Cybersecurity News | Daily Recap [15 Sep 2026]

Cybersecurity News | Daily Recap [15 Sep 2026]
Daily Recap, Cisco patched an actively exploited Secure Email Gateway zero-day that enables command execution as root, while China-linked actors chained a Chrome-Windows zero-day to deploy GRIMWEDGE. Attackers also targeted WooCommerce/WordPress via a third-party plugin, abused exposed Vite dev servers for AWS/Azure secrets, and leveraged a Telegram Desktop HTML export flaw to exfiltrate messages, alongside ongoing ransomware exploitation of a VMware vCenter RCE flaw.
#Cisco #GRIMWEDGE #WooCommerce #WordPress #Vite #AWS #Azure #TelegramDesktop #VMwarevCenter #ClickFix #PasteSwitch #DDROP #BlackAxe

Exploits & Malware

  • Cisco patched an actively exploited Secure Email Gateway zero-day that lets attackers run commands as root, while China-linked threat actors chained a Chrome-Windows zero-day to deploy GRIMWEDGE. – Cisco Zero-Day, Chrome Chain
  • Attackers are abusing a third-party WooCommerce plugin to hit WordPress sites, targeting exposed Vite dev servers for AWS/Azure secrets, and using a hidden JavaScript flaw in Telegram Desktop HTML exports to exfiltrate messages. – WooCommerce Attack, Vite Secrets, Telegram Flaw
  • A Fortinet vulnerability was used to compromise a Thai broadband provider, and a separate 3BB intrusion involved a MeshCentral backdoor to gain root access and steal subscriber credentials. – Fortinet Breach, 3BB Backdoor
  • Researchers say a new DDROP attack can break confidential computing on Intel TDX and AMD SEV-SNP, undermining protected workloads. – DDROP Attack

Ransomware & Critical Infrastructure

  • CISA warned that a critical VMware vCenter RCE flaw is now being exploited by ransomware gangs, highlighting continued attacks on enterprise virtualization. – VMware RCE
  • HBO Max and a compromised Reddit account were used in ClickFix ad campaigns tied to a massive PasteSwitch malware operation that pushed users toward malicious downloads. – HBO Max Ads, PasteSwitch Ops
  • A pro-Ukraine hacking group known as Cat is deploying new malware against Russian targets amid the ongoing cyber conflict. – Cat Malware

Identity, Tokens & Data Exposure

  • A Twitch extension with 30K installs exposed users’ OAuth tokens, while Japan’s Digital Agency said a VPN flaw exposed 246,000 personnel records. – Twitch Tokens, Japan VPN Leak
  • Hundreds of fake government sites are targeting users in Central Asia, while a compromised HBO Max Reddit account was also used to spread malware through deceptive ads. – Fake Gov Sites, Reddit Abuse
  • OpenAI is investigating reports that AI agents may have been linked to the RubyGems attack, adding more scrutiny to autonomous tooling in supply-chain incidents. – RubyGems Probe

Law Enforcement & Geopolitics

  • Five alleged leaders of Black Axe were extradited from South Africa to the US to face cybercrime charges tied to the group’s broader fraud and intrusion operations. – Black Axe Charges, Black Axe Extradition
  • Beijing pushed back against Anthropic CEO warnings on China’s AI development, as broader concerns about AI risks and governance continue to intensify. – China AI Row, AI Risk Debate

Vulnerabilities & Patch Notes

  • Microsoft issued emergency Windows updates to fix RDS failures caused by September security patches, restoring RDP access and addressing issues in Windows Server, Windows 11, and some Hyper-V/USB Audio setups. – Windows Fix
  • Microsoft also confirmed the KB5002914 Excel update breaks copy-and-paste behavior, creating an unexpected productivity issue for users. – Excel Bug
  • Homebrew 7.0.0 shipped with a built-in GUI and stronger security controls, while Apple is adding parental controls in iOS 27 so kids can ask before opening new websites. – Homebrew 7.0, iOS Parental Controls

AI, Governance & Security Trends

  • Security leaders say employees are already using unapproved AI tools, and many audit executives still struggle to quantify what AI is worth. – Shadow AI, AI Value
  • New product updates from Entrust, Bitsight, and Dataminr focus on turning cryptographic inventory, exposure data, and threat intelligence into faster security action. – Entrust CBOM, Bitsight Beacon, Dataminr AI

Cybersecurity News | Daily Recap – hendryadrian.com