Skip to content

Sam's News โ€” security โ€” 2026-09-15

Security

8.5 Cisco Secure Email Gateway zero-day enables root command execution under active attack

Cisco disclosed a critical zero-day vulnerability (CVE-2026-76461, CVSS 9.8) in Secure Email Gateway that allows unauthenticated attackers to execute arbitrary commands with root privileges via malicious email messages. The flaw is actively being exploited in the wild and affects both physical and virtual devices; patching is required as no workarounds exist.

  • CVE-2026-76461, CVSS 9.8 severity
  • Unauthenticated remote root command execution via email
  • Actively exploited in the wild
  • Fixed versions: AsyncOS 15.5.5-0141, 16.0.4-302, 16.5.0-780
  • CISA requires Federal agencies to patch by September 17, 2026
  • CVE-2026-76461 (CVSS 9.8): critical vulnerability in AsyncOS email handling
  • Unauthenticated remote code execution via malicious email
  • Active exploitation detected September 2026; cloud customers targeted and upgraded
  • No workarounds; patching to AsyncOS 16.5.0-780 required mitigation
  • Attackers with root access can tamper with logs to cover tracks

Sources: The Hacker News AI Web Searched, SecurityWeek RSS, Cybernews RSS, BleepingComputer RSS, The Register AI Web Searched

8 Apple Releases iOS 27 and macOS Golden Gate 27 Patching 200 Vulnerabilities

Apple released iOS 27, iPadOS 27, and macOS Golden Gate 27 on September 15, 2026, patching over 200 combined vulnerabilities including kernel memory corruption and privilege escalation flaws across more than 90 platform components. Notable fixes include CVE-2026-64752, a CoreMedia memory corruption issue resolved by removing the flawed code entirely.

  • Release date: September 15, 2026
  • iOS 27 and iPadOS 27: ~126 vulnerabilities (20 kernel flaws)
  • macOS Golden Gate 27: 210 vulnerabilities (~100 shared with iOS)
  • ~100 vulnerabilities affect both mobile and desktop platforms
  • CVE-2026-64752 (CoreMedia): flawed code removed entirely rather than patched

Sources: SecurityWeek AI Web Searched

8 Admin Menu Editor Pro plugin compromised; 1,500 WordPress sites backdoored

Malicious versions of the Admin Menu Editor Pro WordPress plugin were distributed to over 200 customers after an attacker compromised the developer's website, creating hidden backdoor accounts on approximately 1,500 sites.

Sources: BleepingComputer RSS

7.5 Critical LiteSpeed Web Server Vulnerability Allows Root Access on Shared Hosting

LiteSpeed Web Server Enterprise contains a critical vulnerability allowing low-privileged website users to gain root access on shared hosting servers by bypassing file system isolation controls including CageFS. Version 6.3.7, released September 11, 2026, addresses the flaw; manual installation is recommended over auto-update.

  • Affects versions before 6.3.7 released September 11, 2026
  • Low-privileged user to root privilege escalation
  • Bypasses CageFS file system isolation
  • Third root-access vulnerability in LiteSpeed since May 2026
  • OpenLiteSpeed (open-source) unaffected as of September 15

Sources: The Hacker News AI Web Searched

7.5 Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE Backdoor

Chinese threat actor UTA0560 exploited a three-zero-day chain in Chrome and Windows to deliver the GRIMWEDGE JavaScript backdoor targeting NGOs. The attack chain included Chrome sandbox escape, Windows privilege escalation, and an XSS vulnerability, delivering backdoor malware capable of reconnaissance, file management, and command execution.

  • Three zero-day vulnerabilities: CVE-2026-85046, CVE-2026-87491, CVE-2026-85880
  • GRIMWEDGE JavaScript backdoor with host reconnaissance and file management
  • Spear-phishing campaign September 1, 2026 targeting NGOs
  • Three-stage exploit chain called BlueMoon
  • Persistence via MSI installer with obfuscated JavaScript

Sources: The Hacker News AI Web Searched

7.5 BambooToken Malware Exploits MQTT to Control Windows and Linux Systems

Researchers at Lumen Black Lotus Labs disclosed BambooToken, an emerging multi-platform malware family active since at least February 2023 that uses the MQTT protocol for command-and-control of Windows and Linux systems. Initial access is achieved through DLL sideloading of Tendyron's OnKey PKI security token software; most samples originate from Chinese IP space and target organizations across Asia and South America.

  • Malware: BambooToken, active since Feb 2023, discovered on VirusTotal early 2026
  • Platforms: Windows and Linux; C2 via MQTT protocol
  • Initial access: DLL sideloading of Tendyron OnKey software (PKI USB token)
  • Targets: organizations in Asia and South America
  • Most samples from Chinese IP space; latest activity July 2026

Sources: The Hacker News AI Web Searched, BleepingComputer RSS

7.5 KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials

Elastic Security Labs disclosed KREMLIN, a Brazilian banking malware toolkit active since May 2025 that hijacks Chrome and Edge browsers to steal credentials and session tokens. The multi-stage attack uses JavaScript loaders, custom C++ installers, and malicious browser extensions impersonating a dozen Brazilian banks and exploits blockchain-based Ethereum smart contracts as dead drop resolvers for dynamic C2 updates.

  • Malware: KREMLIN (REF9334), active since May 2025
  • Targets: Brazilian banks via fake banking/invoice/company documents in Portuguese
  • Browser extensions targeted: Chrome and Edge, extension ID ndpbidppejfanjbhfgjlohfanbfbklff
  • Uses Ethereum smart contracts as dead drop C2 resolvers for endpoint updates
  • Sandbox/VM evasion; DLL sideloading via SentinelOne binary; credential/token theft

Sources: The Hacker News AI Web Searched

7.5 CenterPoint Energy confirms breach affecting 7.5 million customer records

Texas utility company CenterPoint Energy has confirmed a data breach in which a hacker claims to have stolen 7.5 million customer records.

Sources: SecurityWeek RSS

7.5 CISA warns ransomware gangs now exploiting critical VMware vCenter flaw

The U.S. Cybersecurity and Infrastructure Security Agency reports that ransomware groups are actively exploiting a critical VMware vCenter vulnerability patched in July.

Sources: BleepingComputer RSS

Cybersecurity & Human Rights

7.5 Iranian Intelligence Uses Telegram-Controlled Malware to Spy on Dissidents and Journalists

U.S., U.K., and Netherlands cybersecurity agencies identified Windows malware attributed to Iran's Ministry of Intelligence and Security (MOIS) used to surveil dissidents, journalists, and activists globally via Telegram. The malware (HEAVYGRAM/CHOSEN BRICK) can copy emails and messages, take screenshots, and record audio; confirmed targeting spans the U.S., U.K., and Netherlands since at least 2025, with the campaign dating to autumn 2023.

  • Malware: HEAVYGRAM (FBI) / CHOSEN BRICK (UK NCSC), attributed to Iran MOIS
  • Campaign active since autumn 2023; confirmed targeting since 2025
  • Targets: dissidents, journalists, activists in U.S., U.K., Netherlands
  • Telegram-controlled; capabilities: email/message copy, screenshots, audio recording
  • Attack vectors: social engineering, fake apps (Pictory, KeePass, Telegram, RunwayML, Norton, Adobe, MRI scans)

Sources: The Hacker News AI Web Searched, The Record RSS