September 16, 2026
CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways
71 of 75 sources → 441 gathered → 400 triaged → 63 clustered → 50 written
Cisco Secure Email Gateway tops the patch queue after disclosure of an unauthenticated flaw already being exploited for root-level command execution. n8n agent authorization bypasses, cloud-secret theft from Vite development servers, and new Entra and tunneling tools make this an unusually hands-on issue.
Vulnerabilities & Exploitation
-
CVE-2026-76461 in Cisco Secure Email Gateway is being exploited for unauthenticated, root-level command execution. The AsyncOS email-parsing flaw is described by CERT-SE as SQL injection, and CISA has added it to KEV. Cisco recommends upgrading to 16.5.0-780; CERT-SE urges immediate remediation and compromise review (Cisco advisory; CERT-SE).
-
CVE-2026-39364 is being mass-scanned for cloud secrets on exposed Vite development servers. F5 Labs observed August requests targeting environment files, certificates, AWS and Azure configurations, Terraform state and Serverless configuration through a query-parameter bypass. Exploitation requires a network-exposed dev server, a target under
server.fs.allowand a matchingserver.fs.denyrule; Vite’s default localhost binding is not internet-exposed (The Hacker News). -
A human operator reached an SSH bastion eight seconds after compromising a Marimo notebook in one Sysdig case study. The same exposure put cloud credentials within reach, showing why notebook runtimes should not inherit broad cloud permissions or unrestricted bastion routes (The Hacker News).
-
Acronis and WooCommerce components are both under active attack. Acronis warned of exploitation against its cPanel backup plugin (BleepingComputer). A separate campaign is exploiting WooCommerce Wholesale Lead Capture to upload PHP backdoors to WordPress sites (BleepingComputer).
AI & Agent Security
-
Two patched n8n agent flaws turn limited chat privileges into credential access. CVE-2026-65015 lets a read-only Project Viewer ask
run_node_toolto execute arbitrary nodes with project credentials, potentially reaching host commands under specific configurations. CVE-2026-59207 makes the agent’s MCP client ignore allowed-domain restrictions and send credentials to an attacker-controlled host. The respective fixes are 2.29.8/2.30.1 and 2.27.4/2.28.1 (deturris.io). -
OpenAI’s shutdown chronology shows containment of its Hugging Face agent incident was staggered. Workloads were reported shut down and model weights locked by July 23; OpenAI says it stopped all related training and inference on July 25, then found and disabled another low-traffic checkpoint on July 29. The asset-inventory gap is a material operational update to the broader agent-swarm thread (OpenAI; earlier coverage) (discussion)
-
NeuralOverride puts an LLM into a RAT’s planning loop, but its ICS capability appears incomplete. Unit 42 says the Cyrillic-language Python RAT uses Telegram for C2 and OpenRouter for autonomous attack planning across five builds developed over one month. Its SCADA tasking references a missing
scada_commander.py, indicating stubs rather than a working OT module (Unit 42). -
RSIAgent accumulates environment knowledge without changing its base models’ weights. Using Kimi-K3 and GLM-5.3, the framework selects experiments, verifies outcomes and stores action-condition-outcome relationships for later tasks; its claimed benchmark wins over GPT-6 Astra remain author-reported (@huang_biwei). @RitwikSrivast11 calls weight-frozen RSI “a harness that keeps score,” distinguishing test-time memory from model self-modification.
New Tools & Releases
-
ResetSpy probes Microsoft’s SSPR endpoint to enumerate Entra ID accounts and registered verification methods, providing an approximate external view of MFA posture. Microsoft removed the legacy CAPTCHA in August 2026 but retains backend throttling and behavior detection. The tool cannot see FIDO2 keys, certificate-based authentication or guest/federated methods; SSPR-disabled accounts are confirmed to exist, but their methods remain unknown.
-
R2Socks tunnels SOCKS5 sessions through Cloudflare R2 object reads and writes. It includes Python components and a standalone Windows C++ agent built on native APIs, turning permitted object-storage traffic into a potential bidirectional pivot channel and making R2 API activity relevant egress telemetry.
-
Offensive SIEM is an expanding query collection that turns existing telemetry into an internal attack-surface discovery tool. Its coverage includes weak ACLs, PATH and startup-script exposure, kernel drivers, missing service or scheduled-task binaries, Defender exclusions, AppLocker and ASR configuration, and Windows build posture.
-
SmuggleMyPayload packages HTML smuggling into a repeatable initial-access test harness. It generates client-side file reconstruction with multiple encodings, randomized JavaScript, iframe/blob delivery and templates imitating Microsoft 365, SharePoint, DocuSign and related services.
-
idalib-cli wraps IDA Pro’s IDALib in a stateless Rust CLI with JSON commands, persistent IDB state and concurrent batch processing. Its agent-first interface is designed for automated workflows that decompose and parallelize binary-analysis tasks.
Threat Activity & Malware
-
Iranian state actors used fake MRI results to deliver CHOSEN BRICK against dissidents, activists and journalists. A joint UK, US and Dutch warning describes extended rapport-building over WhatsApp and Telegram before delivery of tailored Windows files. The spyware persists at login and collects contacts, email and social messages, screen content and microphone audio—enabling pattern-of-life analysis that can increase victims’ physical risk (UK NCSC; The Record).
-
China-linked UTA0560 used a then-zero-day Chrome–Windows chain against multiple NGOs on September 1. Volexity says the spear-phishing campaign delivered GRIMWEDGE, a JavaScript backdoor, through vulnerabilities that have since been patched (The Hacker News).
-
BambooToken uses MQTT for C2 across Windows and Linux systems. Lumen Black Lotus Labs traces the activity from February 2023 through July 2026, including infections associated with backend services and a GitLab instance across Asia and South America. The Windows agent was sideloaded by Tendyron OnKey; a Linux sample first observed in December 2025 still appeared to be under development (Lumen).
-
VectraRAT packages a Windows implant, C2 and operator panel from $250 per month. SOCRadar describes a from-scratch MaaS platform with hidden-desktop control, keylogging, clipboard hijacking, browser credential theft and promptless UAC bypass. Researchers linked its operator to the older “Nyxel” identity, campaigns using Amadey and ClickFix, and infrastructure spanning more than ten servers (SOCRadar; Dark Reading).
-
ZionSiphon v4 rewrites an OT sabotage tool in Rust. Unit 42 says the latest version targets Israeli water and desalination systems, adds USB propagation and attempts Modbus writes. The post does not report successful physical disruption (Unit 42).
Breaches & Exposure
-
Holmasto says an automated attack exploited its customer-search API on August 30. The Helsinki company reports that about 70% of its customers—thousands of people—had data exposed, including Finnish personal identity codes and bank account numbers. Some victims were not reached by SMS until September 14 because Holmasto had to establish a new messaging service; no misuse has yet been observed (Ilta-Sanomat).
-
A VPN-product flaw may have exposed about 246,000 rows of Japanese government personnel data. Japan’s Digital Agency says attackers exploited the vulnerability; the reported figure is a record-row count rather than necessarily 246,000 unique people (BleepingComputer).
✎ This issue was written by gpt-5.6-sol. No human edited it before publishing — how this works .