← All briefings
The Exchange Weekly: week ending Friday, September 25, 2026
The Exchange Weekly: week ending Friday, September 25, 2026

Patch clocks hit zero, AI phishing gets disrupted, and states take charge

The Information Exchange weekly wrap for September 25, 2026: CISA deadlines come due on F5 while WSO2 and Adobe Commerce join the list, Microsoft previews the Integrated SOC and takes down an AI phishing machine, an Arkansas city confirms a police-systems breach, the FBI probes claims around its jobs portal, and the state AI governance wave keeps building.

Who this is for

Public-sector CIOs, CISOs, and enterprise IT leaders who need the week's verified developments with clear actions, not noise.

5 things this week

  1. CISA KEV: F5 BIG-IP APM patch due September 25; WSO2 and Adobe Commerce/Magento added September 24.
  2. Microsoft previews Integrated SOC in Defender and disrupts the EvilTokens AI phishing operation.
  3. Fort Smith, Arkansas confirms police-systems data theft; finance and HR untouched; no ransom paid.
  4. FBI investigates claims around FBIjobs.gov; portal reported offline during the probe.
  5. Oregon EO 26-26 starts a 90-day AI safety clock; Digital States 2026 keeps cybersecurity at No. 1.

1. CISA KEV clocks: F5 due today, WSO2 and Adobe Commerce added

CISA KEV clocks
CISA KEV clocks

Federal patch clocks first, and one of them hits zero today. CISA's Known Exploited Vulnerabilities catalog listed CVE-2026-94127 in F5 BIG-IP APM with remediation due September 25 under Binding Operational Directive 26-04, the directive that requires federal agencies to fix cataloged flaws by CISA's deadlines. Then on September 24, CISA added CVE-2026-5430 affecting WSO2 products and CVE-2026-71362 affecting Adobe Commerce and Magento. Reporting cites a September 27 fix target for the new additions; that date comes from reporting, not the CISA alert page itself.

The common thread is internet-facing infrastructure: F5 BIG-IP often sits in front of federal applications as an access gateway, WSO2 middleware connects enterprise systems, and Adobe Commerce powers storefronts that process payment data. Attackers scan for all three within hours of disclosure.

Inventory internet-facing instances, patch, then check for compromise before calling a host clean.

Why it matters

KEV-listed flaws are being actively exploited in the wild, and BOD 26-04 makes remediation mandatory on a clock for federal agencies while setting the pace for everyone else. Roles most impacted: federal agency CISOs and CIOs, SOC analysts, and system owners running F5, WSO2, or Magento estates.

What to do

Roles necessary to act: vulnerability management lead, network and system owners, SOC analysts.

Action plan, from the CISO's perspective: (1) Pull your asset inventory today for internet-facing F5 BIG-IP APM, WSO2, and Adobe Commerce/Magento instances. (2) Patch F5 immediately; the due date is September 25. Schedule WSO2 and Adobe Commerce remediation against the reported September 27 target. (3) Hunt for indicators of compromise on each host before closing the ticket. (4) Report remediation status up the chain the same day.

2. Microsoft: Integrated SOC preview and the EvilTokens takedown

Microsoft Integrated SOC + EvilTokens
Microsoft Integrated SOC + EvilTokens

On September 23, Microsoft previewed Integrated SOC in Microsoft Defender, bringing SIEM and threat protection together so human analysts and AI agents work from one shared foundation instead of swiveling between consoles. For enterprise SOC teams, the pitch is fewer panes of glass and faster handoffs between detection and response.

Separately, Microsoft disrupted EvilTokens, an AI-driven phishing-as-a-service operation linked to more than 12,000 compromised inboxes across over 10,000 organizations. Operations like this industrialize device-code phishing: victims are talked into entering a code that hands the attacker an authenticated session, with no password theft required.

Device-code style access means stolen sessions survive password resets. Revoke sessions and tokens, not just passwords.

Why it matters

SOC consolidation changes tooling strategy and staffing plans, while EvilTokens shows AI is industrializing phishing faster than awareness training can keep up. Roles most impacted: SOC managers and analysts, identity engineers, enterprise CISOs.

What to do

Roles necessary to act: identity team, SOC, security awareness lead.

Action plan, from the SOC manager's perspective: (1) Evaluate the Integrated SOC preview against your consolidation roadmap; fewer consoles only help if the migration is planned. (2) For any suspected compromised account, revoke sessions and tokens first, then reset the password. (3) Move high-risk users to phishing-resistant MFA. (4) Brief the help desk on device-code phishing scripts so social-engineering calls get flagged.

3. Fort Smith, Arkansas confirms police-systems data theft

Fort Smith police-systems breach
Fort Smith police-systems breach

The City of Fort Smith, Arkansas confirmed that an unauthorized party took city data through Police Department systems and released it. Finance, accounting, customer-data, and HR systems were not involved, and no ransom was paid. Claims about the volume of data posted by the Interlock group remain unverified by the city.

Law enforcement systems are a high-value target because they hold criminal histories, active case files, and personal data on residents. The city's statement draws a clear boundary around what was and was not touched, which is exactly what residents and auditors need to hear in the first 72 hours.

Segmentation beats leak-site theater.

Why it matters

This is the municipal breach playbook in action: scope containment decides whether an incident stays a department problem or becomes a citywide crisis. Roles most impacted: city and county CIOs, police department IT, city managers, affected residents.

What to do

Roles necessary to act: city CIO, police IT lead, incident response provider, public communications.

Action plan, from the city CIO's perspective: (1) Confirm and document the scope boundary: which systems were touched and which were not. (2) Isolate affected police systems and engage incident response. (3) Notify under applicable state breach law once facts are firm. (4) Publish a clear what-was and was-not-touched statement early. (5) Do not pay a ransom; it does not guarantee deletion.

4. FBI investigates claims around FBIjobs.gov

FBI FBIjobs.gov probe
FBI FBIjobs.gov probe

The FBI is investigating claims of unauthorized activity affecting FBIjobs.gov, its jobs portal. Claims attributed to ShinyHunters remain unverified; the Bureau has confirmed it is investigating the claims. Reporting indicated the portal was offline while the probe was underway.

A jobs portal is an attractive target because applicants submit exactly the personal data identity thieves want. Until the Bureau closes the loop, treat any FBIjobs.gov outage or unsolicited contact referencing an application with caution, and verify portal status through official FBI channels before submitting personal information.

Verify the portal before you submit personal data.

Why it matters

Applicant PII is at stake, and trust in federal hiring portals affects every agency competing for talent. Roles most impacted: job applicants, FBI HR and IT, federal CISOs watching third-party and portal risk.

What to do

Roles necessary to act: applicants, agency HR IT, security operations.

Action plan, from the applicant's perspective: (1) Do not submit personal data to any jobs portal you cannot verify as official. (2) Reach FBIjobs.gov only through links on fbi.gov. (3) Treat unsolicited emails or calls referencing your application as suspect until verified. (4) If you applied recently, watch for identity-theft indicators and consider a fraud alert.

5. Oregon puts AI on a 90-day clock; Digital States keeps cyber at No. 1

Oregon EO 26-26 + Digital States 2026
Oregon EO 26-26 + Digital States 2026

Oregon Governor Tina Kotek signed Executive Order 26-26, giving State CIO Terrence Woods 90 days to complete third-party AI safety reviews and a frontier AI kill-switch assessment. Read it as a buying gate, not a ban: vendors selling AI into Oregon state government should expect safety review to become part of procurement, and agencies should expect new review steps before deployment.

The kill-switch language is the part to watch. A frontier-model kill switch means the state wants a documented, exercisable way to halt an AI system that behaves dangerously. Every state CIO office is now asking what their own answer would be.

Meanwhile the Digital States 2026 survey still ranks cybersecurity as the number one priority, with about 80 percent of states reporting AI integration in operations. Awards will be presented September 27 at NASCIO in San Diego.

Treat it as a buying gate, not a ban.

Why it matters

State AI governance is moving from principles to procurement requirements, and the Digital States benchmark shapes budget conversations nationwide. Roles most impacted: state CIOs and CISOs, vendors selling AI to government, procurement officers.

What to do

Roles necessary to act: state CIO office, procurement, vendor account teams.

Action plan, from the state CIO's perspective: (1) Stand up a third-party AI safety review process inside the 90-day window; borrow Oregon's framing. (2) Document a kill-switch procedure for frontier AI systems: who can halt a deployment and how. (3) Insert AI safety review into procurement checklists now. (4) Vendors: prepare safety documentation before the RFP asks for it.

6. Also this week

Also this week
Also this week

AWS became the first cloud provider approved for NATO Restricted workloads, a milestone for allied defense IT that opens the door for member nations to run NATO Restricted workloads on commercial cloud. Expect competitors to chase the same authorization.

And Nebraska is planning a statewide cyber ISAC, an Information Sharing and Analysis Center where state agencies, local governments, and critical infrastructure operators trade threat intelligence. It continues the trend of states building their own threat-sharing muscle instead of waiting on federal feeds.

States are building their own threat-sharing muscle.

Why it matters

The AWS authorization sets a precedent allied nations will follow, and state-level ISACs are becoming the practical layer of US threat sharing. Roles most impacted: defense IT leaders, state CISOs, critical infrastructure operators.

What to do

Roles necessary to act: defense cloud architects, state CISO offices.

Action plan, from the state CISO's perspective: (1) Track the AWS NATO Restricted authorization as a procurement precedent. (2) If your state lacks an ISAC, study Nebraska's planning effort and join a regional sharing group in the meantime. (3) Feed state and local IOCs upward; the value of an ISAC is what members contribute.

The week at a glance

The Information Exchange weekly wrap, September 25, 2026 (all stories)
The Information Exchange weekly wrap, September 25, 2026 (all stories)

Keep the conversation going

Was this useful? Get the weekly wrap in your inbox: drop a note to info@MetoraSolutions.com.

Share this with friends and colleagues on LinkedIn.

Follow Metora Solutions on LinkedIn and subscribe to The Information Exchange for the weekly wrap.

If your team is wrestling with any of these issues (patch clocks, SOC consolidation, municipal breach response, state AI governance, or allied cloud authorization) and you want a sounding board or hands-on help, reach out. We take on select projects and advisement work with public-sector and enterprise IT leaders. Drop a note to info@MetoraSolutions.com.

Discussion prompt

Which of this week's stories hits closest to home for your team: the patch clocks, the AI phishing wave, or the state AI governance push? Tell us in the comments.

About The Information Exchange

The Information Exchange delivers verified public-source intelligence for executive decision-makers. All information is from reputable, publicly available sources. Every effort is made to keep details accurate as of publication time, but readers should always confirm time-sensitive items such as policy changes, budget figures, and timelines with official documents and briefings.

The Information Exchange does not constitute legal, investment, procurement, security, compliance, or technical advice. Content is for informational purposes only.

The Information Exchange is a production of Metora Solutions LLC, a HUBZone and Service Disabled Veteran Owned Small Business. All rights reserved. Copyright Metora Solutions LLC 2026.

Because guesswork isn't a strategy.