CISA added an exploited remote code execution flaw in Cisco Secure Email Gateway to its KEV catalog with a three day federal deadline, Sandworm was tied to an upgraded Cyclops Blink botnet spread through Cisco firewall flaws, and a Chinese speaking actor breached 13 organisations in six countries by exploiting a Gitea RCE bug.
🔴 CRITICAL (2)
CISA adds exploited Cisco Secure Email Gateway SQL injection CVE-2026-76461 to KEV catalog Confirmed
CISA added CVE-2026-76461, a CVSS 9.8 SQL injection in Cisco AsyncOS for Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities catalog on September 14 after evidence of active exploitation. An unauthenticated remote attacker can reach the flaw through email parsing, and reporting on the bug says it can be turned into command execution with root privileges on the appliance. Federal agencies have until September 17 to apply mitigations, so administrators of internet facing mail gateways should patch or mitigate now and review logs for unusual mail handling activity.
Sources CISA|Cisco|Gridinsoft
Sandworm linked to upgraded Cyclops Blink botnet deployed through Cisco firewall flaws Confirmed
DarkReading reports that the Russian group Sandworm is chaining Cisco Secure Firewall Management Center vulnerabilities, including the actively exploited CVE-2026-20079, to spread an upgraded version of Cyclops Blink, the network device botnet the FBI disrupted in 2022. Earlier reporting attributed the same flaws to a suspected Russian state cluster and to a Qilin ransomware affiliate that used them for credential theft and root access. Operators of internet facing firewall management interfaces should confirm their patch level and hunt for web shells, unexpected admin accounts and altered device firmware.
Sources DarkReading|Security Affairs
🟠 HIGH (6)
Exploitation of maximum severity GitLab CVE-2026-85706 continues as supply chain risk flagged Confirmed
CISA is warning that attackers are now exploiting CVE-2026-85706, the CVSS 10.0 path traversal in GitLab Community and Enterprise Edition that lets an unauthenticated attacker read arbitrary files from the server through the repository commits API in a single request. DarkReading highlights the supply chain dimension, because exposed instances can leak repository contents and CI secrets that downstream projects trust. Self managed servers should already be on 19.1.8, 19.2.6 or 19.3.2, and any secrets readable from an affected instance should be rotated.
Sources BleepingComputer|DarkReading|Rapid7
Japan's Digital Agency says VPN flaw exposed around 246,000 personnel records Confirmed
Japan’s Digital Agency disclosed a data breach in which an attacker exploited a vulnerability in a VPN device protecting its government shared services network, potentially exposing roughly 246,000 record rows containing personal information about government employees. The agency is still assessing the full scope and notifying the people and organisations affected. The case is a reminder that unpatched remote access appliances remain one of the most common entry points into government and enterprise networks.
Sources BleepingComputer|crypto.news
Red Heron exploits Gitea RCE to compromise 13 organisations across six countries Confirmed
Acronis Threat Research Unit attributes a multinational campaign to a Chinese speaking actor it tracks as Red Heron, which rapidly exploited a remote code execution flaw in Gitea (CVE-2026-60004) on internet facing instances. The actor scanned 1,386 Gitea servers across seven countries, kept a separate list of 477 Taiwan based systems, and used the access to hit 13 organisations across six countries, including government and defence related targets, deploying a previously undocumented Linux rootkit. Self hosted Gitea installations should be patched immediately and checked for the rootkit, rogue accounts and repository access.
Sources The Hacker News|Acronis TRU
Telus warns customers of account breaches spanning February 2025 to June 2026 Confirmed
Telus is telling some Canadian customers that unauthorised parties used stolen credentials to access their accounts over a campaign that ran from February 2025 to June 2026, exposing personal information and billing records. The company says the affected accounts were secured, and no exploitation of a software vulnerability has been reported. Attacks that rely on valid credentials are not fixed by patching, so customers should reset passwords and enable phishing resistant multi factor authentication, and defenders should alert on billing changes and logins from unusual locations.
Sources SecurityWeek
Mass scanning campaign targets exposed Vite dev servers to harvest AWS and Azure credentials Confirmed
BleepingComputer reports a large scale automated campaign probing internet exposed Vite development servers and abusing a file read flaw to lift cloud credentials and configuration from AWS and Azure deployments. Vite dev servers are intended for local use and should never be reachable from the internet. Teams should confirm their dev servers bind to localhost only, rotate any cloud keys that may have been exposed, and review cloud audit logs for API calls from unfamiliar addresses.
Sources BleepingComputer
Thai broadband provider 3BB hit through FortiGate SSL-VPN with MeshCentral used as backdoor Confirmed
Hunt.io uncovered a live intrusion at 3BB, one of Thailand’s largest broadband providers, after discovering an attacker controlled server left open on the internet. The evidence shows initial access through a FortiGate SSL-VPN flaw, a legitimate MeshCentral remote management tool repurposed for persistent root level control, and attempts to reach subscriber RADIUS databases that hold authentication credentials. Network operators should audit remote access appliances and any management agents running inside their networks, and assume subscriber credentials in reach of the attacker are exposed.
Sources The Hacker News|Hunt.io
🟡 MEDIUM (5)
Microsoft ships out-of-band updates fixing RDS, Hyper-V and USB audio breakage from September patches Confirmed
Microsoft released emergency updates outside its normal cycle to fix Remote Desktop Services failures, Hyper-V problems and USB audio breakage introduced by the September 2026 security updates, including KB5124008 and KB5124012 on some Windows versions. Administrators who deferred the original updates or disabled services as a workaround should install the out of band fix and restore normal operation. This resolves the RDS failures reported in yesterday’s digest.
Sources BleepingComputer|BleepingComputer
Apple patches 261 vulnerabilities in its annual release across all operating systems Confirmed
Apple shipped its yearly update wave across iOS, iPadOS, macOS, watchOS and tvOS, fixing 261 vulnerabilities according to SANS ISC, the most Apple has patched in a single release. The updates also add features, and no actively exploited flaws have been flagged in this batch. Device owners and fleet administrators should schedule the update rather than defer it, since a backlog of unpatched Apple devices is a known target for browser and messaging exploits.
Sources SANS ISC
Hijacked HBO Max Reddit account used to push ClickFix malware through paid ads Confirmed
Attackers took over the official HBO Max Reddit account and used it to run malicious advertisements that delivered ClickFix lures, tricking Windows and macOS users into pasting commands that installed information stealing malware. The incident shows how quickly an established brand account can be turned into a malware distribution channel, and why paid placements on social platforms need independent verification. Users should treat any copy and paste fix prompt served by a web page as hostile.
Sources BleepingComputer
Telegram Desktop flaw hid JavaScript in exported chat HTML Confirmed
Researchers at ExPatch disclosed a flaw in Telegram Desktop where a bot’s message planted hidden JavaScript inside an inline keyboard button. The message looked ordinary in Telegram, the bot did not need to join the chat, and the script ran only once a user opened an HTML export of that conversation in a browser, where it could copy every message in the file to an attacker server. Export files should only be opened from trusted sources, and Telegram Desktop should be kept current.
Sources The Hacker News|ExPatch
Identity verification provider IDScan.net discloses breach of names and government ID numbers Confirmed
Check Point’s weekly threat intelligence report notes that IDScan.net, a US identity verification provider, disclosed unauthorised access detected on September 1, with names and government identification numbers exposed and a criminal marketplace advertising the data. Organisations that use third party identity verification vendors should request incident details and determine whose data was shared with the vendor. People notified of the breach should watch for identity fraud and consider a credit freeze.
Sources Check Point Research
⚪ WATCH (5)
DDRop hardware attack undermines Intel TDX and AMD SEV-SNP confidential computing Confirmed
Researchers disclosed a hardware attack called DDRop that silently drops writes to a server’s memory so the processor keeps reading stale encrypted data as if it were current, breaking the memory protection that Intel TDX and AMD SEV-SNP confidential computing depends on. The attack requires an attacker who already controls the server’s software and brief physical access to insert a small circuit, so it is not a remote exploit. The finding matters to cloud providers and regulated workloads that treat confidential virtual machines as a trust boundary. No exploitation in the wild has been reported.
Sources The Hacker News
WordPress adds automated security review of plugin updates before distribution Confirmed
WordPress announced that every plugin release will pass an automated security review before being distributed through the WordPress.org update API, closing a gap where new plugins were reviewed on entry but updates shipped unchecked afterwards. The change should shorten the window in which a compromised or deliberately malicious update reaches millions of sites. Site owners should still stage and test plugin updates, and keep a rollback path for third party components.
Sources The Hacker News
Microsoft lists double free in Windows Secure Kernel Mode as CVE-2026-85921 Confirmed
Microsoft’s September update guide lists CVE-2026-85921, a double free in Windows Secure Kernel Mode that allows an attacker with an existing foothold to elevate privileges locally. No exploitation in the wild has been reported for this CVE. Defenders should include it in the standard Windows update cycle and keep monitoring for local privilege escalation behaviour on endpoints.
Sources MSRC
MetaMask adds transfer screening and transaction preview enforcement against drainers Confirmed
MetaMask released wallet protections that flag suspicious transfers and block transactions whose executed result does not match what the user was shown, a pattern used by wallet drainer kits. The change is preventative: no single incident prompted it. Crypto users should still review token approvals regularly, revoke unused ones, and treat unsolicited airdrops and urgent support messages as hostile.
Sources Decrypt
Unit 42 maps cloud identity roles from audit logs to detect behavioural drift Confirmed
Unit 42 published a behavioural clustering method that builds a baseline of cloud identity roles from audit logs and flags deviations using standard SQL queries, aimed at spotting compromised or misused cloud credentials without bespoke tooling. The approach suits teams running lean cloud security operations that cannot buy and tune another platform. No incident is attached to the research.
Sources Unit 42
Methodology: compiled from vendor advisories, government feeds (CISA KEV, MSRC), security news sources and on-chain/security-firm alerts. Grouping: one incident, one entry, with every source cited. Unconfirmed reports are labeled. Crypto items are incident reporting, not investment advice. Corrections from prior digests are noted at the top when applicable.