identity verification

AppWizard
September 11, 2026
The Cybersecurity and Infrastructure Security Agency (CISA) warned of a critical vulnerability in NetScaler, identified as CVE-2026-19490, with a CVSS score of 9.3, which has been exploited and affects all NetScaler ADC and Gateway appliances. Citrix has patched this vulnerability as of August 19. AdaptHealth reported a data breach affecting over 4.1 million individuals, compromising personal, health, and insurance information, but not Social Security numbers or financial data. A new strain of Android malware, MantaxOtax, attributed to Indonesian threat actors, combines ransomware and spyware, stealing sensitive information and affecting older Android versions. The Gigabud banking trojan has evolved to evade detection by installing a secondary app that hides the malicious application. CISA acting director Nick Andersen emphasized the need for swift adaptation to cybersecurity threats and highlighted staffing improvements within CISA. Russian e-commerce giant Wildberries experienced disruptions from a DDoS attack affecting payments to sellers, following claims of a cyber operation by Ukraine's military intelligence. McKesson faced a cyberattack exposing sensitive data of 6.4 million individuals, with the ShinyHunters group releasing this data after a failed extortion attempt. IDScan confirmed a data breach affecting 150 million individuals, resulting in the theft of personally identifiable information and government-issued documents.
Winsage
September 9, 2026
The September 2026 security cycle revealed a bifurcated approach to vulnerability management by Microsoft, focusing on cloud-side identity services with silent mitigations and traditional Patch Tuesday updates for on-premises Windows infrastructure. On September 3, Microsoft addressed nine cloud-side vulnerabilities, including two with a CVSS score of 10.0: CVE-2026-83711 (Azure AD B2C elevation of privilege) and CVE-2026-70352 (Azure AI Language Authoring missing authentication). Additionally, CVE-2026-83941 (Entra ID elevation of privilege, rated 9.9) and CVE-2026-80098 (Copilot Studio cryptographic flaw) were noted. On September 8, the Patch Tuesday update addressed 70 CVEs, including critical issues in the on-premises stack, such as CVE-2026-83939 (Windows Secure Kernel Mode elevation of privilege). CVE-2026-69414 (ShieldBreak), an elevation of privilege vulnerability in the Defender Malware Protection Engine, was patched out-of-band on September 3 after being publicly exposed for three weeks. Microsoft is shifting its Self-Service Password Reset (SSPR) enforcement to default to passkeys as of September 7, with plans to phase out SMS and voice-based authentication by February 2027. This aims to enhance security by moving away from legacy credentials.
AppWizard
September 8, 2026
Ohio residents with Android devices can now integrate their driver's license or state ID into Google Wallet as part of the state's Mobile ID program. This digital credential is a companion to the physical card, and users are encouraged to carry their plastic IDs. To add the credential, users can navigate through the Google Wallet app. The digital ID is accepted for age and identity verification at various businesses, state buildings, TSA checkpoints, and casinos in Ohio. It utilizes specialized readers for presentation and allows users to review shared data. The credentials are encrypted and can be remotely erased if the phone is lost or stolen. Participation in the program is voluntary and free, adhering to privacy and security standards. Governor Mike DeWine highlighted the convenience of this innovation, and vendors are expanding support for mobile driver’s licenses in multiple states.
Winsage
September 4, 2026
Microsoft is introducing Windows Age APIs to improve age verification in applications by categorizing users into age groups and indicating whether their age has been independently verified. This initiative responds to increasing regulatory demands for stricter age verification laws in the US, UK, and EU. The APIs allow apps to ask users about their age group and verification status without accessing actual birth dates, enhancing privacy. However, only authorized applications can utilize these APIs after being assessed by Microsoft's Digital Safety platform. The Windows Age APIs are documented in the Windows SDK but are not yet active in Windows 11, with an expected rollout before the end of 2026.
AppWizard
August 21, 2026
Google has introduced a new app installation framework called "Advanced Flow," which allows sideloading of apps on Android devices but requires developers to complete real-name verification. Applications signed by unverified developers will be flagged during installation. Users can still sideload apps, but must enable "Developer Options" and acknowledge risks associated with unverified software. A 24-hour waiting period is imposed after enabling Developer Options, with options for permanent or temporary toggling. Google plans to enforce these developer verification requirements starting September 30 in Brazil, Indonesia, Singapore, and Thailand, with a global rollout expected by 2027. ADB installations are not subject to these restrictions.
Tech Optimizer
August 12, 2026
Databricks has acquired Electric, a company known for its contributions to the Postgres ecosystem, including PGlite, a compact version of Postgres for WebAssembly environments. This acquisition includes a real-time synchronization engine that keeps local data copies consistent with a central cloud database. Electric's team will join Neon, a serverless Postgres company previously acquired by Databricks. The integration aims to enhance Lakebase, Databricks' managed Postgres offering, by using PGlite for local data management. PGlite's weekly downloads surged from approximately 1 million to 13 million over the past year, indicating growing developer interest in embedded database models. The acquisition reflects a shift towards decentralized data management for AI agents, with synchronization mechanisms becoming crucial. Databricks is reinforcing its investment in Neon, signaling a deeper relevance of its Postgres offerings. The increase in PGlite downloads suggests early developer interest in local-first database architectures, though widespread production adoption remains uncertain. The emergence of state, identity, payments, isolation, and sync as infrastructure components indicates a competitive landscape for the agent runtime layer, with Databricks strategically positioned in this race.
AppWizard
August 4, 2026
Google will require mandatory identity verification for all developers creating applications for the Android platform, affecting those from countries under U.S. sanctions, such as Russia, Iran, Cuba, and North Korea, who will be excluded from the verification system and may not distribute their apps internationally. The new regulations apply to developers of apps for Android 7 and later versions.
Search