Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (17 September 2026)
Published: Loading…
At a Glance
- Google patched a Pixel Cellular Modem zero-day, CVE-2026-58704, exploited in zero-click, no-interaction attacks.
- WSO2 API Manager flaw CVE-2026-5430 is under active exploitation, allowing forged JWT tokens for account takeover.
- Iranian state actors deploy CHOSEN BRICK malware via Telegram against dissidents, activists and journalists worldwide.
- Acronis Backup plugin flaw CVE-2026-87886 exploited in targeted Linux attacks against cPanel and WHM deployments.
- Brevo supply chain attack served WordPress backdoors and Clickfix malware to over 100,000 customer sites.
- Parallels Desktop flaw CVE-2026-90894 lets local Mac users escalate to root via appliance install.
Editorial Analysis
N-able's N-central flaw, CVE-2026-86218, has now been added to CISA's Known Exploited Vulnerabilities catalogue with a CVSS score of 10.0, despite earlier fixes and repeated emergency updates to the platform. The vulnerability requires neither authentication nor user interaction, allowing an attacker with network access to execute code on a vulnerable server. Because N-central is used to manage client networks remotely, compromising one server can potentially provide a path to the devices and systems it administers.
Spain's AEPD has also documented an incident involving an AI agent operating against a real organisation. The unnamed agent logged into the target system, conducted vulnerability scans, modified personal data and accessed invoices. The agency stressed that the use of a particular model does not mean the model or its provider was compromised, and cautioned against drawing broader conclusions from a single case. What the report does establish is a documented instance of an AI agent carrying out several stages of an intrusion with limited human intervention.
Highlights of the Day
Google Patches Dozens of Critical Pixel Security Flaws
Google released the September 2026 Pixel Update Bulletin, addressing numerous vulnerabilities across bootloader, modem, kernel and trusted execution components. Several critical remote code execution flaws affect subsystems including the IP Multimedia Subsystem, VPU, modem and BigOcean, alongside many critical elevation of privilege bugs in the bootloader and Goodix Fingerprint TA. Devices updated to the 2026-09-05 patch level or later address all issues covered in this bulletin and the accompanying Android Security Bulletin.
Spain Reports First Data Breach Attributed to an AI Agent
Spain's data protection authority, AEPD, received its first notification of a personal data breach reportedly executed by an AI agent using a language model. The agent logged in successfully, autonomously searched the application for vulnerabilities, then used them to modify personal data and access invoices. AEPD notes the information comes solely from the affected organisation's notification and does not confirm the AI provider's infrastructure was compromised.
Acronis Backup Flaw Exploited in Targeted Linux Attacks
Acronis disclosed CVE-2026-87886, a high-severity local privilege escalation flaw caused by insecure file permissions on Linux. The vulnerability affects the Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk, and has already been exploited in limited, targeted attacks. Updated builds are available for both affected products.
Iranian Malware CHOSEN BRICK Targets Dissidents and Journalists
The NCSC, FBI and Dutch AIVD detailed CHOSEN BRICK, malware used by Iranian state actors against dissidents, activists and journalists since 2025. Attackers build rapport on platforms like WhatsApp and Telegram before persuading targets to open disguised files, deploying Windows-only malware that steals contacts, emails and messages via Telegram command and control. Some victims' stolen data has since appeared on pro-Iranian leak sites.
Oracle Patches 673 Flaws in September Security Update
Oracle's September Critical Patch Update addressed 673 vulnerabilities, with 104 rated critical and 503 rated important. Oracle E-Business Suite received the most patches at 159, followed by Fusion Middleware with 153, of which 78 are remotely exploitable without authentication. Three E-Business Suite flaws and multiple Fusion Middleware vulnerabilities carry critical severity ratings, including CVEs scoring 9.8.
Brevo Supply Chain Attack Hits Over 100,000 Sites
Email marketing provider Brevo served malware to visitors of its own site and more than 100,000 customer sites on 14 September. Attackers, who appear to have breached Brevo's Cloudflare account, injected a script that secretly installed a backdoored WordPress plugin for logged-in admins or showed other visitors a Clickfix overlay tricking them into running malicious commands. Brevo stopped serving the malicious code the following day, though affected WordPress sites may remain backdoored.
Parallels Desktop Bug Let Local Users Gain Root Access
Researchers at JFrog disclosed CVE-2026-90894, a Parallels Desktop for Mac vulnerability allowing unprivileged local users to execute code as root. The flaw combines a world-writable Unix socket, weak client authentication, and argument injection in the appliance-install path, letting attackers hijack the tar extraction process. Parallels fixed the issue in version 27.0.0, released before the vulnerability's public disclosure.
Daily Coverage