# Archive
Browse past daily curated stories
Friday, September 18, 2026
-
1The Hacker News generalCisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Cisco disclosed CVE-2026-76460, a CVSS 10.0 authentication bypass zero-day in Identity Services Engine (ISE) that allows unauthenticated remote attackers to bypass authentication via crafted API requests. This is the second actively exploited ISE zero-day disclosed in as many days, and ISE has now seen three actively exploited vulnerabilities since June 2025 — making it a critical priority for patching in enterprise environments.
-
2CyberScoop generalCisco alerts customers to second actively exploited zero-day in as many days
Cisco issued an emergency alert about a second maximum-severity zero-day in Identity Services Engine within a 24-hour window, underscoring a pattern of active exploitation targeting this product. Security teams running ISE should treat both vulnerabilities as urgent given confirmed in-the-wild exploitation and the product's central role in network access control.
-
3BleepingComputer generalBrevo supply-chain attack injected ClickFix scripts on customer sites
A supply-chain attack against email platform Brevo saw attackers steal a Cloudflare API key to inject malicious ClickFix scripts into Brevo's own websites and JavaScript files embedded on customer sites, enabling downstream malware distribution. The incident illustrates how a single stolen cloud service credential can propagate malicious payloads across thousands of third-party sites relying on shared JS assets.
-
4SecurityWeek generalCyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
The US Coast Guard and FBI physically boarded two oil tankers — including the supertanker VL Prosperity — after evidence of network compromise by foreign cyber actors, marking a rare kinetic response to maritime cyber incidents. The Coast Guard confirmed malicious cyber activity on the VL Prosperity but has not formally attributed the attack, while the vessels were US-bound through the Gulf of Mexico.
-
5The Hacker News generalCritical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
Check Point disclosed a critical unauthenticated remote code execution vulnerability in its Security Management Server and Log Server products, allowing network-accessible attackers to run arbitrary code as root without credentials. Check Point has released a fix via its LivePatch channel and reports no evidence of exploitation in the wild, but the affected system controls firewall policy and administrator access — making it a high-value target.
-
6The Hacker News generalChina-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
China-aligned APT FamousSparrow has deployed a new modular C++ backdoor called SparroWocky against government organizations across Latin America since at least August 2025, according to ESET researchers Alexandre Côté Cyr and Romain Dumont. The campaign aligns with growing US-China competition for influence in the region and represents a previously unreported toolset from this established espionage actor.
-
7The Hacker News generalGyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
Image-sharing platform Gyazo suffered a breach exposing approximately 23.62 million user records — including email addresses and password hashes — along with roughly 490 million image metadata records, primarily for images from January 2019 or earlier. Kyoto-based parent company Helpfeel disclosed the incident Wednesday; the scale of metadata exposure creates significant privacy risk through enumerable image link IDs.
-
8SecurityWeek generalRevolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Revolut allegedly had customer data fed to hackers over a five-month period, with attackers impersonating an Italian government agency to extract information on 680 high-profile accounts and subsequently demanding a $3 million ransom. The extended duration of the breach before detection is a significant red flag for social-engineering-based insider threat scenarios targeting financial institutions.
-
9The Hacker News generalBIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
ISC released BIND 9.20.29 and 9.21.26 on September 16 to fix 14 security flaws, including an unauthenticated crash vulnerability affecting any BIND server configured with DNS-over-HTTPS — a single malformed SIG record is sufficient to kill the named process. Additionally, CVE-2026-81642 is a critical heap overflow in the DNSSEC validator in Unbound before version 1.26.1 that enables RCE via a malicious DNS zone.
-
10The Hacker News generalIran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
Iran-linked hacktivist persona Handala Hack has been attributed to HEAVYGRAM, a Telegram-based surveillance backdoor built with capabilities including remote command execution, credential and session file exfiltration, screenshot capture, DLL sideloading, and Telegram session hijacking, alongside a Delphi-based utility called CRUDEEXCLUDE. The attribution links a politically motivated persona to sophisticated persistent access tooling, raising the operational threat level of what had appeared to be a hacktivist group.