Allowlisting takes center stage; 24-hour vulnerability reporting deadline begins. ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
Zero Trust Weekly

This week in Zero Trust

Governments put prevention and visibility in focus

Estimated reading time: 4–5 minutes

 

In this issue:

  • Why the NSA recommends allowlisting
  • EU Cyber Resilience Act 24-hour reporting begins today
  • Why you shouldn't implicitly trust child processes
  • Threats: Stolen AI sessions and another Chrome zero-day
View in browser

Manage preferences

From the CEO

153 million U.S. and Canadian stolen driver's license images

 

"There are countless uses for this data, including spearphishing and identity theft, but one that businesses should be on the lookout for is fake remote employees using stolen identification. We all know the stories about North Korean IT workers, and those cases have already shown how stolen and forged IDs can be used to trick HR departments." - Danny Jenkins

From the ThreatLocker blog

 

NSA says blocklisting isn't enough for AI-enhanced threats

Latest best practices focus heavily on prevention

 

The NSA's latest cyber hygiene guidance highlights weak authentication, unpatched systems, and misconfigurations among the most persistent issues attackers exploit, while recommending strict application allowlisting as a key Zero Trust control. 

 

With attacks moving at machine speed, prevention becomes increasingly important.

How to implement allowlisting without friction

24-hour vulnerability reporting begins Sept. 11

New deadline applies to manufacturers covered by EU Cyber Resilience Act

 

New EU Cyber Resilience Act requirements go into effect today, requiring manufacturers to report actively exploited vulnerabilities and severe incidents within 24 hours of discovery. A 24-hour reporting deadline leaves little time for discovery. Organizations need visibility into vulnerabilities and exploitation before the reporting clock becomes a problem.

How the CRA reporting clock works

Control the chain, not just the starting point

Stop trusted software from launching untrusted activity

 

A trusted application can still take untrusted actions with the wrong permissions in place. Controlling what applications are permitted to launch can stop an attack chain even when the parent application itself is legitimate.

High-risk parent-child relationships to watch
Zero Trust World 2027, Orlando, FL: Prevention is the cure. Join the year's premier Zero Trust event | Register now

Threats you need to know

 

Attackers hijack AI accounts through infostealer logs

Stolen session tokens can bypass MFA

  • What's happening: Researchers analyzed an infostealer dump from nearly 6,000 infected machines and found thousands of unexpired authentication tokens and valid API keys tied to AI and cloud services.  

  • What defenders need to know: Don't stop at authentication. Treat session tokens and API keys like credentials by limiting their lifespan and privileges and limit what an authenticated session can access in the first place.

Chrome zero-day actively exploited in the wild

V8 flaw enables code execution through malicious webpage

  • What's happening: Google patched CVE-2026-87491, an actively exploited Chrome V8 vulnerability that could allow attackers to execute code through a malicious webpage. It's the seventh actively exploited Chrome zero-day Google has addressed this year. 

  • What defenders need to know: Patch Chrome and other Chromium-based browsers, but don't stop there. Limiting browser privileges and controlling what processes browsers can launch can help contain an attack when the next zero-day arrives.

Next webinar

ThreatLocker CEO Danny Jenkins (right) and CPO Rob Allen

Debunking the cybersecurity myths that leave you exposed

Tuesday, Sept. 29 | 11 a.m. EDT

 

ThreatLocker CEO Danny Jenkins and CPO Rob Allen will demonstrate real attack techniques and practical defense strategies to examine the assumptions many security teams rely on and the gaps they're creating for attackers to exploit. 

Sign up now

Meet ThreatLocker near you next week

 

Australia | Dubai | London | Dublin | Philadelphia | Dallas | Nashville

See all upcoming events
ThreatLocker: Zero Trust Platform | Zero Trust Weekly

ThreatLocker, 1901 Summit Tower Blvd, Orlando, Florida 32810, United States

Manage preferences

Connect with us

                             

©2026 ThreatLocker Inc., All Rights Reserved