43Articles
9Categories
2026-09-15Date
🚨 CISA KEV 1[−]
15 Sep KEVA maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure troveYet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity. CVE-2026-85706 , the second flaw GitLab has disclosed in just a month, is a maximum-severity vulnerability that allows attackers to read arbitrary files in a single…CSOONLINE.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 3[−]
15 SepRoot RCE Zero-Day in Cisco Secure Email Gateway Under Active ExploitationAn unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek .SECURITYWEEK.COM
15 Sep KEVCisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command ExecutionCisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described a…THEHACKERNEWS.COM
15 Sep KEVCisco patches actively exploited email gateway zero-day (CVE-2026-76461)Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday. The vendor’s Product Security Incident Response Team became aware of active exploitation of this vulnerability in…HELPNETSECURITY.COM
⚠️ VULNERABILITY DISCLOSURE 22[−]
15 SepHomebrew 7.0.0 is out, here’s what changed for securityHomebrew installs command-line software and desktop applications from the terminal on macOS and Linux, and Mac developers use it to set up their machines. On Sunday the project shipped version 7.0.0 and closed eight security advisories with it. The most serious of them let unsign…HELPNETSECURITY.COM
15 SepYour employees are already using AI tools you never approvedSeventy-four percent of respondents report departmental or scaled AI adoption at their organizations, including within individual teams or departments, across business functions, and as part of processes and operations, according to the latest OneTrust 2026 AI-Ready Governance Re…HELPNETSECURITY.COM
15 SepChina-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGEA Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the monik…THEHACKERNEWS.COM
15 SepCisco patches Secure Email Gateway zero-day exploited in attacksCisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]BLEEPINGCOMPUTER.COM
15 SepLiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared ServerA critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers' sites run on a single machine, and an atta…THEHACKERNEWS.COM
15 SepThreat actors are coming for your AI assets to operationalize their use of AIBoth state-affiliated cyberespionage group and cybercrime gangs are targeting AI-related documents, configuration files, and proprietary models during intrusions. In addition, the number and scope of distillation attacks, where the knowledge, logic, and reasoning capabilities of …CSOONLINE.COM
15 SepMicrosoft Releases Emergency Patch to Fix RDS SnafuMicrosoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch TuesdayINFOSECURITY-MAGAZINE.COM
15 SepAkuity gives AI agents operational context to safely ship softwareAkuity has introduced its Agentic Control Plane and MCP Server. Akuity’s Agentic Control Plane lets AI agents accelerate software delivery by giving them the operational context and permissions to act, all governed by the same controls Akuity already enforces across the pip…HELPNETSECURITY.COM
15 SepTraefik Labs brings independent verification to AI agent governanceTraefik Labs has introduced the Sovereign Trust Plane (STP), a set of capabilities in Traefik Hub that brings verifiable evidence to AI agent governance, with general availability planned by September 30, 2026. STP connects delegated access, policy enforcement and protected recor…HELPNETSECURITY.COM
15 SepTelegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft TrapsA Telegram Desktop flaw let bots inject JavaScript into exported chats, enabling data theft and page manipulation. Old HTML exports remain unsafe. A vulnerability in Telegram Desktop could have turned an ordinary chat export into a serious data leak. Security researchers Denis an…SECURITYAFFAIRS.COM
15 SepNon-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at RiskJapan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan ‘s Digital Agency disclosed that attackers exploited a vulnerability in a VPN device to access it…SECURITYAFFAIRS.COM
15 SepAI is exposing a security structure built for yesterday’s threatsOrganizations are investing more in security than ever before, yet many still struggle with a fundamental problem: they are preparing for tomorrow’s crisis with yesterday’s mindset. For decades, companies organized security around neat categories. Cybersecurity protected networks…CSOONLINE.COM
15 SepThe AI Threat Multiplier: Securing Mobile Apps in the Automated Era - ASW #400While agents and LLMs haven't fundamentally changed core mobile vulnerability types, they have supercharged speed, scale, and accessibility—democratizing threats like automated phishing, synthetic identity fraud, and easier identification of hard-coded secrets. Ryan Lloyd and Jas…YOUTUBE.COM
15 Sep25 Years of Mass Surveillance Is EnoughThis essay was written with Cindy Cohn, and originally appeared in Lawfare . One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass…SCHNEIER.COM
15 Sep1Password's AI patching benchmark is misleading1Password’s FLAWED report , published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes only 26% of the time. That figure includes experiments that deliberately instructed agents to apply the wrong fix, along wit…TRAILOFBITS.COM
15 SepAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitzAttackers compromised the verified official HBO Max Reddit account, u/hbomax, and used its trusted advertising status to launch a ClickFix campaign targeting macOS and Windows devices with information-stealing malware. Screenshot of the fraudulent ad (Source: Alex Cutts) ClickFix…HELPNETSECURITY.COM
15 Sep240,000 Hit by Data Breach at Japan’s Digital AgencyHackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people. The post 240,000 Hit by Data Breach at Japan’s Digital Agency appeared first on SecurityWeek .SECURITYWEEK.COM
15 SepApple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 ReleasesThe updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks. The post Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases appeared first on SecurityWeek .SECURITYWEEK.COM
15 SepHackers demand 10,000 Bitcoin from Revolut following data breachDev Kundaliya reports: Revolut recently disclosed a security incident in which an unauthorised third party obtained sensitive customer information by sending fraudulent requests from the email domain of a legitimate government agency. People claiming responsibility for the incide…DATABREACHES.NET
15 SepMembers of ‘Black Axe’ cybercriminal group extradited from South AfricaJonathan Greig reports: Five alleged members of the Black Axe cybercriminal organization will make their first court appearance on Monday after being extradited from South Africa. Prosecutors unsealed a 2021 indictment accusing the five men of conducting lucrative romance scams t…DATABREACHES.NET
15 SepStudent photos, bank details stolen by hackers after St James Anglican School in Perth hit by cyber attackEmma Kirk reports: A school in Perth’s north has been targeted in a cyber attack, with hackers stealing students and families’ personal information. St James Anglican School, in Perth’s north, identified a cyber breach involving unauthorised access into its computer systems. Pare…DATABREACHES.NET
15 SepOne Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under FireTwo China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, VolexityR…SECURITYAFFAIRS.COM
📋 SECURITY BULLETINS 1[−]
15 SepMicrosoft confirms KB5002914 Excel update breaks copy and pasteMicrosoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 3[−]
15 SepSupreme Court denies Trump request to allow USPS mail ballot changesOne justice said the attempt to change the rules ahead of the 2026 elections would be "arbitrary and capricious” and violated the Administrative Procedures Act. The post Supreme Court denies Trump request to allow USPS mail ballot changes appeared first on CyberScoop .CYBERSCOOP.COM
15 SepMicrosoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety ConstraintsThe Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability. The post Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints appeared first on SecurityWeek .SECURITYWEEK.COM
15 SepMicrosoft sets security and safety rules for its AI modelsMicrosoft AI has published the first draft of its Humanist AI Code of Conduct, a training manual outlining how it develops AI models and intends them to behave during deployment. The draft is open for public consultation for six weeks. The company plans to review the feedback, re…HELPNETSECURITY.COM
🔥 INCIDENT REPORTING 3[−]
15 SepHacked HBO Max Reddit Account Used for Malware Delivery via ClickFix AttackAds led to a ClickFix page designed to trick macOS and Windows users into installing malware. The post Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack appeared first on SecurityWeek .SECURITYWEEK.COM
15 SepHBO Max Reddit account hijacked in PasteSwitch malware campaignA compromised verified HBO Max Reddit account was used to distribute more than 100 malicious advertisements as part of a large cross-platform ClickFix campaign targeting both Windows and macOS users. Researchers at Hudson Rock and Kirk from ADAMnetworks traced the incident to a b…CYBERINSIDER.COM
15 SepCenterPoint Energy confirms data breach after hacker claims 7.49M recordsCenterPoint Energy has confirmed that an unauthorized third party obtained personal information belonging to some of its customers through an external-facing system. The disclosure follows an online post in which a threat actor claimed to have stolen and released information on a…CYBERINSIDER.COM
🕵️ THREAT INTELLIGENCE 4[−]
15 SepISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094, (Tue, Sep 15th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
15 SepMost chief audit executives can’t tell you what AI is worth yetAuditors are using AI in their daily work, and their departments have mostly left them to figure it out alone. 93% of audit leaders and auditors report some level of AI use, while 15% say their department has deployed formal use cases and runs them routinely in audits, according …HELPNETSECURITY.COM
15 SepProduct showcase: mSecure makes one vault do more than remember passwordsmSecure is a password manager and data vault for storing credentials and other sensitive information. It is available for iOS, Android, macOS, and Windows, with data synchronization across supported devices. The app uses AES-256 encryption and a zero-knowledge architecture. The c…HELPNETSECURITY.COM
15 SepOn the NSA’s Supercomputer from the 1960sReally interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.SCHNEIER.COM
🌐 CYBER THREAT LANDSCAPE 1[−]
15 SepGoogle Doc Sidebar Sends Mac and Windows Users Down Different Paths to MalwareA single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.HUNTRESS.COM
📡 INFOSEC NEWS 5[−]
15 SepFormer AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison. That should be plenty of time for him to rue the day he agreed to increase his monthly income by helping a SIM swap gang in…BITDEFENDER.COM
15 SepSearch results are sending people to fake Bitrefill checkoutsFake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers.MALWAREBYTES.COM
15 SepSuspected Black Axe gang leaders face cybercrime charges in the USFive alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. [...]BLEEPINGCOMPUTER.COM
15 SepMeta AI builds detailed profiles of children from years of family postsA mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts.MALWAREBYTES.COM
15 SepA House Divided: The CIA, State, and a Coup in South VietnamIt's a dark moment in American history that leads to a lot of what-ifs. By the spring of 1963, eight years into the Vietnam War, two opposing factions across the CIA and the State Department had President John F. Kennedy's ear. One side wanted to keep South Vietnam's first presid…THECYBERWIRE.COM