Monthly Archives: September 2026

This US Green Card Category Could Slam Shut in the Next Two Weeks

The State Department’s September 2026 Visa Bulletin warns of a possible green card category retrogression. It could hit several employment-based categories before the fiscal year closes on September 30. EB-1 India, EB-2 for all countries, and the EB-5 Unreserved category are all named. The trigger is simple. Demand keeps pace with how many visa numbers remain available.

Why a Green Card Category Retrogression Happens Every September

Congress caps the number of employment-based green cards issued each fiscal year. The State Department allocates those numbers on a rolling basis through the Visa Bulletin. A category’s usage can near its annual limit before the fiscal year ends. When that happens, the department has two options. It can retrogress the final action date, pushing it backward so fewer applicants qualify. Or it can make the category fully unavailable until the new fiscal year opens on October 1. This is an annual bottleneck, not a new policy change. It recurs whenever demand in a category runs ahead of supply late in the fiscal cycle.

Which Categories Are Actually at Risk This Year

green card category retrogression

Immigration firms including Fragomen have summarized the September bulletin’s warnings. EB-1 India’s final action date currently sits at October 15, 2022. High demand could still exhaust that category’s annual allocation before new numbers open in FY2027. EB-2 for all countries has already been marked “Unavailable” for the rest of FY2026. EB-5 Unreserved faces a similar risk. The State Department says demand and usage there could force a retrogression or closure before September 30. The goal is keeping total number use within the fiscal year’s cap.

What Retrogression Actually Means for an Applicant

If a category retrogresses or becomes unavailable, USCIS generally cannot approve new applications in it. That holds until the next fiscal year begins. It also holds even if an applicant’s priority date was previously current. Applicants who already filed shouldn’t need to refile once new numbers open on October 1. Still, they may see a real gap of days or weeks with no further approvals in that category. Fragomen’s guidance notes something reassuring here. USCIS has said it will keep honoring final action dates that were current when a case was filed. That softens some of the risk for applicants already in the pipeline.

How This Differs From the October Bulletin’s Good News

This warning about near-term retrogression tells a different story. Tamara News covered a more optimistic outlook for the October 2026 bulletin separately. That bulletin could reopen EB-2 India and advance other stalled categories once the new fiscal year begins. Both things can be true at once. A category can face retrogression risk in late September. It can still see meaningful forward movement starting October 1. The annual limits simply reset with the new fiscal year.

Why Fiscal Year-End Timing Catches People Off Guard

Applicants who checked their category’s status earlier in the summer sometimes assume it holds steady until the next bulletin. It often doesn’t. Category movement can shift week to week in September specifically. That is when USCIS and the State Department reconcile actual number use against the annual cap for the first time all year. Attorneys describe the final weeks of the fiscal year as the least predictable stretch on the entire visa calendar. That is exactly why guidance can change with little advance notice.

Who This Warning Doesn’t Affect

Family-based green card categories operate under a separate set of annual limits and aren’t named in this particular warning. Neither are most other employment-based categories outside EB-1 India, EB-2, and EB-5 Unreserved, which have their own final action dates and haven’t shown the same usage pressure this fiscal year. That’s a separate question from the public charge rule taking effect September 18, which affects admissibility rather than annual visa limits. Applicants in unaffected categories should still track the monthly bulletin as a matter of routine, but the September 30 deadline pressure described here applies specifically to the three categories named above.

What Applicants Should Do Before September 30

Immigration attorneys generally advise one thing to applicants with pending cases in EB-1 India, EB-2 or EB-5 Unreserved: confirm case status with counsel now. Waiting for a possible retrogression announcement carries real risk. USCIS processing timelines mean action taken in the final two weeks of September matters more than usual. Applicants should also watch for the October 2026 Visa Bulletin’s publication. It’s expected in the second half of September, and it will confirm whether any at-risk categories actually retrogressed or held steady.

Frequently Asked Questions

What is a green card category retrogression?
It’s when the State Department moves a visa category’s final action date backward, or makes it unavailable. This happens when usage nears the fiscal year’s annual limit.

Which green card categories are at risk before September 30, 2026?
EB-1 India, EB-2 for all countries, and EB-5 Unreserved are the categories the State Department flagged as at risk.

Will I have to refile my application if my category retrogresses?
Generally no. USCIS has said it will keep honoring final action dates that were current when a case was filed. New approvals may still pause until the next fiscal year.

Does this affect the October 2026 Visa Bulletin outlook?
No, they’re separate. A category can face retrogression risk in late September and still move forward once new fiscal year numbers open on October 1.

When does the new fiscal year’s visa allocation begin?
October 1, 2026. Fresh annual numbers become available then for every employment-based category.

Sources

  • Fragomen — United States: September 2026 Visa Bulletin analysis. fragomen.com
  • US Department of State — Visa Bulletin for September 2026. travel.state.gov

Revolut Data Breach Began With a Real Government Email Domain

Revolut has confirmed a Revolut data breach in which an unauthorised third party obtained customer data by sending fraudulent information requests from a legitimate government agency email domain. The fintech says a limited number of customers were affected and that funds are safe. The method is what makes this one worth reading closely: nothing was hacked in the conventional sense. The attacker used a real government domain and the legal process that obliges companies to answer it.

What Revolut has confirmed

According to TechCrunch, which reported the confirmation on 12 September, Revolut described the incident as a sophisticated external impersonation in which a third party used a genuine government agency domain to submit fraudulent requests for customer information. Bloomberg reported the company’s statement the same day.

Revolut says it blocked the address once it identified the scheme and notified the relevant government agency, financial regulators, law enforcement and data-protection authorities. The company’s characterisation of the scale — a limited number of customers — is its own, and has not been independently quantified.

What was exposed, and what was not

The exposed material, per the company’s disclosure and subsequent reporting, includes identity and contact details: date of birth, postal and email addresses and phone numbers. It also includes copies of identity documents such as passports and driving licences, and may include verification selfies, account statements and transaction histories.

Revolut says passwords and full payment card details were not accessed, and that customer funds are safe.

That split matters, and not in the reassuring direction most breach notices imply. Passwords can be changed. A passport scan paired with a verification selfie, a date of birth and an address cannot be. That combination is precisely the bundle used to pass remote identity checks at banks, crypto exchanges, mobile carriers and government portals. Help Net Security’s summary sets out what is known so far.

Why fake law-enforcement requests work

Financial firms and online platforms receive a steady stream of lawful requests for customer data from police, regulators and prosecutors. A subset are marked urgent, on the basis that a delay could cost a life or let a suspect flee. Companies are expected to respond quickly, and the main authenticity signal available to a reviewer is that the request arrived from an official government email domain.

That is a weak signal. Government mailboxes are compromised regularly, through phishing, credential stuffing or reused passwords, and a compromised mailbox grants exactly the one thing the fraud needs. The request itself can be well-drafted; the domain does the vouching.

The defence is procedural rather than technical: out-of-band verification by calling the agency back on a published number, mandatory secondary approval for identity-document disclosure, rate limiting on any single requester, and treating an urgent flag as a reason for more scrutiny rather than less. None of that is exotic. It is slow, which is why it erodes under volume.

What affected customers should do

If you receive a notification from Revolut, the useful steps are narrow and specific:

  • Assume identity-theft risk, not account-takeover risk. Passwords were not taken; your documents may have been. The threat is someone opening accounts as you elsewhere.
  • Place a credit freeze or fraud alert with the credit bureaus in your country. This is the single highest-value action and it is usually free.
  • Expect targeted phishing. An attacker holding your date of birth, address and transaction history can write a far more convincing message than the usual spam. Treat any inbound contact about the breach as suspect and use the app, not a link.
  • Enable a passkey or hardware key if your accounts support it, and review devices authorised on the Revolut app.
  • Note the date. If you later dispute a fraudulent account opened in your name, being able to point to a documented breach and notification date is useful.

For regulators, the open question is whether the disclosure meets the notification standards of the jurisdictions Revolut operates in, and whether the agency whose domain was abused will say anything about how it was compromised. That second answer is the one that would help every other company facing the same request queue.

Frequently asked

What happened in the Revolut data breach?

An unauthorised third party used a legitimate government agency email domain to send fraudulent requests for customer information, and Revolut supplied data in response before identifying the scheme.

What data was exposed?

Identity and contact details including date of birth, postal and email addresses and phone numbers, plus copies of identity documents such as passports and driving licences. It may also include verification selfies, account statements and transaction histories.

Were passwords or card details taken?

Revolut says no passwords and no full payment card details were accessed, and that customer funds are safe.

How many customers were affected?

Revolut has described it as a limited number. The company has not published a figure, and the scale has not been independently verified.

What is an emergency data request scam?

A fraud in which an attacker sends a company an urgent-looking law-enforcement request from a compromised or spoofed official email account, relying on the company’s obligation to respond quickly to lawful requests.

What should I do if I am affected?

Freeze your credit file or place a fraud alert, expect targeted phishing, strengthen authentication on your accounts, and keep a record of the notification date.

More security coverage

Heathrow, Gatwick and Manchester Just Told Passengers: Check Before You Leave

Major UK airports issued an urgent UK airport travel disruption notice on September 14, 2026. London Heathrow, Gatwick and Manchester all warned travelers to verify flight status before heading to the terminal. Operational recovery efforts continue across the country’s airspace.

What’s Behind This UK Airport Travel Disruption

The advisory covers the country’s three busiest aviation gateways at once. That scale typically points to an airspace-wide capacity or weather issue. It’s not a problem isolated to one terminal or airline. UK airports have already faced a difficult stretch this month. A runway closure at Gatwick recently triggered one of the airport’s worst evenings of the year. It delayed roughly 90% of flights, with average waits of 71 minutes. Early September also brought a wave of US-bound delays and cancellations. Labor Day travel volumes and separate weather systems both contributed.

This Follows a Rough Few Weeks for European Airports

UK airport travel disruption

UK airports aren’t operating in isolation here. Tamara News previously covered how a single bad day in Berlin rippled across a dozen European airports. That story showed how quickly one hub’s problem can cascade through connecting itineraries continent-wide. The September 14 advisory suggests UK airports are trying to get ahead of a similar cascade risk. They are warning passengers early, rather than waiting for delays to compound before communicating.

What Passengers Should Actually Do

Airlines and airports are directing travelers to check their specific flight’s status directly with the operating carrier. Do this before leaving for the airport. General advisories alone aren’t enough to plan around. UK261 passenger rights rules still apply during weather- or air-traffic-linked disruption in many circumstances. That means affected travelers may be entitled to rebooking, refunds or compensation. It depends on the cause and length of delay. Airlines can still decline compensation claims tied to extraordinary circumstances, such as severe weather.

How This Compares to Recent US Flight Disruption

The UK advisory lands just over a week after nearly 1,700 US flights were delayed in a single day. That’s part of a broader pattern of early-September disruption on both sides of the Atlantic. Aviation analysts point to a mix of causes straining major hubs this particular September: congestion, weather, and schedule limits. No single cause explains every incident. Together, that pattern makes this month look more turbulent for air travel than usual. That’s true even before counting the UK’s specific runway and airspace issues.

What Frequent Flyers Are Doing Differently This Month

Business travelers with tight connections through Heathrow or Gatwick have changed their habits this month. Many are now building in extra buffer time between flights, according to travel advisors quoted in UK coverage of the disruption. Some are shifting to earlier departure slots too. That helps them avoid the afternoon congestion windows that have produced the longest delays. Airlines have also expanded same-day rebooking options at some UK hubs. That lets affected passengers move to a later flight without paying a change fee during active disruption periods.

What Airlines Are Telling Passengers Directly

Several carriers operating out of the three hubs have pushed direct notifications to affected travelers through their apps, rather than relying on passengers to check airport-wide advisories alone. That shift reflects lessons learned from the Berlin disruption, where delayed communication left many travelers finding out about cancellations only after arriving at the terminal. Airlines say the goal this time is giving passengers enough notice to rebook or adjust plans before they leave home. Frequent-flyer forums have also filled with real-time reports from travelers at all three airports, which airlines and journalists alike have used to spot developing problems faster than official channels sometimes manage.

What to Watch as Recovery Efforts Continue

Airports have not given a firm timeline for when normal operations will resume across all three hubs. Passengers with near-term travel through Heathrow, Gatwick or Manchester should plan carefully. Treat the next 24 to 48 hours as the most likely window for continued knock-on delays. Recovery from a multi-airport disruption typically takes longer than a single bad day. Clearing connecting aircraft and crew schedules back into position simply takes time. Anyone flying long-haul into or out of the three hubs this week should build extra time into ground transport plans too, since knock-on delays tend to hit connecting rail and coach services around major airports as well. Passengers connecting through a fourth UK airport, such as Stansted or Luton, should still check status directly, since disruption at one hub can spill over onto shared airspace corridors.

Frequently Asked Questions

Which UK airports issued the disruption advisory?
Heathrow, Gatwick and Manchester all issued advisories on September 14, 2026. They warned passengers to verify flight status before traveling to the terminal.

What caused this round of UK airport travel disruption?
The advisory follows a recent Gatwick runway closure and broader operational recovery efforts. Airports haven’t attributed the September 14 notice to one specific cause.

Am I entitled to compensation if my flight is delayed?
UK261 rules can entitle passengers to rebooking, refunds or compensation. It depends on the cause and length of delay, and airlines can decline claims tied to severe weather.

Is this connected to recent US flight delays?
Not directly. But it follows a similar pattern of early-September disruption in the US, where nearly 1,700 flights were delayed in a single day.

How long will the disruption last?
Airports haven’t given a firm timeline. Multi-airport disruptions typically take longer than a single day to fully clear from connecting schedules.

Sources

  • NomadLawyer — UK Airport Disruption Advisory: Heathrow Delays, UK261 Compensation Rights. nomadlawyer.org

Cox Spectrum Rebrand Reaches Customers in Mid-September

The Cox Spectrum rebrand arrives in customers’ homes this month. Charter Communications completed its acquisition of Cox Communications on 20 August 2026, alongside a separate merger with Liberty Broadband, in a transaction valued at $34.5bn. The paperwork closed in August; the part customers notice — Spectrum branding, Spectrum pricing and Spectrum packaging replacing Cox’s — begins rolling into former Cox markets from mid-September.

What closed in August

Charter described the combined business as the leading broadband and video company in the United States, serving 37 million customers across 45 states. That figure is the company’s own, published in its completion announcement, and it counts customer relationships rather than individual services.

Two transactions closed together: the Cox acquisition and a merger with Liberty Broadband, the holding vehicle that had a large stake in Charter. Collapsing that structure simplifies the ownership chain at the same time as the operating footprint expands. Charter also filed the relevant disclosure with the SEC; the 8-K exhibit is the primary document.

The part customers see this month

For households in former Cox territories — Las Vegas, Phoenix, San Diego, Hampton Roads, Omaha, New Orleans and others — the change is a rebrand plus a repricing. Charter is moving its Spectrum products, pricing and packaging into those markets, which means the shape of the bill changes even where the underlying connection does not.

Charter has also said it will give former Cox internet customers who are not already on Cox Mobile a free year of mobile service. That is a company promotion with the usual purpose: convert broadband-only households into bundled ones, which are materially harder to churn. Treat it as a customer-acquisition offer rather than a windfall, and read the terms for what happens in month thirteen.

What does not change immediately: the physical network. The cable plant, the node splits and the fibre in the ground are the same assets they were in July. Service quality in a given neighbourhood is a function of that plant, not of the logo on the router.

The naming arrangement, which is genuinely odd

Within a year of closing, the parent company is due to take the Cox Communications name while continuing to operate its services under the Spectrum brand everywhere. So the acquirer adopts the target’s corporate identity and the target’s customers adopt the acquirer’s consumer brand. Variety covered the arrangement at closing.

The logic is family ownership. Cox is a long-held private family business, and preserving the name is the kind of term that gets negotiated into a deal of this size. For customers it is a distinction without a difference: the entity on the corporate filings will say Cox; the app, the bill and the truck will say Spectrum.

What a bigger cable company means for prices

Cable consolidation in the US has generally been approved on the argument that cable operators no longer compete against each other — their footprints do not overlap — so combining them does not reduce choice in any given street. That argument is technically sound and practically incomplete. Scale changes negotiating power with programmers, purchasing power for equipment, and the operator’s ability to fund fibre upgrades and mobile subsidies.

The competitive pressure that actually disciplines prices for most US households now comes from elsewhere: fibre overbuilders and fixed-wireless broadband sold by mobile carriers, which has taken meaningful share from cable over the past few years. A larger Charter is better placed to respond to that pressure — the free-mobile offer is exactly such a response — but it does not remove it.

What to watch: whether Spectrum pricing in former Cox markets lands above or below what those customers were paying, and how quickly promotional rates step up. Those two numbers will tell the story better than any merger statement.

Customer questions

Is Cox now Spectrum?

Yes for consumer-facing purposes. Charter completed the acquisition on 20 August 2026 and is rolling Spectrum branding, pricing and packaging into former Cox markets from mid-September.

How big was the deal?

$34.5bn, completed alongside a separate merger with Liberty Broadband.

How many customers does the combined company have?

Charter says 37 million customers across 45 states. That is the company’s own figure.

Will my equipment or connection change?

The physical network does not change with a rebrand. Equipment swaps happen over time as Spectrum standardises hardware, but the cable plant serving an address is the same.

What is the free mobile offer?

Charter has said former Cox internet customers not already subscribing to Cox Mobile are eligible for a free year of mobile service. It is a promotional offer; check the terms for what applies after twelve months.

Why will the parent company be called Cox?

Under the deal terms the parent adopts the Cox Communications name within a year while services continue to operate as Spectrum.

Continue with these

A Bug Rated 9.3 Out of 10 Could Let an Attacker Escape Your Virtual Machine

Broadcom patched a critical VMware Workstation Fusion flaw on September 3, 2026. It fixed an integer-overflow bug tracked as CVE-2026-59346, carrying a CVSS severity score of 9.3 out of 10. The bug could let an attacker with elevated privileges inside a virtual machine run code on the host computer itself.

How the VMware Workstation Fusion Flaw Actually Works

Security researchers call this a VM-escape vulnerability. That means malicious code can break out of the isolated virtual machine it’s running in and execute on the underlying host operating system. According to SecurityWeek’s report on the advisory, the bug is an integer-overflow issue. A specially crafted input can cause a calculation to wrap around and corrupt memory. That corruption gives an attacker code execution rights. Broadcom’s advisory, published as VMSA-2026-0007, credits the discovery to researchers who reported it through coordinated disclosure. It was not found after active exploitation.

Who Needs to Patch, and How Urgently

VMware Workstation Fusion flaw

The flaw affects VMware Workstation and Fusion versions 25H2 and 26H1. Those are the desktop virtualization products widely used by developers, IT administrators and security researchers to run guest operating systems on Mac and Windows machines. Broadcom’s fix arrived in version 26H1u1. The vulnerability requires an attacker to already have elevated privileges inside a guest VM, so it’s not remotely exploitable from the open internet on its own. That’s a modest comfort at best. Anyone who runs untrusted code, malware samples, or third-party software inside a VM often does so precisely because they assumed the host was safely isolated.

Why a 9.3 Severity Score Is Rare

CVSS reserves scores above 9.0 for flaws combining high-impact consequences with low exploit complexity. A VM-escape bug earns that rating for a simple reason. Virtualization’s entire security premise holds that whatever happens inside the VM stays inside the VM. That premise collapses completely once someone exploits the flaw. Security researchers who use VMs specifically to safely analyze malware, or test suspicious code, carry the most direct exposure here. That’s exactly the scenario the isolation boundary exists to protect against.

This Follows a Pattern of September Disclosures

The VMware patch arrived in the same week as other significant disclosures. Attackers started actively exploiting an unpatched Magento and Adobe Commerce zero-day on September 4, using it to backdoor online stores. Separately, attackers breached JetBrains’ Cadence product through an unpatched TeamCity vulnerability. Taken together, this run of disclosures reflects a busy patch cycle across enterprise software this month. It isn’t one vendor’s isolated problem — the same week saw Google patch its seventh emergency Chrome bug of the year, and Berlin’s city government confirm a ransomware breach that leaked 5.8 terabytes of files.

What Makes VM-Escape Bugs Different From Ordinary Malware Risk

Most software vulnerabilities threaten only the system they’re found on. A VM-escape flaw works differently, because it defeats a security boundary that other tools depend on. Sandboxed malware analysis, isolated test environments, and even some cloud hosting setups all lean on one assumption: a VM can’t reach its host. When that assumption fails, every control built on top of it needs a fresh check too, not just the VM software itself.

How This Compares to Past VMware Security Incidents

VMware products have faced serious vulnerabilities before, including several VM-escape bugs disclosed in prior years that prompted similar emergency patching cycles. What sets this one apart is the severity score. A 9.3 rating places CVE-2026-59346 among the more dangerous flaws Broadcom has disclosed for its desktop virtualization line specifically, as opposed to its enterprise server products, which see a higher volume of security research attention overall. Broadcom’s acquisition of VMware in 2023 also changed how these advisories get published, consolidating disclosures under the company’s broader security bulletin process rather than VMware’s older, standalone system.

What IT Teams Should Do Next

Broadcom’s guidance is straightforward. Teams should upgrade affected Workstation and Fusion installations to version 26H1u1 as soon as operationally possible. Prioritize machines that run untrusted or unverified code first. Organizations that rely on VM isolation as a security control for malware analysis or sandboxed testing should treat this patch as time-sensitive. It is not routine maintenance, given how directly the flaw undermines that isolation assumption. Security teams that maintain a patch-management dashboard should flag this advisory for cross-checking against every desktop image still running the older builds, not just servers. IT administrators managing shared lab machines, where multiple researchers rotate through the same physical hardware, face the highest practical exposure and should treat this update as a same-week priority rather than folding it into a routine monthly patch cycle.

Frequently Asked Questions

What is CVE-2026-59346?
It’s a critical integer-overflow vulnerability in VMware Workstation and Fusion that can let an attacker escape a virtual machine and run code on the host computer.

How severe is this VMware Workstation Fusion flaw?
It carries a CVSS score of 9.3 out of 10, reflecting both high potential impact and relatively low exploitation complexity once an attacker has elevated access inside a VM.

Which product versions does this flaw affect?
It affects VMware Workstation and Fusion versions 25H2 and 26H1. Broadcom’s fix arrives in version 26H1u1.

Is this exploitable remotely over the internet?
Not directly. An attacker needs elevated privileges inside a guest virtual machine first. That’s still a realistic scenario for anyone running untrusted code in a VM.

Did anyone exploit this flaw before the patch came out?
Available reporting indicates researchers disclosed it through a coordinated process, not after active exploitation. Even so, organizations should patch promptly.

Sources

  • SecurityWeek — VMware Workstation and Fusion Updates Patch Critical Vulnerability. securityweek.com
  • Security Affairs — Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities. securityaffairs.com