# Archive
Browse past daily curated stories
Tuesday, September 15, 2026
-
1SecurityWeek generalRoot RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
CVE-2026-76461 is an unauthenticated remote code execution zero-day in Cisco Secure Email Gateway that allows attackers to execute arbitrary commands with root privileges on the underlying OS. The vulnerability is under active exploitation, making immediate patching or mitigation critical for organizations relying on Cisco's email security appliances.
-
2Dark Reading generalMaximum Severity GitLab Flaw Puts Supply Chains at Risk
CVE-2026-85706 is a CVSS 10.0 path traversal vulnerability affecting both GitLab Community Edition and Enterprise Edition, and CISA has confirmed active exploitation in the wild. The maximum severity score and GitLab's widespread use in software development pipelines makes this a critical supply chain risk requiring immediate patching.
-
3BleepingComputer generalCISA: Hackers now exploit max severity GitLab flaw in attacks
CISA issued a warning that threat actors are actively exploiting CVE-2026-85706, the maximum-severity GitLab path traversal flaw, in real-world attacks against internet-facing GitLab instances. Organizations running unpatched GitLab CE or EE deployments should treat this as an emergency remediation priority given CISA's active exploitation confirmation.
-
4Dark Reading general'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
Russian APT group Sandworm is chaining Cisco vulnerabilities to deploy an upgraded variant of the Cyclops Blink botnet malware, which the FBI previously disrupted in 2022. The revival and enhancement of Cyclops Blink by a nation-state actor signals a persistent threat to network infrastructure operators using vulnerable Cisco devices.
-
5The Hacker News generalRed Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
Chinese threat actor Red Heron exploited a recently disclosed Gitea RCE vulnerability to scan 1,386 Gitea instances across seven countries, successfully compromising 13 organizations across six countries, with a separate dataset of 477 Taiwan-based systems maintained. Acronis Threat Research Unit attributed the multi-national campaign, underscoring the rapid weaponization of self-hosted Git platform vulnerabilities by state-aligned actors.
-
6SecurityWeek generalThree JFrog Artifactory Flaws Exploited for Backdoor Deployment
Three vulnerabilities in JFrog Artifactory are being actively exploited to deploy backdoors, with attackers leveraging authentication bypass and privilege escalation flaws to reach administrator-level access. JFrog Artifactory is widely used in enterprise software build pipelines, making exploitation of these flaws a significant supply chain threat.
-
7SecurityWeek generalConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
ConnectWise has patched a ScreenConnect vulnerability that allows unauthenticated file transfer and execution through active remote sessions, with exploitation observed in worm-like attack campaigns. ScreenConnect's broad deployment in managed service provider environments amplifies the potential blast radius of this flaw.
-
8BleepingComputer generalRevolut discloses data breach exposing financial info, passports
Fintech company Revolut disclosed a data breach in which an undisclosed number of customers had financial information and passport data exposed after the company inadvertently shared data with a threat actor impersonating a government agency via a legitimate government email account. The incident demonstrates the risk of emergency data request abuse as a social engineering vector against financial institutions.
-
9The Hacker News generalNew DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers disclosed DDRop, a new hardware attack that defeats memory protection in both Intel TDX and AMD SEV-SNP confidential computing environments by silently dropping memory writes, causing processors to read stale encrypted data. The attack requires brief physical access and server-level software control, threatening the integrity guarantees that cloud providers rely on for trusted execution environments.
-
10Schneier on Security threat-intelMicrosoft’s Patching
Microsoft's September 2026 Patch Tuesday set a record with approximately 972 vulnerabilities fixed, including 112 rated critical-severity, surpassing the previous record of 620 set just last month. The accelerating patch volume — up from 570 in July — places severe strain on enterprise patch management programs and underscores the growing complexity of the Windows attack surface.