This website uses cookies

Read our Privacy policy and Terms of use for more information.

Summary: Cisco released patches for CVE-2026-76460, a CVSS 10.0 authentication-bypass vulnerability in an API endpoint of Identity Services Engine (ISE) and ISE Passive Identity Connector. An unauthenticated remote attacker can send a crafted request to bypass the web management interface and gain unauthorized access; successful exploitation can lead to root-level command execution.

Cisco PSIRT confirmed active exploitation in the wild; no workarounds exist. CISA added the flaw to its Known Exploited Vulnerabilities catalog with a three-day federal remediation deadline. Fixed releases include 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4.

Key takeaway / Actionable note: Immediately inventory and patch all ISE/ISE-PIC nodes; review access.log for suspicious usernames and cross-check external firewall/network logs for anomalous traffic, as attackers may erase local evidence after obtaining root.

Summary: Helpfeel disclosed that on 11 September 2026 an attacker exploited a vulnerability in Gyazo’s image-upload server, executed arbitrary commands, and accessed backend systems.

Approximately 23.62 million user records (names/nicknames, email addresses, password hashes, user/device/session IDs, X integration tokens, Google SSO emails, profile and billing-status data) and roughly 490 million image-metadata records (primarily pre-February 2019, including image IDs usable to reconstruct share URLs) were exposed. No payment-card numbers were compromised.

The company blocked access routes and remediated the vulnerability within hours; some image viewing was temporarily disabled as a precaution.

Key takeaway / Actionable note: Gyazo users should rotate passwords and revoke any linked X or Google tokens; treat any pre-2019 image links as potentially compromised.

Summary: Brevo confirmed that attackers obtained a long-lived Cloudflare API key (hard-coded in source code) and used it to deploy a malicious Cloudflare Worker. For approximately 5.5 hours on 14 September the Worker rewrote responses at the CDN edge on brevo.com, sendinblue.com, sibforms.com and related domains, injecting ClickFix lures and modifying embedded Brevo forms, Conversations widgets and SDK loaders used by customers. Sansec estimated impact on up to 100,000 websites.

On WordPress sites the script attempted to install a malicious “Web Media Optimizer” plugin that provided persistence and admin backdoor access. Core Brevo infrastructure and customer account data were not affected.

Key takeaway / Actionable note: Sites embedding Brevo scripts should verify integrity of those assets, check for unexpected plugins installed on 14 September, and rotate any administrator credentials if a logged-in admin visited an affected page that day.

Summary: The FBI seized nightmare-stresser.com and nightmarestresser.org, the primary domains of NightmareStresser, one of the longest-running DDoS-for-hire (“booter”) services. Active since at least 2022, the platform had been used in hundreds of thousands of attacks worldwide and previously advertised capacities up to 200 Gbps. The action forms part of the ongoing international Operation PowerOFF targeting booter and stresser infrastructure.

Key takeaway / Actionable note: Organizations experiencing unexplained volumetric or application-layer DDoS should check whether attack traffic matches known NightmareStresser patterns and update blocklists accordingly.

Summary: Check Point released LivePatch updates addressing CVE-2026-91843, a stack-based buffer overflow in the login process of Security Management Server and Log Server. Unauthenticated attackers can achieve remote code execution with root privileges in low-complexity attacks requiring no user interaction.

All Security Management Server deployments are affected regardless of configuration. Temporary mitigations include restricting management access to trusted IPs via SmartConsole Trusted Clients settings. Detection relies on “Administrator failed to log in: Username too long” audit alerts.

Key takeaway / Actionable note: Apply the LivePatch immediately or enforce IP restrictions and monitor the indicated audit events until the patch can be deployed.

Summary: ESET researchers report that the China-aligned APT group FamousSparrow has been using a previously undocumented modular C++ backdoor named SparroWocky against government organizations in multiple Latin American countries since at least August 2025. The backdoor supports extensive post-exploitation capabilities and continues the group’s long-running espionage focus on the region.

Key takeaway / Actionable note: Latin American government and critical-infrastructure entities should hunt for SparroWocky indicators and review network traffic for the C2 patterns described by ESET.

Summary: U.S. Coast Guard and FBI personnel boarded two oil tankers after evidence of malicious cyber activity was confirmed on at least one vessel (VL Prosperity). The incidents disrupted communications and raised concerns about possible interference with engine-room or navigation systems.

Attribution remains open; Iranian-linked activity has been discussed in media reporting but has not been officially confirmed by the Coast Guard.

Key takeaway / Actionable note: Maritime operators should treat OT/ICS systems on vessels as high-value targets, enforce network segmentation between IT and control networks, and maintain offline backups of critical navigation and propulsion configurations.

Summary: Zimperium researchers detailed RatHat, a new Android trojan distributed via phishing and malvertising. After obtaining Accessibility Service privileges it enables Wireless Debugging, pairs with the device’s own ADB interface, and establishes a reverse proxy. A generative-AI component serializes the Accessibility tree and receives coordinates for automated UI interaction, enabling sophisticated overlay attacks, credential theft and 2FA interception. Persistence mechanisms reinstall the malware and re-grant permissions even after forced removal.

Key takeaway / Actionable note: Mobile users and MDM teams should deny Accessibility permissions to untrusted apps and monitor for unexpected enabling of Developer Options or Wireless Debugging.

Summary: The Internet Systems Consortium published BIND 9.20.29 and 9.21.26 addressing 14 security flaws. One vulnerability allows an unauthenticated sender to crash the named process via a single malformed DNS-over-HTTPS request. Other issues can lead to resource exhaustion, unexpected exits or cache-related problems. No active exploitation has been reported.

Key takeaway / Actionable note: DNS operators should upgrade to the fixed releases promptly, especially any servers answering DoH queries.

Summary: NLnet Labs disclosed CVE-2026-81642, a critical heap overflow in the DNSSEC validator of every Unbound release prior to 1.26.1. An attacker controlling a malicious zone can trigger remote code execution when a vulnerable resolver processes the zone. Version 1.26.1, released the same day as the advisory, resolves the issue.

Key takeaway / Actionable note: Any organization running Unbound should upgrade to 1.26.1 or later without delay.

Also Noted:

Bottom line: The past 24 hours were dominated by actively exploited critical infrastructure flaws (Cisco ISE) and high-volume data exposure (Gyazo), underscoring that identity and management-plane systems remain prime targets. Supply-chain compromises via CDN credentials (Brevo) and AI-assisted mobile malware further expand the attack surface.

Prioritize immediate patching of network-access-control and management servers, rotate any long-lived third-party API keys, and treat image-hosting and marketing-script dependencies with the same scrutiny applied to core infrastructure.

Reply

Avatar

or to participate