Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Thursday, September 17, 2026

Here are today’s top cybersecurity stories for Thursday, September 17, 2026.

Cisco Patches Maximum-Severity Zero-Day Under Active Attack in Identity Services Engine
Cisco released emergency patches for CVE-2026-76460, a CVSS 10.0 authentication bypass in Identity Services Engine and ISE Passive Identity Connector, after confirming active exploitation. An attacker sends a single crafted request to an unprotected API endpoint and gains full administrative control of the appliance, with no workaround available. CISA added the flaw to its Known Exploited Vulnerabilities catalog with a September 19 remediation deadline for federal agencies. SecurityWeek

Revolut Faces $3 Million Ransom After Fake Government Requests Exposed Customer Data
Attackers compromised a government employee’s email account through an infostealer infection and used it over five months to send forged official requests to Revolut’s Lithuania-based banking subsidiary. The campaign exposed identity documents, contact details, and financial records for roughly 680 customers, many described as cryptocurrency holders. A group calling itself “iamnotavillain” demanded 6,000 Monero, worth about $3 million, and threatened to sell the data to other criminal groups. SecurityWeek

Japanese Image-Hosting Service Gyazo Discloses Breach Touching 23.6 Million Accounts
Helpfeel, operator of image-sharing platform Gyazo, confirmed an attacker exploited a flaw in its image upload server to run commands and reach its database on September 11. The intrusion exposed names, email addresses, password hashes, device IDs, and login sessions for 23.62 million users, along with 490 million image metadata records tied to older uploads. Helpfeel disabled viewing on some affected images and asked all users to change their passwords. The Hacker News

China-Aligned Group Swaps Backdoors to Expand Espionage Across Latin America
ESET researchers report the China-aligned threat actor FamousSparrow has replaced its longtime SparrowDoor implant with a new modular backdoor named SparroWocky across government targets in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The new tool runs commands, proxies traffic, and exfiltrates files and screenshots on a set schedule, with activity traced back to at least August 2025. ESET links the group to broader Salt Typhoon and Earth Estries infrastructure. The Hacker News

Coast Guard and FBI Board Tankers After Suspected Cyberattacks on Ship Systems
US Coast Guard and FBI personnel boarded two energy tankers bound for Texas last month after cyberattacks disrupted onboard systems during their voyage. One vessel, the Liberian-flagged VL Prosperity, lost communications for roughly 30 hours after attackers reportedly reached its fuel and engine-speed systems while transiting the Strait of Gibraltar. Investigators have not confirmed whether the two incidents connect or identified the responsible actor. SecurityWeek

FBI and RCMP Seize Domains Behind Long-Running DDoS-for-Hire Service
The FBI’s Anchorage field office and the Royal Canadian Mounted Police seized the domains behind NightmareStresser, one of the longest-running distributed denial-of-service booter services, as part of the international Operation PowerOFF campaign. Court filings describe hundreds of thousands of attacks launched against schools, government agencies, gaming platforms, and other targets worldwide since 2022. The action brings the multi-year operation’s total to more than 100 seized booter domains and 12 defendants charged. Help Net Security

CISA Retires Weekly Vulnerability Bulletin for Risk-Based Prioritization
CISA announced it will discontinue its weekly Vulnerability Bulletin on September 28, ending a product listing every newly recorded CVE alphabetically by product without exploitation context. The agency said the shift follows Binding Operational Directive 26-04, which directs federal agencies to prioritize vulnerabilities by real-world risk rather than raw severity scores. CISA will continue publishing risk-focused vulnerability data through its Known Exploited Vulnerabilities catalog, alerts, and advisories. SecurityWeek

CISA Publishes Guidance on Deploying Cyber Decoys for Critical Infrastructure
CISA released new guidance describing how critical infrastructure operators set up decoy systems, accounts, and data to detect and slow attackers inside their networks. The guidance outlines planning, deployment, and monitoring steps for deception technology alongside existing defenses. SecurityWeek

Docker Sandboxes Flaw Let Guest Code Escape to macOS Host Files
Docker disclosed CVE-2026-77179, a CVSS 9.4 flaw in the virtio-fs host server used by Docker Sandboxes on macOS. Malicious code inside a sandboxed virtual machine replaces a parent directory with a symlink and follows it out of the shared workspace to read or modify files anywhere on the host. Docker fixed the issue in version 0.42.0 on September 7 and reports no evidence of exploitation. The Hacker News

Attackers Exploit Hardcoded Key in Issabel PBX Framework for Remote Command Execution
Shadowserver observed active exploitation, starting September 9, of CVE-2026-89026, a critical flaw in the Issabel unified communications framework. A hardcoded JWT signing key shared across every installation lets an unauthenticated attacker forge a valid token and call an API endpoint reaching Asterisk’s command interpreter, resulting in arbitrary OS command execution. A patch has been available since August 1. The Hacker News

WordPress Plugin Flaw Draws Over 100,000 Exploit Attempts
Wordfence reports more than 100,000 attempts to exploit CVE-2026-27540, a CVSS 9.8 arbitrary file upload flaw in the WooCommerce Wholesale Lead Capture plugin, active on roughly 6,000 WordPress sites. An unauthenticated attacker uploads a PHP web shell through an unvalidated AJAX handler, gaining remote code execution on the underlying server. The developer patched the flaw in version 2.0.3.2 in February, and site owners are urged to update and check upload directories for unfamiliar PHP files. The Hacker News

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.