used for authorised push payment fraud. At least one victim lost eighteen hundred Singapore dollars. Flag this if you're tracking fraud trends in Southeast Asia.
iProov released an experimental draft specification called HAPS — Human Approval and Presence Specification — designed to cryptographically bind human presence and explicit approval to machine-readable actions. It's strictly non-production at this stage, but adds useful context if you're working on high-assurance user confirmation systems or following developments in authentication frameworks.
And finally, Joshua Wright introduced the Dynamic Approach to Incident Response, or DAIR — an iterative framework intended to replace linear models like PICERL and the NIST guidance. The premise is that modern incidents don't stay in neat boxes, so response processes shouldn't either. Worth a read if you're looking at how your team handles persistent threats or incomplete eradication.
That's your briefing for today. All articles are credited to their original authors — the analysis here was automated. We'll be back with the next round soon.