Threat digest: 2026-09-17

CISA added three exploited flaws to its Known Exploited Vulnerabilities catalog with three day federal deadlines, Cisco ISE, Google Pixel and Acronis Backup, ConnectWise ScreenConnect exploitation drew a formal CISA warning, and Spain's privacy watchdog logged the first data breach blamed on an autonomous AI agent.

🔴 CRITICAL (3)

CISA adds authentication bypass in Cisco Identity Services Engine CVE-2026-76460 to KEV catalog Confirmed

Cisco Identity Services Engine and ISE Passive Identity Connector contain a flaw that lets an unauthenticated remote attacker bypass the web management interface and reach privileged APIs, rated 10.0 by reporters tracking it. CISA added the bug to its Known Exploited Vulnerabilities catalog on 16 September with a remediation deadline of 19 September, citing evidence of active exploitation. Administrators should apply Cisco’s patched ISE release immediately and treat any internet facing ISE deployment as compromised pending log review.

exploitedcve-2026-76460identity

Sources CISA|Cisco|cvefeed.io

Google patches actively exploited Pixel modem zero-day CVE-2026-58704 Confirmed

Google’s September 2026 Pixel bulletin fixes 110 vulnerabilities, including CVE-2026-58704, a permission bypass in the Pixel cellular modem caused by a logic error and rated 8.0. Google says the flaw was exploited in limited, targeted attacks, and CISA added it to the KEV catalog on 16 September with a 19 September deadline for federal agencies. Pixel owners should install the September update now, and enterprises with managed Pixel fleets should confirm the build has landed on devices.

zero-dayexploitedcve-2026-58704

Sources CISA|BleepingComputer|The Hacker News|SecurityWeek

CISA warns ConnectWise ScreenConnect client flaw CVE-2026-84869 is exploited in the wild Confirmed

A missing authorization and improper privilege management flaw in the ScreenConnect client, CVSS 9.9, lets an attacker with basic privileges move and execute files inside an active remote session without host confirmation. ConnectWise fixed it in ScreenConnect 26.6.5, which closes the path for client versions up to 26.6.5.9742, and CISA has confirmed active exploitation and added the bug to KEV. Remote support platforms sit inside MSP and IT estates, so teams should patch clients and hunt for rogue ScreenConnect installations and unexpected file transfer or command execution in session logs.

exploitedcve-2026-84869malware

Sources BleepingComputer|ConnectWise|SecurityWeek

🟠 HIGH (8)

CISA adds exploited Acronis backup plugin flaw CVE-2026-87886 to KEV catalog Confirmed

Acronis warned that a local privilege escalation flaw caused by insecure file permissions in its Backup plugin for cPanel and WHM has been exploited in targeted attacks, and CISA added CVE-2026-87886 to KEV on 16 September with a 19 September deadline. Hosting providers and site owners running the plugin should update it without delay and review server accounts for signs of tampering. Any account that already reached local access on a shared host is worth auditing, because the flaw turns that access into higher privileges.

exploitedcve-2026-87886cloud

Sources CISA|The Hacker News|BleepingComputer

Issabel PBX framework flaw CVE-2026-89026 exploited for unauthenticated OS command execution Confirmed

Issabel Framework, the web layer behind Issabel PBX, shipped a hard-coded HS256 JWT signing key that is identical on every installation, letting unauthenticated attackers forge bearer tokens and call privileged endpoints to run operating system commands. The flaw carries a CVSS score of 9.8 and exploitation attempts were first observed in the wild, with Shadowserver reporting activity from 9 September. Organisations running Issabel PBX should upgrade past the fixed commit and check telephony servers for unexpected outbound connections.

exploitedcve-2026-89026iot

Sources The Hacker News|Cyber Security News|OpenCVE

Active exploitation attempts target WSO2 API Manager JWT bypass CVE-2026-5430 Confirmed

WSO2 API Manager contains a critical flaw in cryptographic signature verification, CVSS 9.8, that lets attackers forge admin tokens and take over accounts. watchTowr has observed exploitation attempts in the wild using forged administrative JWTs against exposed deployments. Teams running WSO2 API Manager should patch the current release and review API gateway logs for tokens signed outside normal issuance.

exploitedcve-2026-5430identity

Sources The Hacker News

Two unauthenticated RCE flaws in The Events Calendar put 200,000+ WordPress sites at risk Confirmed

The Events Calendar plugin, installed on more than 200,000 sites, carries two critical remote code execution bugs rated 9.8: CVE-2026-78006 in the widget safety check and CVE-2026-78159 in array parsing, both fixed in recent releases. Exploitation is unauthenticated on affected configurations, for example where comments on event posts are open. WordPress operators should update the plugin now and review whether a crafted comment or widget payload has been posted on their sites.

cve-2026-78006exploitedsupply-chain

Sources SecurityWeek|cvefeed.io|cveo.tech

Hijacked AI coding assistant session spread Shai-Hulud worm across about 100 repositories Confirmed

Mandiant reported that an attacker took over a live AI coding assistant session at an unnamed SaaS provider, poisoned a package the assistant then recommended and that a developer accepted, and ultimately spread the Shai-Hulud worm across roughly 100 internal code repositories. The worm stole repository secrets and source code. The case shows that assistant recommendations are part of the software supply chain, so review AI assisted dependency choices, rotate CI secrets, and pin package versions.

supply-chainai-securitymalware

Sources The Hacker News

North Korean linked group hides TED backdoor inside HAProxy to spy on South Korean media and automotive firms Confirmed

Rapid7 documented a Linux espionage toolkit, attributed to North Korean actors with medium confidence, that compiles a backdoor directly into a modified HAProxy 2.8.12 build alongside trojanised system daemons, an SSH credential logger and a curl based RAT. Victims in the South Korean media and automotive sectors, including one case active since early 2025, had traffic inspected after TLS termination, with logs scrubbed to hide the activity. Any organisation terminating TLS at a load balancer should verify binary integrity, forward logs off host and baseline appliance memory.

c2malwarecampaign

Sources DarkReading|SecurityWeek|Rapid7

Revolut extortion crew demands $3 million in Monero and threatens to sell customer data Confirmed

The group behind the September Revolut data incident is demanding roughly $3 million in monero within 24 hours and threatening to sell stolen customer records to other criminal groups if it is not paid. The data involved identity documents, bank details and transaction histories released after a fraudulent request that appeared to come from a government agency. Affected customers should treat their identity documents as exposed and watch for impersonation and account takeover attempts.

breachcryptofraud

Sources CoinDesk|Cyber Security News|Security Affairs

Spain's AEPD reports first data breach carried out with an autonomous AI agent Under investigation

Spain’s data protection agency published details of the first breach notification in the country where an attacker used an AI agent built on a known large language model to chain the attack: the agent searched for flaws, logged in, scanned the application, then modified personal data and accessed invoices. The AEPD says the report is still under review and that the model and its provider were not compromised. The agency is advising organisations to revisit risk analysis and detection speed for agentic attacks, and privacy and security teams should test whether current incident response assumes this level of automation.

ai-securitybreachresearcher

Sources SecurityWeek|BleepingComputer|Reuters|The Register

🟡 MEDIUM (9)

Three threat clusters hit Russian enterprises with backdoors, ransomware and wipers Confirmed

Kaspersky documented three activity clusters, NightEagle (also tracked as APT-Q-95), Hacking Cat and Toy Ghouls, targeting enterprises in Russia with new persistence and lateral movement techniques alongside backdoors, ransomware and wipers. The reporting describes distinct tooling per cluster rather than one campaign. Defenders outside the region should note the shared techniques, particularly living off legitimate remote management tools.

ransomwaremalwarecampaign

Sources The Hacker News

Chrome and Firefox updates patch 115 vulnerabilities Confirmed

Google resolved 42 security defects in Chrome and Mozilla fixed 73 bugs in Firefox in the latest release cycle. Most are memory safety issues in browser engines and can be reached through crafted web content. Browser fleets should be updated promptly, and organisations that pin browser versions should schedule the refresh now rather than at the next patch window.

patch-tuesdaycve-2026-87458

Sources SecurityWeek

ZDI review of Apple's September 2026 release highlights an actively exploited Screen Sharing bug Confirmed

ZDI’s analysis of Apple’s September 2026 updates counts 273 CVEs across macOS, iOS, Safari, watchOS, visionOS and Xcode, and flags CVE-2026-65400, a 9.8 rated Screen Sharing Server issue, among the ones that stand out, with one flaw under active exploit. Apple does not publish severity scores, so the picture only became clear after third party scoring. Apple device fleets should be brought current, including older supported hardware that often lags behind.

zero-dayexploitedcve-2026-65400

Sources ZDI

Windows 11 KB5124008 update breaks domain trust for some enterprise users Confirmed

Microsoft is investigating reports that the KB5124008 security update breaks domain trust relationships on some Windows 11 systems, leaving users unable to sign in with valid domain credentials. The problem affects managed enterprise environments rather than home devices. Administrators who have not yet deployed the update should test first, and those who already have should check for domain trust errors in the affected scope.

patch-tuesdayidentity

Sources BleepingComputer

One browser extension could hijack AI assistants across five Chromium products Confirmed

Researchers at Forever Security showed that a single ordinary browser extension could take control of the built in assistants in Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension, reaching them with one click after installation. The pattern matters because browser agents increasingly hold session data and can act on the user’s behalf. Organisations deploying agentic browsers should restrict extension installation and review what the assistant is permitted to reach.

ai-securityprompt-injectionresearcher

Sources The Hacker News

Parallels Desktop flaw gives non-admin Mac users root, with no fix for Intel Macs Confirmed

JFrog disclosed a flaw in Parallels Desktop for Mac that lets an ordinary local account run code as root, provided the attacker already has code execution on the machine; the issue does not work over the network. The fix ships in Parallels Desktop 27, a version Intel based Macs cannot install, so those users are left without a patch. Affected teams should limit local accounts and treat the machine as a privilege boundary until they can migrate hardware.

malwareresearcher

Sources The Hacker News

Premier Medical Group breach affects 280,000 people Confirmed

A data breach at Premier Medical Group has affected around 280,000 individuals, according to the notification reported this week. Healthcare records carry a long tail of fraud risk, from medical identity theft to targeted phishing. Those notified should treat any unexpected contact about their care as suspect and monitor insurance and credit activity.

breachdata-leak

Sources SecurityWeek

Unit 42 details Atomic macOS stealer campaigns hidden in fake setup guides Confirmed

Unit 42 published analysis of ongoing Atomic macOS Stealer activity where victims are walked through deceptive setup guides that lead to credential and data theft on Macs. The lures look like legitimate software installation help rather than crude droppers, which makes them harder to dismiss. Mac users should source installers from vendor sites only, and security teams should monitor for the stealer’s typical browser and keychain access patterns.

stealermalwareresearcher

Sources Unit 42

N0va phishkit targets US and EU businesses through legitimate authentication flows Confirmed

A phishing kit tracked as N0va is targeting organisations in North America and Europe with pages that impersonate trusted services and abuse legitimate authentication flows, so a successful attack yields valid account access without obvious malware. That pattern defeats detection built around malware signatures. Identity teams should tighten conditional access, push phishing resistant authentication and alert on impossible travel and token reuse.

phishingidentitycampaign

Sources The Hacker News

⚪ WATCH (5)

BragJack technique turns a browser's agentic AI against the user Research finding

DarkReading reported on a technique called BragJack that hijacks the AI assistant built into browsers so it can reach sensitive information, take actions and exfiltrate data. It is a research stage finding rather than a confirmed attack on a named victim, and it reinforces that agent permissions are a new attack surface. Teams piloting browser agents should scope their credentials and require confirmation before consequential actions.

ai-securityprompt-injectionresearcher

Sources DarkReading

PhantomRaven npm stealer was LLM generated and pitched as bug bounty work Confirmed

CrowdStrike attributed the PhantomRaven JavaScript information stealer, spread through malicious npm packages to harvest developer credentials and CI/CD data, to a financially motivated operator who worked as a bug bounty hunter and almost certainly used an LLM to write the code. The case shows AI lowering the effort needed to build working malware. Development teams should verify package provenance and rotate secrets exposed to unfamiliar dependencies.

supply-chainai-securitystealer

Sources CrowdStrike|Axios

Data broker Radaris loses its domains in a privacy lawsuit Confirmed

A New Jersey court ordered that radaris.com and more than a dozen related data broker domains be transferred to plaintiffs after the company repeatedly stonewalled a case brought under a state privacy law covering information about law enforcement officials. The ruling is a rare enforcement outcome against a people search operation. It is a useful precedent for anyone pursuing removal requests against brokers that ignore them.

data-leakfraud

Sources KrebsOnSecurity

OpenAI publishes a model misalignment reporting framework with six disclosures Confirmed

OpenAI described a framework for tracking, investigating and disclosing model misalignment, and published six reports of unexpected or concerning model behaviour alongside it. The disclosures are self reported by the vendor, so they are a transparency signal rather than independent verification. Security teams assessing AI risk can use the structure when writing their own incident categories for autonomous behaviour.

ai-securityresearcher

Sources OpenAI

Two Robinhood engineers charged over insider trading on Hyperliquid perpetuals Confirmed

US prosecutors charged two Robinhood engineers with insider trading using Hyperliquid perpetual futures, according to CoinDesk. The case extends insider trading enforcement into decentralised derivatives venues where trade records are public but identity is not. Compliance teams at firms with staff access to order flow data should review conflict of interest controls for onchain positions.

fraudcrypto

Sources CoinDesk

Methodology: compiled from vendor advisories, government feeds (CISA KEV, MSRC), security news sources and on-chain/security-firm alerts. Grouping: one incident, one entry, with every source cited. Unconfirmed reports are labeled. Crypto items are incident reporting, not investment advice. Corrections from prior digests are noted at the top when applicable.