CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (16 September 2026)

Published: Loading…

At a Glance

  • Cisco confirmed active exploitation of CVE-2026-76461, a critical SQL injection flaw enabling root command execution on Secure Email Gateway.
  • Chinese threat actors UTA0560 and JungleBamboo chained Chrome and Windows zero-days to deploy GRIMWEDGE and LONGTALE malware against NGOs.
  • CenterPoint Energy confirmed a breach exposing customer data after a hacker claimed to leak 7.5 million records.
  • CISA warned ransomware gangs now exploit a critical VMware vCenter vulnerability patched in July.
  • Three Western governments exposed CHOSEN BRICK, Iranian spyware using Telegram command-and-control to target dissidents and journalists.
  • A critical LiteSpeed Enterprise flaw could let a hosting account escalate to root access on shared servers.

Editorial Analysis

Cisco's Secure Email Gateway flaw is notable for sitting inside the appliance's email-parsing function: a crafted message can reach root without authentication. CISA's warning that ransomware groups are exploiting a critical VMware vCenter flaw, and cPanel's disclosure of a LiteSpeed bug that can let one shared-hosting tenant reach root on the server, involve different technologies but similarly high-value targets. In each case, compromising the management, virtualisation or security layer can provide access well beyond the vulnerable component itself.

Two malware operations disclosed today also rely on infrastructure designed to be difficult to disrupt. KREMLIN operators targeting Brazilian banks use Ethereum smart contracts to store and update command-and-control configuration, allowing payload URLs and extension IDs to change without registering new domains. Silent Push's research into fast-flux infrastructure found nearly 2,000 phishing domains rotating IP addresses across dozens of networks. Blocking individual addresses therefore has limited effect while the domains remain active. The techniques differ, but both make the infrastructure supporting an operation harder to remove without relying on a change to the malware itself.

Highlights of the Day

Critical Cisco Email Gateway Flaw Under Active Exploitation

Cisco disclosed CVE-2026-76461, a critical SQL injection flaw in Secure Email Gateway's email parsing logic, scoring 9.8 on CVSS. Unauthenticated attackers can send crafted emails containing malicious SQL statements to gain root command execution on the underlying operating system. Cisco confirmed active exploitation in September 2026 and has released fixed AsyncOS software releases, with no workarounds available.

Source: Cisco

Iranian Spyware Uses Fake MRI Scans to Target Regime Critics

British, American and Dutch agencies exposed CHOSEN BRICK, an Iranian state-sponsored spyware tool delivered through social engineering lures including fake MRI scans. The Windows-only malware harvests contacts, messages and screen content, activates microphones, and evades Microsoft Defender detection. It communicates via individual Telegram bots per victim, with the joint NCSC, FBI and AIVD advisory covering victims across all three countries since 2025.

Source: The Record

CenterPoint Energy Confirms Customer Data Breach

CenterPoint Energy disclosed that an unauthorised third party obtained customer personal information through one of the company's external-facing systems. The utility became aware after a third party posted online claiming to possess the stolen data set, then activated its incident response protocols and engaged external cybersecurity experts. Electric and gas service delivery remained unaffected, and the company reported the incident to law enforcement and relevant regulators.

Chinese Hackers Chain Chrome and Windows Zero-Days in Espionage Campaigns

Volexity identified two Chinese threat actors, UTA0560 and JungleBamboo, exploiting a shared Chrome and Windows zero-day chain against NGOs and other targets. The chain combines a V8 type-confusion flaw, a WebAssembly sandbox escape, and a Windows kernel privilege escalation bug to inject code into Chrome's browser process. UTA0560 deployed the GRIMWEDGE JScript backdoor, while JungleBamboo installed a credential-stealing Chrome extension called LONGTALE via a loader named SUPERSTOMP.

Source: Volexity

Fast-Flux Network Powers Global Phishing Operation Targeting Banks

Silent Push identified nearly 2,000 phishing domains hidden behind fast-flux infrastructure, which rapidly rotates DNS records across multiple IPs to evade detection. One cluster impersonates Canadian banks, tax authorities and postal services using traffic-distribution cloaking that shows scanners a 404 page while directing real victims to interactive, operator-driven phishing kits. A second cluster runs callback phishing against UK, US, Australian and European banks, combining cloned login pages with live fraud-hotline operators who deliver malware through password-protected files.

Brazilian Malware Uses Ethereum Blockchain to Hide Banking Trojan Infrastructure

Elastic Security Labs detailed KREMLIN, a Brazilian banking malware toolkit active since May 2025 that installs malicious browser extensions in Chrome and Edge. The malware uses Ethereum smart contracts as dead-drop resolvers to dynamically update command-and-control endpoints, bypassing Chromium integrity protections by regenerating cryptographic hashes. Across seven campaigns targeting twelve Brazilian banks, operators evolved from PULSAR to REMCOS RAT payloads, and Elastic disrupted over 1,500 infections by registering the malware's kill-switch domain.

Daily Coverage

Developments
Cisco Secure Email Gateway RceGrimwedge/Longtale CampaignCenterpoint Energy BreachVmware Vcenter Ransomware
Vulnerabilities
CVE-2026-76461Cisco Secure Email 14.0.0-698 (Critical)CVE-2026-13293Mq 9.1.0.0 (High)CVE-2026-19290Sterling File Gateway 6.2.0.0 (High)CVE-2026-91752Libextractor (High)
Threat Groups
AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.