Summary: Cisco has disclosed CVE-2026-76460, a maximum-severity (CVSS 10.0) authentication-bypass vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector. The flaw stems from insufficient authentication control on an API endpoint; an unauthenticated remote attacker can send a crafted request and gain unauthorized access to the web-based management interface.
Cisco’s PSIRT confirmed active exploitation in the wild. Fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. CISA added the CVE to its KEV catalog with a September 19 deadline for federal agencies. No workarounds exist; iACLs limiting management traffic are the only temporary mitigation.
Key takeaway / Actionable note: Immediately inventory all ISE/ISE-PIC instances and apply the listed patches; review access.log for unexpected usernames (e.g., “dummyuser”) as an IoC.
Summary: The FBI, working with the U.S. Attorney’s Office for the District of Alaska and the Royal Canadian Mounted Police, seized the domains nightmare-stresser.com and nightmarestresser.org used by NightmareStresser, described as one of the world’s longest-running DDoS-for-hire (“booter”) services. Court documents state the platform facilitated hundreds of thousands of actual or attempted DDoS attacks against educational institutions, government agencies, gaming platforms and other targets worldwide since 2022. The action is part of the ongoing international Operation PowerOFF.
Key takeaway / Actionable note: Organizations that experienced unexplained volumetric or application-layer DDoS spikes in recent years should review logs for traffic patterns associated with known booter infrastructure.
Summary: Helpfeel, operator of the Gyazo image-sharing service, disclosed that an attacker exploited a vulnerability in the image-upload server on or around September 11, executed arbitrary commands, and accessed the database. Approximately 23.62 million user records (email addresses, password hashes, user/device IDs, X/Google SSO tokens, profile data, etc.) and roughly 490 million image-metadata records (mostly pre-January 2019, including image IDs, EXIF, OCR text and hashed private-image passphrases) were exposed. No payment-card data was involved. The company has disabled viewing of some affected images and urged all users to change passwords.
Key takeaway / Actionable note: Gyazo users should rotate passwords immediately and treat any linked X or Google accounts as potentially compromised until tokens are revoked.
Summary: ESET researchers report that the China-aligned APT FamousSparrow has replaced its earlier SparrowDoor implant with a new modular C++ backdoor called SparroWocky. The malware has been used since at least August 2025 against government organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela (roughly 90 % of observed targets in the region). Capabilities include command execution, TCP proxying, file theft, screenshot capture, in-memory Beacon Object File loading, and anti-analysis techniques that manipulate low-level Windows structures.
Key takeaway / Actionable note: Latin-American government and critical-infrastructure networks should hunt for SparroWocky indicators and review public-facing Exchange or other remote-access services historically targeted by the group.
Summary: A joint advisory from the UK NCSC, U.S. FBI and Dutch AIVD details the Windows malware family CHOSEN BRICK used by Iranian state actors since at least 2025. Operators socially engineer targets (dissidents, activists, journalists) via messaging apps, deliver the payload disguised as legitimate software or medical files, and use Telegram bots for C2. The malware adds Microsoft Defender exclusions, establishes persistence via Run keys, captures screenshots and microphone audio, steals browser-stored Telegram/WhatsApp data and emails, and can download additional payloads or wipe the system. Stolen personal details have appeared on pro-Iranian leak sites.
Key takeaway / Actionable note: High-risk individuals should treat unsolicited files from messaging apps as hostile, keep Windows and Defender fully updated, and enable MFA on all accounts.
Summary: ISC released BIND 9.20.29 and 9.21.26 to address 14 security vulnerabilities disclosed on 16 September. Issues include an unauthenticated remote crash via a crafted DNS-over-HTTPS SIG(0) request (CVE-2026-77692, CVSS 7.5), DNSSEC validation bypasses that could enable cache poisoning, and multiple resource-exhaustion and zone-transfer problems. No active exploitation is known. The 9.18 branch is end-of-life and receives no fixes.
Key takeaway / Actionable note: Operators of BIND 9.20 or 9.21 should upgrade to the listed releases without delay; 9.18 users must migrate to a supported branch.
Summary: In addition to the exploited ISE zero-day, Cisco issued patches for dozens of additional critical and high-severity vulnerabilities affecting ISE, Secure Firewall Management Center (FMC), Nexus Dashboard and related products. Several allow authenticated or unauthenticated remote code execution, command injection as root, SQL injection, or authentication bypass. Cisco notes that three of the ISE issues had been publicly disclosed prior to the advisory.
Key takeaway / Actionable note: Treat the entire Cisco security-product patch set as urgent; prioritize internet-facing or management-plane instances.
Summary: Google’s September 2026 Pixel security update addresses 110 vulnerabilities, including one zero-day privilege-escalation flaw (CVE-2026-58704) that was actively exploited in targeted attacks. The update is available for supported Pixel devices.
Key takeaway / Actionable note: Pixel users should install the September security patch immediately; enterprise MDM policies should enforce the update where possible.
Also Noted:
Bottom line: The last 24 hours delivered a classic high-severity mix—an actively exploited identity-platform zero-day, a major consumer data breach, nation-state tooling updates, and infrastructure takedowns. Prioritize Cisco ISE and related management-plane patches first, force password resets for any Gyazo-linked accounts, and keep hunting for the newly documented APT implants.
Volume of critical advisories remains elevated; treat every internet-facing management interface as a potential entry point until proven otherwise.

