Daily Cybersecurity Intelligence - September 16, 2026
Daily cybersecurity intelligence digest from CyberNetSec.io - September 16, 2026 ๐ 9 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories. 1. Cisco Patch
Daily cybersecurity intelligence digest from CyberNetSec.io - September 16, 2026
๐ 9 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. Cisco Patches Critical RCE Zero-Day in Secure Email Gateway
Cisco has released an emergency patch for a critical zero-day vulnerability, CVE-2026-76461, in its Secure Email Gateway appliances. The flaw, a CVSS 9.8 SQL injection, is under active exploitation, allowing unauthenticated attackers to gain root-level remote code execution. The vulnerability affects physical, virtual, and cloud-based gateways. CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, mandating immediate action for federal agencies and urging all customers to apply updates.
2. Google Fixes Exploited Pixel Modem Flaw CVE-2026-58704
Google has released its September 2026 security update for Pixel devices, patching a high-severity zero-day vulnerability (CVE-2026-58704) in the cellular modem. The flaw, a privilege escalation issue, is reportedly under limited, targeted exploitation. It allows a remote attacker in proximity to the device to escalate privileges without user interaction. CISA has added the vulnerability to its KEV catalog, urging federal agencies to patch by September 19, 2026.
3. WSO2 API Flaw (CVE-2026-5430) Actively Exploited
A critical authentication bypass vulnerability, CVE-2026-5430, in WSO2's widely used API management platform is being actively exploited in the wild. The flaw, which has a CVSS score of 10.0, allows unauthenticated attackers to forge JWT tokens, take over administrator accounts, and access sensitive backend credentials and data. The vulnerability was patched in April 2026, but security researchers have now detected active exploitation attempts, making it urgent for organizations to verify they are patched.
4. APT31 and UTA0560 Exploit Chrome Zero-Day CVE-2026-85046
Two distinct China-linked threat actors, UTA0560 and JungleBamboo (APT31), were observed exploiting the same Google Chrome zero-day vulnerability, CVE-2026-85046, in separate espionage campaigns. The attacks, which began around September 1, 2026, targeted non-governmental organizations (NGOs) before Google had released a patch. The shared use of the exploit chain suggests it may have been developed by a third party and sold to both groups, highlighting a sophisticated cyber weapon supply chain.
5. CISA Warns of Critical Flaws in OT/ICS Systems
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published several advisories for critical vulnerabilities in operational technology (OT) and industrial control systems (ICS). The flaws affect Digital Watchdog DVRs/NVRs used in surveillance and Wรคrtsilรค onboard ship systems used in the maritime sector. Some vulnerabilities carry CVSS scores as high as 9.6 and could allow for full system takeover, highlighting ongoing risks to critical infrastructure.
6. Parallels Desktop Flaw 'ParaShells' Gives macOS Root Access
A high-severity local privilege escalation vulnerability, CVE-2026-90894 or "ParaShells," has been found in Parallels Desktop for Mac. The flaw allows any local user, including those with standard, non-administrative privileges, to escalate their access to full root control over the host macOS system. The vulnerability has been patched by Alludo in Parallels Desktop v27.0.0, and users are strongly urged to update.
7. JetFormBuilder Flaw CVE-2026-12793 Allows Admin Takeover
A critical privilege escalation vulnerability, CVE-2026-12793, has been found in the JetFormBuilder WordPress plugin, affecting all versions up to 3.6.2. The flaw, rated 9.8 on the CVSS scale, allows unauthenticated attackers to create new administrator-level user accounts on affected websites by submitting a crafted request. With a public exploit reportedly available, administrators are urged to update the plugin immediately to prevent a complete site takeover.
8. Click2Mail Data Breach Exposes Customer Financial Data
C2M LLC, which operates the online postal mail service Click2Mail, has disclosed a data breach that exposed customer financial information. According to a notification filed with the Vermont Attorney General, the compromised data includes financial account codes and credit and debit card information. The full scope and timeline of the breach have not yet been made public, but affected individuals are at risk of financial fraud.
9. Atomic macOS (AMOS) Stealer Activity Analysis
An analysis of the Atomic macOS (AMOS) Stealer reveals its evolving tactics for compromising Apple systems. Threat actors are using deceptive websites with fake setup instructions to trick users into manually executing malicious scripts. This method bypasses some traditional defenses and allows the stealer to harvest system information, browser credentials, and cryptocurrency wallet data. The malware's infrastructure, including C2 servers and domains, changes frequently, making detection challenging. This report breaks down the infection chain from an August 2026 case, providing technical details, indicators of compromise, and mitigation strategies for defenders.
๐ Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes โ full credit and traffic to the original publisher.