# Today's Top Stories
September 16, 2026
-
1The Hacker News general Sep 15Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Cisco's AsyncOS Software for Secure Email Gateway contains CVE-2026-76461 (CVSS 9.8), a critical unauthenticated RCE vulnerability in the email parsing logic that enables root command execution and is already being actively exploited in the wild. Security teams running Cisco Secure Email Gateway appliances should treat this as an emergency patch priority given the zero-day exploitation status and the severity of the attack surface — internet-facing email infrastructure.
-
2BleepingComputer general Sep 15Cisco patches Secure Email Gateway zero-day exploited in attacks
Cisco confirmed active exploitation of a critical zero-day in its Secure Email Gateway before the vulnerability was disclosed or patched, though the company has not detailed the attack scope or nature of the campaigns. Defenders should apply the patch immediately and audit email gateway logs for indicators of compromise, as unauthenticated attackers can leverage the flaw for root-level access.
-
3BleepingComputer general Sep 15CISA: Critical VMware RCE flaw now exploited by ransomware gangs
CISA confirmed that ransomware groups are now actively exploiting a critical VMware vCenter RCE vulnerability that was patched in July 2026, escalating the threat level for unpatched vCenter environments. Organizations still running vulnerable vCenter instances face immediate ransomware exposure, as threat actors have moved from targeted attacks to broader ransomware deployment using this flaw.
-
4The Hacker News general Sep 15China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
Volexity attributed a September 1, 2026 spear-phishing campaign to Chinese threat actor UTA0560, which chained patched zero-days in Google Chrome and Microsoft Windows to deliver a JavaScript backdoor called GRIMWEDGE against multiple NGOs. The use of a Chrome-Windows exploit chain against civil society targets underscores the ongoing risk of nation-state actors leveraging browser-plus-OS zero-day combinations for targeted espionage.
-
5SecurityWeek general Sep 15Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases
Apple's iOS 27 and macOS Golden Gate 27 releases patch approximately 200 vulnerabilities, including kernel flaws leading to memory corruption, privilege escalation, system termination, and information leakage. Security teams managing Apple device fleets should prioritize deployment of these updates given the breadth of kernel-level issues addressed.
-
ADSponsoredProtect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected → -
6The Hacker News general Sep 15Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
A joint advisory from US, UK, and Netherlands cybersecurity agencies detailed an Iranian intelligence-operated Windows malware controlled via Telegram that exfiltrates emails, chat messages, and screenshots, and activates the microphone to surveil dissidents, journalists, and activists worldwide. The Telegram-based C2 mechanism is notable for its operational security appeal to state actors and its targeting of high-risk individuals rather than traditional corporate networks.
-
7BleepingComputer general Sep 15Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
A threat actor compromised the maintainer's website for the Admin Menu Editor Pro WordPress plugin and pushed malicious updates to over 200 customers, resulting in backdoored installations across approximately 1,500 WordPress sites with hidden admin accounts created for persistent access. This supply-chain-style attack on a premium plugin highlights the risk of automatic plugin updates in WordPress environments where the upstream vendor's own infrastructure is compromised.
-
8BleepingComputer general Sep 14Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
Japan's Digital Agency disclosed a data breach caused by exploitation of a vulnerability in a VPN product, potentially exposing approximately 246,000 rows of personal information belonging to government employees. The breach at a central government digital authority is significant both for the scale of records exposed and as a demonstration of VPN infrastructure remaining a high-value attack surface against public sector targets.
-
9CyberScoop general Sep 15Cisco warns customers of actively exploited zero-day in email gateways
Cisco confirmed that a zero-day vulnerability in its Secure Email Gateway appliances was exploited in the wild before the company disclosed or patched it, though Cisco declined to describe the nature of the attacks or how many customers were impacted. The pre-patch exploitation window makes this a critical incident for organizations relying on Cisco email security infrastructure for perimeter defense.
-
10The Hacker News general Sep 15KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Elastic Security Labs identified a Brazilian banking malware operation tracked as REF9334, active since at least May 2025, delivering a toolkit called KREMLIN that installs malicious browser extensions on Google Chrome and Microsoft Edge to steal credentials and session tokens from users of approximately a dozen Brazilian banks. The MaaS-style operation's use of browser extension hijacking to bypass credential protections represents a growing threat vector for financial sector defenders in Latin America and beyond.