Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 15, 2026

Cisco confirmed active exploitation of CVE-2026-76461, an unauthenticated SQL-injection flaw in Secure Email Gateway's AsyncOS email parsing that yields root command execution; CISA added it to the KEV catalog with a September 17 patch deadline, and Cisco published IoCs directing defenders to inspect cluster mail_logs for suspicious SQL statements. Volexity attributed the BlueMoon Chrome-Windows chain (CVE-2026-85046, -87491, -85880) to two China-linked actors, UTA0560 and APT31, who targeted NGOs on September 1 through a patch gap in which Chromium source carried the fixes before any stable Chrome release shipped them.

Compiled by the Slugnet Editorial System. Published Sep 15, 2026, 7:36 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    The Hacker News

    LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

    What happened

    cPanel issued an advisory on September 14 warning that a vulnerability in LiteSpeed Web Server Enterprise allows a low-privilege hosting account to bypass isolation controls like CageFS and gain root access on shared servers. The flaw affects versions prior to 6.3.7, which LiteSpeed released on September 11, and requires manual installation via the `lsup.sh` script because automatic updates may be delayed.

    Why it ranks #1

    cPanel issued an advisory on September 14 warning that a vulnerability in LiteSpeed Web Server Enterprise allows a low-privilege hosting account to bypass isolation controls like CageFS and gain root access on shared servers.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    What to do

    Update cPanel to version 6.3.7, released September 11, to address the flaw affecting earlier versions.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    product
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    BleepingComputer

    Cisco patches Secure Email Gateway zero-day exploited in attacks

    What happened

    Cisco disclosed that threat actors are actively exploiting CVE-2026-76461, a zero-day vulnerability in Secure Email Gateway appliances that allows unauthenticated remote attackers to execute arbitrary commands with root privileges. The flaw stems from insufficient validation in the email parsing logic, enabling attackers to inject malicious SQL statements via crafted messages to gain full control of the underlying operating system. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch their systems by September 17.

    Why it ranks #2

    Cisco disclosed that threat actors are actively exploiting CVE-2026-76461, a zero-day vulnerability in Secure Email Gateway appliances that allows unauthenticated remote attackers to execute arbitrary commands with root privileges.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    enterprise
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    Schneier on Security

    Microsoft’s Patching

    What happened

    Microsoft released a record-breaking September patch addressing approximately 972 vulnerabilities, including 112 rated as high or critical. The update follows an industry-wide warning that AI-enabled attacks are shrinking the window for remediation, with some estimates suggesting exploits can be generated within hours of a vulnerability hint.

    Why it ranks #3

    Microsoft released a record-breaking September patch addressing approximately 972 vulnerabilities, including 112 rated as high or critical.

    Who should care

    CISOs and security leaders

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    BleepingComputer

    Hackers target exposed Vite dev servers to steal AWS, Azure secrets

    What happened

    A mass-scanning campaign is actively exploiting CVE-2026-39364, a high-severity file access control bypass in Vite versions 7.1.0 through 7.3.2 and 8.x before 8.0.5, to steal AWS and Azure credentials from internet-exposed development servers. F5 detected over 800 attacks in a month, with threat actors using extensive wordlists to target environment files and cloud configuration backups. Administrators should update Vite to the latest version, block port 5173, and rotate any secrets accessible from unpatched, publicly exposed instances.

    Why it ranks #4

    A mass-scanning campaign is actively exploiting CVE-2026-39364, a file access control bypass in Vite versions 7.1.0 through 7.3.2 and 8.x before 8.0.5, to steal AWS and Azure credentials from internet-exposed development servers.

    Who should care

    Application security teams, Cloud security teams, IT and platform operations, SOC and incident response teams

    What to do

    Block port 5173, filter suspicious /@fs/ requests, and do not trust crawler User-Agent strings.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    Help Net Security

    Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz

    What happened

    Attackers compromised the verified HBO Max Reddit account to distribute 108 ClickFix advertisements over 48 hours, directing users to malicious sites that deploy information-stealing malware on macOS and Windows. The campaign, part of a broader operation named PasteSwitch, used the account's trusted status to bypass user skepticism and deliver payloads that collect browser credentials, cryptocurrency recovery phrases, and system data.

    Why it ranks #5

    Attackers compromised the verified HBO Max Reddit account to distribute 108 ClickFix advertisements over 48 hours, directing users to malicious sites that deploy information-stealing malware on macOS and Windows.

    Who should care

    CISOs and security leaders, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    The Hacker News

    3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

    What happened

    Hunt.io identified an attacker who maintained root access to 3BB's internal network using a hidden MeshCentral backdoor and targeted the company's RADIUS databases for subscriber credentials. The exposed staging server contained scripts for lateral movement and a complete exploit for the FortiGate SSL-VPN vulnerability CVE-2024-21762, though the initial intrusion vector remains unconfirmed.

    Why it ranks #6

    Hunt.io identified an attacker who maintained root access to 3BB's internal network using a hidden MeshCentral backdoor and targeted the company's RADIUS databases for subscriber credentials.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    The Hacker News

    Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

    What happened

    Acronis attributes a multi-national campaign to the suspected Chinese threat actor Red Heron, which weaponized the Gitea remote code execution flaw CVE-2026-60004 to compromise 13 organizations across six countries. The actor automated the exploitation of the July 2026 vulnerability to steal source code, collect credentials, and establish root-level access on a three-node Proxmox cluster.

    Why it ranks #7

    Acronis attributes a multi-national campaign to the suspected Chinese threat actor Red Heron, which weaponized the Gitea remote code execution flaw CVE-2026-60004 to compromise 13 organizations across six countries.

    Who should care

    CISOs and security leaders, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    proof of concept
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    The Hacker News

    China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

    What happened

    Volexity attributed a spear-phishing campaign to a Chinese threat actor, UTA0560, that exploited a chain of zero-day flaws in Google Chrome and Microsoft Windows to deploy the GRIMWEDGE JavaScript backdoor. The attack chain, dubbed BlueMoon, leveraged a patch gap where fixes existed in the Chromium source but had not yet reached stable Chrome releases, allowing the actor to target non-governmental organizations on September 1.

    Why it ranks #8

    Volexity attributed a spear-phishing campaign to a Chinese threat actor, UTA0560, that exploited a chain of zero-day flaws in Google Chrome and Microsoft Windows to deploy the GRIMWEDGE JavaScript backdoor.

    Who should care

    CISOs and security leaders, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    sector
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    BleepingComputer

    Twitch extension with 30K installs exposes users’ OAuth tokens

    What happened

    Socket identified that the Twitch Enhanced Viewer | JeetBot extension, which has over 30,000 installs, captures users' Twitch OAuth session tokens and transmits them as cleartext URL parameters to third-party proxy servers. This mechanism writes the credentials into the proxy request logs, allowing the vendor to access the tokens for every channel a user watches. Socket recommends that users remove the extension and re-authenticate their Twitch sessions to invalidate the exposed credentials.

    Why it ranks #9

    Socket found the Twitch extension captures OAuth tokens and sends them as cleartext URL parameters to third-party proxies, writing credentials into request logs for every watched channel.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    BleepingComputer

    Suspected Black Axe gang leaders face cybercrime charges in the US

    What happened

    Five alleged leaders of the Black Axe syndicate were extradited to the United States on September 11 to face wire fraud and money laundering charges. Prosecutors accuse the defendants of coordinating a 2011–2021 campaign from Cape Town that used romance scams and advance fee schemes to defraud U.S. victims.

    Why it ranks #10

    Five alleged leaders of the Black Axe syndicate were extradited to the United States on September 11 to face wire fraud and money laundering charges for a 2011–2021 campaign involving romance scams and advance fee schemes.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    critical
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email