Here are today’s top cybersecurity stories for Tuesday, September 15, 2026.
Cisco Secure Email Gateway Zero-Day Under Active Exploitation
Cisco confirmed a zero-day flaw in Secure Email Gateway appliances is under active exploitation. CVE-2026-76461, rated CVSS 9.8, is an email-parsing issue in Cisco’s AsyncOS software, letting an unauthenticated attacker send a specially crafted email containing malicious SQL statements to execute arbitrary commands with root privileges. CISA added the flaw to its Known Exploited Vulnerabilities catalog Monday, with a September 17 deadline for federal agencies. It marks only the second Cisco Secure Email Gateway flaw added to the KEV catalog, after a China-linked campaign exploited a separate bug in late 2025. SecurityWeek
Ransomware Gangs Join Ongoing VMware vCenter Exploitation Campaign
CISA updated its Known Exploited Vulnerabilities catalog entry for CVE-2026-59310, a critical directory traversal flaw in VMware vCenter’s Syslog server, warning ransomware operators now exploit the bug alongside a suspected China-nexus group already using it for backdoor access. Attackers deployed reverse_ssh binaries for persistent access and, in at least one case, followed up with Babuk-derived ransomware. The campaign has compromised 361 unique victim IP addresses across 47 countries, with the heaviest concentrations in Germany, the United States, and Turkey. Broadcom patched the flaw on July 29. BleepingComputer
Two China-Linked Groups Chain Chrome and Windows Zero-Days Against NGOs
Volexity is tracking two separate China-linked threat clusters, UTA0560 and JungleBamboo, independently exploiting the same Chrome and Windows kernel zero-day chain since September 1. Spear-phishing emails direct targets to legitimate university websites vulnerable to cross-site scripting, which redirect victims to attacker-controlled pages exploiting CVE-2026-85046, CVE-2026-87491, and Windows kernel flaw CVE-2026-85880. The intrusions install either a JScript backdoor named GRIMWEDGE or a credential-stealing browser extension named LONGTALE. Byte-for-byte identical exploit code across both unrelated actors points to a shared exploit broker or supply chain. The Hacker News
Phishing Campaign Hides Keywords With Invisible Unicode Characters
Microsoft researchers documented a large-scale phishing campaign inserting invisible Unicode tag characters inside finance-related words to evade keyword-based email filters, at its peak sending 2.37 million messages in a single day. A word such as “funding” gets split by a hidden character from the Unicode Tags block, most often U+E0020, so the term no longer matches filter word lists while still rendering normally to the reader. Microsoft identified 148 finance-themed sender domains behind roughly 96 percent of flagged messages, and says Defender for Office 365 still blocks the large majority through other detection signals. The Hacker News
Exposed Server Reveals Live Intrusion Toolkit at Thai Broadband Provider
Researchers at Hunt.io discovered an open directory hosting the full toolkit behind an active breach of Thai broadband provider 3BB (Triple T Broadband), reached through FortiGate SSL-VPN flaw CVE-2024-21762. The exposed cache held 298 files across 30 subdirectories, including brute-force and privilege-escalation scripts, a MeshCentral remote-access backdoor, and a list of compromised machines built around RADIUS subscriber credentials. The attacker also staged scripts to erase evidence while preserving access. SecurityWeek
Researcher Releases Three New Zero-Day Exploits for Security Software
A researcher known for past Microsoft Defender bypasses released three new privilege-escalation exploits targeting endpoint and system software from other vendors. PrettyPrague targets an Avast sandbox component and spawns a shell with full system privileges, an issue also present in related GenDigital products AVG and Norton. FalconFlank abuses a macro-remediation feature inside the CrowdStrike Falcon sensor for local privilege escalation, and GreenSection exploits an out-of-bounds write in shared memory used across multiple Nvidia components. Gen Digital patched the Avast flaw, CrowdStrike shipped a temporary mitigation, and Nvidia says it continues investigating. SecurityWeek
LiteSpeed Enterprise Flaw Lets One Hosting Account Reach Root
A privilege-escalation flaw in LiteSpeed Enterprise web server software, versions before 6.3.7, lets a low-privilege website account on a shared hosting server escalate to root access, exposing every other site on the same host. No CVE identifier had been assigned to the flaw as of publication. Site administrators on shared hosting platforms are advised to confirm their LiteSpeed version and apply the vendor’s update once available. The Hacker News
Microsoft Publishes Draft Code of Conduct for AI Cyber Capabilities
Microsoft AI released a draft “Humanist AI Code of Conduct” for its MAI models, setting boundaries around offensive cyber use, a defined chain of command for high-risk actions, and limits on autonomous agent behavior. The draft arrives after a string of incidents this year tying AI agents to intrusion campaigns and vulnerability research, including autonomous agents linked to the RubyGems package registry attack earlier this year. Microsoft opened the draft for public comment ahead of finalizing the policy. SecurityWeek
Japan’s Digital Agency Discloses Breach of 240,000 Records
Japan’s Digital Agency disclosed a breach affecting personal information tied to roughly 240,000 individuals, discovered in late June after unusual activity surfaced on internal systems. Investigators traced the access to a maintenance employee’s account, reached after attackers exploited a flaw in a VPN product used by the agency. The agency has not named the affected VPN vendor and says it is still assessing the scope of exposed data. SecurityWeek
Stay tuned for today’s in-depth analysis posts.






