Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 17, 2026

Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint that lets a remote unauthenticated attacker bypass the web management interface; the fix requires upgrading to 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4, and no workarounds exist. The Shadowserver Foundation separately observed active exploitation of CVE-2026-89026 in Issabel Framework, where a hard-coded HS256 JWT signing key in pbxapi/index.php lets an unauthenticated attacker forge bearer tokens and execute arbitrary OS commands as the Asterisk user; a patch shipped August 1, 2026, replaces the key with one stored in /etc/issabel.conf.

Compiled by the Slugnet Editorial System. Published Sep 17, 2026, 7:45 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    Help Net Security

    Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

    What happened

    Cisco confirmed that unauthenticated attackers are actively exploiting CVE-2026-76460, an authentication bypass vulnerability in an API endpoint of Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector. By sending a crafted request to this endpoint, remote attackers can bypass the web-based management interface to gain unauthorized access to affected devices running releases 3.0 through 3.5. Cisco advises customers to upgrade to the latest fixed patches, as no workarounds exist for this flaw.

    Why it ranks #1

    Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in ISE API endpoints allowing unauthenticated remote access to management interfaces on versions 3.0 through 3.5.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    Upgrade to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4, as no workarounds address this vulnerability.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    product
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

    What happened

    VulnCheck reported that the Issabel Framework contains a hard-coded HS256 JWT signing key in the pbxapi index.php file, which allows unauthenticated remote attackers to forge valid bearer tokens and execute arbitrary operating system commands via the manager '/pbxapi/manager/originate' endpoint. The vulnerability stems from a hard-coded JSON Web Token signing key that is identical across all installations, enabling attackers to forge valid bearer tokens and access the Asterisk manager endpoint. A patch released on August 1, 2026, resolves the issue by replacing the static key with a unique value stored in the configuration file.

    Why it ranks #2

    VulnCheck reported that the Issabel Framework contains a hard-coded HS256 JWT signing key in the pbxapi index.php file, allowing unauthenticated remote attackers to forge valid bearer tokens and execute arbitrary operating system commands via the manager '/pbxapi/manager/originate' endpoint.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    What to do

    Users of the Issabel Framework are advised to apply the latest fixes for optimal protection.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    BleepingComputer

    Critical ScreenConnect flaw now actively exploited in attacks

    What happened

    CISA reported that attackers are actively exploiting a critical-severity vulnerability in ConnectWise ScreenConnect. The agency's advisory confirms the flaw is being used in the wild, though the provided source text does not specify the CVE identifier or technical details of the exploit.

    Why it ranks #3

    CISA reported that attackers are actively exploiting a critical-severity vulnerability in ConnectWise ScreenConnect, though the agency's advisory does not specify the CVE identifier or technical details of the exploit.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    medium
    Scope
    enterprise
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    The Hacker News

    Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

    What happened

    Acronis confirmed that exploitation of CVE-2026-87886, a local privilege escalation vulnerability in its cPanel and Plesk backup plugins, has been detected in the wild in limited, targeted attacks. Acronis advises users to install the 1.9.3 HF3 update, which the vendor states contains fixes for the high-severity security vulnerability, while CISA added CVE-2026-87886 to its Known Exploited Vulnerabilities catalog on September 16, 2026.

    Why it ranks #4

    Acronis confirmed limited, targeted exploitation of CVE-2026-87886, a local privilege escalation flaw in its cPanel and Plesk backup plugins, prompting a vendor patch and CISA catalog addition.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    What to do

    Apply the latest Acronis backup plugin updates immediately to maintain protection.

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    Help Net Security

    Fake AI trading agent steals crypto wallet passwords

    What happened

    HP identified a campaign using a fake AI trading agent to install Needle Stealer, which replaces browser wallet extensions with malicious copies that exfiltrate passwords to attackers. The malware targets users of seven extensions, including MetaMask and Coinbase Wallet, by leveraging DLL side-loading and process hollowing to execute within legitimate processes.

    Why it ranks #5

    HP identified a campaign deploying a fake AI trading agent to install Needle Stealer, which uses DLL side-loading and process hollowing to replace legitimate browser wallet extensions with malicious copies that exfiltrate passwords.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    BleepingComputer

    Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

    What happened

    Government agencies issued a joint advisory warning that Iranian state-linked actors are deploying CHOSEN BRICK, a Windows malware strain designed to spy on dissidents, activists, and journalists. The malware establishes persistence via Windows Registry Run keys and uses a unique Telegram bot for command-and-control, enabling it to record audio, capture screenshots, and exfiltrate communications from WhatsApp, Telegram, and email.

    Why it ranks #6

    Government agencies issued a joint advisory warning that Iranian state-linked actors are deploying CHOSEN BRICK, a Windows malware strain designed to spy on dissidents, activists, and journalists.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    sector
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    The Hacker News

    One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

    What happened

    Forever Security demonstrated that a single browser extension with standard permissions can hijack the built-in AI assistants in Chrome, Edge, Opera Neon, and Claude. By injecting code into the trusted web pages these agents monitor, the extension can command the AI to read local files, access camera and microphone feeds, or execute actions on the user's behalf. Google and Microsoft have patched the identified flaws in Chrome 143.0.7499.192 and Edge 150.0.4078.48, respectively.

    Why it ranks #7

    Forever Security demonstrated a single browser extension can hijack AI assistants in Chrome, Edge, Opera Neon, and Claude by injecting code into trusted pages, prompting vendors to patch the flaws.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    The Hacker News

    Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

    What happened

    Kaspersky reports that three threat groups—NightEagle, Hacking Cat, and Toy Ghouls—are deploying backdoors, ransomware, and wipers against Russian enterprises. NightEagle uses GhostContainer to access Microsoft Exchange servers, while Hacking Cat deploys Gorilla RAT and Monkey ransomware, and Toy Ghouls utilizes a new custom backdoor that communicates via MQTT and Matrix.

    Why it ranks #8

    Kaspersky reports three threat groups deploying backdoors, ransomware, and wipers against Russian enterprises, with specific tools including GhostContainer, Gorilla RAT, and a custom MQTT-based backdoor.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    The Hacker News

    Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

    What happened

    Mandiant reported that an attacker hijacked an active AI coding-assistant session at an unnamed SaaS provider to install an infostealer via a poisoned PyPI package. The intruder subsequently deployed the Shai-Hulud worm across approximately 100 internal code repositories, stealing source code and GitHub OAuth tokens.

    Why it ranks #9

    Mandiant reported that an attacker hijacked an active AI coding-assistant session at an unnamed SaaS provider to install an infostealer via a poisoned PyPI package, subsequently deploying the Shai-Hulud worm across approximately 100 internal code repositories to steal source code and GitHub OAuth tokens.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    The Hacker News

    BambooToken Malware Uses MQTT to Control Windows and Linux Systems

    What happened

    Lumen Black Lotus Labs disclosed BambooToken, a multi-platform malware family active since 2023 that uses the MQTT protocol for command-and-control to target organizations in Asia and South America. Lumen Black Lotus Labs reported that subsequent versions of the BambooToken malware sideload a rogue OnKeyToken_KEB.dll into the Tendyron OnKeySrv program to enumerate the host and use MQTT for command-and-control, while the malware’s antivirus plugin uses WMI to gather and exfiltrate details about installed antivirus products on Windows machines.

    Why it ranks #10

    Lumen Black Lotus Labs disclosed BambooToken, a multi-platform malware family active since 2023 that uses the MQTT protocol for command-and-control to target organizations in Asia and South America.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email