This website uses cookies

Read our Privacy policy and Terms of use for more information.

Summary: CISA has added CVE-2026-84869, a critical improper privilege management and missing authorization vulnerability in ConnectWise ScreenConnect, to its Known Exploited Vulnerabilities catalog. The flaw allows an attacker with basic privileges to transfer and execute files through an active remote session without authorization or host confirmation. It was patched in ScreenConnect 26.6.5 and later; federal agencies were given three days to remediate. Shadowserver still tracks more than 1,000 exposed unpatched instances.

Key takeaway / Actionable note: Upgrade on-prem servers to 26.6.5 or later, reinstall host clients and access agents, and disable TransferFiles permissions as an interim control if patching is delayed.

Summary: Google’s September 2026 Pixel security bulletin addresses 110 vulnerabilities, including the high-severity Cellular Modem privilege-escalation flaw CVE-2026-58704 (CVSS 8.0). Google stated there are indications the issue “may be under limited, targeted exploitation.” The bug stems from a logic error allowing remote (proximal/adjacent) privilege escalation with no user interaction. Patch level 2026-09-05 or later resolves all listed issues.

Key takeaway / Actionable note: Pixel users should install the September security update immediately via Settings > Security & privacy.

Summary: US, UK and Dutch agencies issued a joint advisory on Chosen Brick (also tracked by the FBI as HEAVYGRAM), a Windows malware family used by Iranian state cyber actors since at least 2025. Operators target dissidents, activists and journalists via WhatsApp and Telegram social engineering, delivering weaponized files disguised as utilities or MRI results. The malware uses per-victim Telegram bots for C2, captures screenshots, audio, emails and chat data, and can deploy secondary payloads or wipe data.

Key takeaway / Actionable note: Monitor for Telegram-based C2, review inbound messages from unknown contacts offering documents, and apply the indicators published by NCSC, FBI and AIVD.

Summary: Acronis disclosed CVE-2026-87886, a high-severity (CVSS 7.8) local privilege-escalation flaw caused by insecure file permissions in its Backup plugin for cPanel & WHM and the Backup extension for Plesk. Exploitation has been observed in limited, targeted attacks against the cPanel plugin. Fixed versions are 1.9.3 HF3 (cPanel) and 1.8.11 (Plesk).

Key takeaway / Actionable note: Hosting providers and admins running the affected plugins should update immediately and hunt for signs of privilege escalation on Linux hosts.

Summary: watchTowr reported active exploitation attempts against CVE-2026-5430, a critical (CVSS up to 10.0) JWT authentication bypass in WSO2 API Manager and related products. Attackers can forge tokens signed with unsupported algorithms to achieve account takeover and access backend APIs, credentials and consumer secrets. The flaw was patched by WSO2 earlier in 2026; honeypots saw forged admin tokens on 13 September.

Key takeaway / Actionable note: Apply the WSO2 updates for API Manager, API Control Plane, Traffic Manager and Universal Gateway without delay and review JWT validation configurations.

Summary: Two critical unauthenticated remote-code-execution chains (CVE-2026-78006 and CVE-2026-78159, both CVSS 9.8) affect The Events Calendar WordPress plugin versions before the fixed releases. The flaws allow code injection or PHP object injection via event comment rendering when comments are enabled. Approximately 200,000–240,000 sites remain on vulnerable versions; the fully patched release is 6.17.4.1.

Key takeaway / Actionable note: Update The Events Calendar to 6.17.4.1 or later immediately and consider disabling comments on event pages until confirmed patched.

Summary: CenterPoint Energy confirmed in an SEC Form 8-K that an unauthorized third party obtained personal information belonging to a portion of its customers through an external-facing system. The disclosure followed a cybercrime-forum claim of roughly 7.49 million records containing names, contact details, account data, driver’s license numbers and partial SSNs. Electric and gas service was not impacted.

Key takeaway / Actionable note: Affected customers should monitor accounts and watch for official notification letters from the utility.

Summary: Oracle’s September 2026 Critical Security Patch Update delivers 673 new security patches addressing more than 800 vulnerabilities across 17 product families, including over 100 critical-severity issues and more than 240 that are remotely exploitable without authentication. E-Business Suite, Fusion Middleware and Hyperion received the largest numbers of fixes.

Key takeaway / Actionable note: Prioritize application of the CSPU patches for exposed Oracle products, especially those with unauthenticated remote vectors.

Summary: Google resolved 42 security defects in Chrome and Mozilla fixed 73 bugs in Firefox in the latest browser updates. The releases close multiple high- and critical-severity issues across both browsers.

Key takeaway / Actionable note: Ensure enterprise and personal browsers are updated to the latest Chrome and Firefox versions.

Summary: Threat actors are actively exploiting a critical unauthenticated file-upload vulnerability in the premium WooCommerce Wholesale Lead Capture WordPress plugin (more than 6,000 active installs) to plant PHP web shells and achieve remote code execution. Wordfence reported blocking numerous exploitation attempts.

Key takeaway / Actionable note: Update or remove the plugin and scan for web shells on any site that has used it.

Also Noted:

Bottom line: The past 24 hours were dominated by active exploitation of remote-access, mobile, API-management and WordPress components, alongside a high-profile utility data breach and a multi-agency nation-state spyware warning. Prioritize ScreenConnect, Pixel, Acronis, WSO2 and The Events Calendar patches today; review external-facing APIs and customer data exposure; and apply the Iranian malware indicators across Windows estates.

Reply

Avatar

or to participate