Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (16 September 2026)
Published: Loading…
At a Glance
- Cisco confirmed active exploitation of CVE-2026-76461, a critical SQL injection flaw enabling root command execution on Secure Email Gateway.
- Chinese threat actors UTA0560 and JungleBamboo chained Chrome and Windows zero-days to deploy GRIMWEDGE and LONGTALE malware against NGOs.
- CenterPoint Energy confirmed a breach exposing customer data after a hacker claimed to leak 7.5 million records.
- CISA warned ransomware gangs now exploit a critical VMware vCenter vulnerability patched in July.
- Three Western governments exposed CHOSEN BRICK, Iranian spyware using Telegram command-and-control to target dissidents and journalists.
- A critical LiteSpeed Enterprise flaw could let a hosting account escalate to root access on shared servers.
Editorial Analysis
Cisco's Secure Email Gateway flaw is notable for sitting inside the appliance's email-parsing function: a crafted message can reach root without authentication. CISA's warning that ransomware groups are exploiting a critical VMware vCenter flaw, and cPanel's disclosure of a LiteSpeed bug that can let one shared-hosting tenant reach root on the server, involve different technologies but similarly high-value targets. In each case, compromising the management, virtualisation or security layer can provide access well beyond the vulnerable component itself.
Two malware operations disclosed today also rely on infrastructure designed to be difficult to disrupt. KREMLIN operators targeting Brazilian banks use Ethereum smart contracts to store and update command-and-control configuration, allowing payload URLs and extension IDs to change without registering new domains. Silent Push's research into fast-flux infrastructure found nearly 2,000 phishing domains rotating IP addresses across dozens of networks. Blocking individual addresses therefore has limited effect while the domains remain active. The techniques differ, but both make the infrastructure supporting an operation harder to remove without relying on a change to the malware itself.
Highlights of the Day
Critical Cisco Email Gateway Flaw Under Active Exploitation
Cisco disclosed CVE-2026-76461, a critical SQL injection flaw in Secure Email Gateway's email parsing logic, scoring 9.8 on CVSS. Unauthenticated attackers can send crafted emails containing malicious SQL statements to gain root command execution on the underlying operating system. Cisco confirmed active exploitation in September 2026 and has released fixed AsyncOS software releases, with no workarounds available.
Iranian Spyware Uses Fake MRI Scans to Target Regime Critics
British, American and Dutch agencies exposed CHOSEN BRICK, an Iranian state-sponsored spyware tool delivered through social engineering lures including fake MRI scans. The Windows-only malware harvests contacts, messages and screen content, activates microphones, and evades Microsoft Defender detection. It communicates via individual Telegram bots per victim, with the joint NCSC, FBI and AIVD advisory covering victims across all three countries since 2025.
CenterPoint Energy Confirms Customer Data Breach
CenterPoint Energy disclosed that an unauthorised third party obtained customer personal information through one of the company's external-facing systems. The utility became aware after a third party posted online claiming to possess the stolen data set, then activated its incident response protocols and engaged external cybersecurity experts. Electric and gas service delivery remained unaffected, and the company reported the incident to law enforcement and relevant regulators.
Chinese Hackers Chain Chrome and Windows Zero-Days in Espionage Campaigns
Volexity identified two Chinese threat actors, UTA0560 and JungleBamboo, exploiting a shared Chrome and Windows zero-day chain against NGOs and other targets. The chain combines a V8 type-confusion flaw, a WebAssembly sandbox escape, and a Windows kernel privilege escalation bug to inject code into Chrome's browser process. UTA0560 deployed the GRIMWEDGE JScript backdoor, while JungleBamboo installed a credential-stealing Chrome extension called LONGTALE via a loader named SUPERSTOMP.
Fast-Flux Network Powers Global Phishing Operation Targeting Banks
Silent Push identified nearly 2,000 phishing domains hidden behind fast-flux infrastructure, which rapidly rotates DNS records across multiple IPs to evade detection. One cluster impersonates Canadian banks, tax authorities and postal services using traffic-distribution cloaking that shows scanners a 404 page while directing real victims to interactive, operator-driven phishing kits. A second cluster runs callback phishing against UK, US, Australian and European banks, combining cloned login pages with live fraud-hotline operators who deliver malware through password-protected files.
Brazilian Malware Uses Ethereum Blockchain to Hide Banking Trojan Infrastructure
Elastic Security Labs detailed KREMLIN, a Brazilian banking malware toolkit active since May 2025 that installs malicious browser extensions in Chrome and Edge. The malware uses Ethereum smart contracts as dead-drop resolvers to dynamically update command-and-control endpoints, bypassing Chromium integrity protections by regenerating cryptographic hashes. Across seven campaigns targeting twelve Brazilian banks, operators evolved from PULSAR to REMCOS RAT payloads, and Elastic disrupted over 1,500 infections by registering the malware's kill-switch domain.
Daily Coverage