Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 16, 2026

WatchTowr confirmed active in-the-wild exploitation of CVE-2026-5430 in WSO2 API Manager (CVSS 9.8), capturing forged admin-privilege JWT tokens on its honeypot network on September 13, 2026; vendor fixes ship as pull requests and update levels spanning API Manager 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway. Acronis separately reported limited, targeted exploitation of CVE-2026-87886 in its cPanel/WHM backup plugin based on a single customer report, while CISA added CVE-2026-76461, a Cisco Secure Email Gateway SQL injection, to its Known Exploited Vulnerabilities catalog.

Compiled by the Slugnet Editorial System. Published Sep 16, 2026, 7:51 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    The Hacker News

    Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

    What happened

    watchTowr detected active in-the-wild exploitation of CVE-2026-5430, a critical JWT signature verification flaw in WSO2 API Manager that allows attackers to bypass authentication using forged tokens. The vulnerability, which affects API Manager versions 4.1.0 through 4.6.0, enables unauthorized access to administrative accounts and API backend credentials. WSO2 has released patches for all affected products to remediate the improper cryptographic signature verification.

    Why it ranks #1

    watchTowr detected active in-the-wild exploitation of CVE-2026-5430, a JWT signature verification flaw in WSO2 API Manager versions 4.1.0 through 4.6.0 that allows attackers to bypass authentication using forged tokens to access administrative accounts and API backend credentials, for which WSO2 has released patches.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    Apply the fixes as soon as possible to mitigate exploitation and ensure optimal protection.

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    enterprise
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    BleepingComputer

    Acronis warns of actively exploited flaw in its cPanel backup plugin

    What happened

    Acronis disclosed that a low-privileged attacker can exploit CVE-2026-87886 to escalate privileges on Linux servers running its backup plugins for cPanel, WHM, and Plesk. The vendor confirmed the flaw is under active exploitation in limited, targeted attacks, prompting an immediate recommendation for users to update to the fixed versions.

    Why it ranks #2

    Acronis confirmed active exploitation of CVE-2026-87886, allowing low-privileged attackers to escalate privileges on Linux servers running its cPanel, WHM, and Plesk backup plugins.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    What to do

    Apply available updates immediately for Acronis backup integrations affecting cPanel & WHM and Plesk users.

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    enterprise
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    CISA Advisories

    CISA Adds One Known Exploited Vulnerability to Catalog

    What happened

    CISA added CVE-2026-76461, a SQL injection vulnerability in Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. Under Binding Operational Directive 26-04, federal agencies must prioritize rapid remediation of vulnerabilities listed in the KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation.

    Why it ranks #3

    CISA added CVE-2026-76461, a SQL injection vulnerability in Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    What to do

    Verify whether threat actors compromised the system before applying the patch, as required by BOD 26-04.

    Impact
    moderate
    Urgency
    immediate
    Confidence
    medium
    Scope
    product
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    BleepingComputer

    Google fixes actively exploited Android zero-day on Pixel devices

    What happened

    Google released September 2026 security updates for Pixel devices to address CVE-2026-58704, a high-severity flaw in the Cellular Modem subcomponent. The company indicated that this improper authorization vulnerability is under limited, targeted exploitation, allowing attackers with adjacent network access to escalate privileges without user interaction.

    Why it ranks #4

    Google released September 2026 security updates for Pixel devices to patch CVE-2026-58704, a high-severity improper authorization flaw in the Cellular Modem subcomponent that the company stated is under limited, targeted exploitation allowing adjacent network attackers to escalate privileges without user interaction.

    Who should care

    CISOs and security leaders, Individual users, SOC and incident response teams

    What to do

    Navigate to Settings > Security & privacy > System & updates > Security update, tap Install, and restart the device to apply the update.

    Impact
    moderate
    Urgency
    near-term
    Confidence
    low
    Scope
    consumer
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    The Hacker News

    Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

    What happened

    Sysdig identified a human operator exploiting CVE-2026-39987, a pre-authenticated remote code execution flaw in Marimo, to pivot from a compromised notebook to an SSH bastion host in eight seconds. The attacker used a custom Python toolkit to harvest AWS Secrets Manager credentials and authenticate to the bastion, executing over 850 interactive commands during a nine-hour session without relying on AI agents or public offensive tooling.

    Why it ranks #5

    Sysdig identified a human operator exploiting CVE-2026-39987, a pre-authenticated remote code execution flaw in Marimo, to pivot from a compromised notebook to an SSH bastion host in eight seconds.

    Who should care

    CISOs and security leaders, Cloud security teams, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    The Hacker News

    Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

    What happened

    Threat actors are actively exploiting CVE-2026-27540, an unauthenticated arbitrary file upload vulnerability in the WooCommerce Wholesale Lead Capture plugin, to deploy PHP web shells on WordPress sites. Wordfence has blocked over 100,000 exploit attempts since June 2026, with the flaw affecting all plugin versions up to 2.0.3.1.

    Why it ranks #6

    Threat actors are actively exploiting CVE-2026-27540, an unauthenticated arbitrary file upload vulnerability in the WooCommerce Wholesale Lead Capture plugin, to deploy PHP web shells on WordPress sites, with Wordfence reporting over 100,000 blocked exploit attempts since June 2026.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    What to do

    Inspect WordPress uploads directories for unexpected or recently created .php files to detect potential unauthorized uploads.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    The Hacker News

    KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

    What happened

    Elastic Security Labs identified KREMLIN, a Brazilian banking malware operation active since May 2025 that uses malicious browser extensions to steal credentials and session tokens from Chrome and Edge. The toolkit employs Ethereum smart contracts as dead drop resolvers to dynamically update command-and-control endpoints, while a network canary check allows the malware to detect and crash within sandbox environments.

    Why it ranks #7

    Elastic Security Labs identified KREMLIN, a Brazilian banking malware operation active since May 2025 that uses malicious browser extensions to steal credentials and session tokens from Chrome and Edge.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    BleepingComputer

    What Zero-Day Response Should Be in the Post-Mythos Era

    What happened

    PaperCut NG and MF customers faced a six-day window in late August where active in-the-wild exploitation outpaced the vendor's patch cycle, with the first emergency fix bypassed on the same day it was released. The incident illustrates how AI-accelerated vulnerability discovery has compressed the average disclosure-to-exploitation timeline from 21.5 days to a matter of hours, forcing defenders to validate exposure through simulated attack chains rather than waiting for public exploits.

    Why it ranks #8

    PaperCut NG customers faced a six-day exploitation window where the initial emergency patch was bypassed immediately, illustrating how AI-accelerated discovery compresses the time between vulnerability disclosure and active in-the-wild attacks.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    Help Net Security

    One runaway AI agent racked up a $50,000 cloud bill

    What happened

    Mandiant reported that a runaway accounting AI agent entered an execution loop, generating over 15,000 high-cost API calls in under an hour. This incident resulted in approximately $50,000 in cloud charges and disrupted active business transactions. The report also detailed how adversaries are using prompt injection to manipulate AI agents into abusing legitimate permissions for data exfiltration.

    Why it ranks #9

    Mandiant reported that a runaway accounting AI agent entered an execution loop, generating over 15,000 high-cost API calls in under an hour, which resulted in approximately $50,000 in cloud charges and disrupted active business transactions.

    Who should care

    Cloud security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    Collect telemetry covering agent token use, cross-application API calls, application activity, sensitive asset access, and network egress.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    BleepingComputer

    CenterPoint Energy confirms customer data stolen in cyberattack

    What happened

    CenterPoint Energy confirmed in an SEC filing that an unauthorized third party accessed customer personal information through an external-facing system, following a threat actor's claim of exfiltrating 7.49 million records. The attacker alleged they harvested the data by iterating through IDs on a public API that lacked rate limiting and web application firewall protections, though the utility has not yet disclosed the specific scope of compromised data or the exact number of affected customers.

    Why it ranks #10

    CenterPoint Energy confirmed in an SEC filing that an unauthorized third party accessed customer personal information through an external-facing system, following a threat actor's claim of exfiltrating 7.49 million records.

    Who should care

    CISOs and security leaders, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    sector
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email