Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (18 September 2026)
Published: Loading…
At a Glance
- Cisco disclosed CVE-2026-76460, a maximum-severity ISE authentication bypass under active exploitation, urging immediate patching.
- The FBI seized domains behind NightmareStresser, a long-running DDoS-for-hire booter service, under Operation PowerOFF.
- China-aligned FamousSparrow deployed a new SparroWocky backdoor against government targets across Latin America since August 2025.
- Handala Hack was tied to HEAVYGRAM, a Telegram-based Windows backdoor targeting Iranian dissidents and journalists since 2023.
- A zero-click flaw dubbed Plugin4Shell affects Claude Code, Codex, Gemini CLI and Copilot AI coding agents.
- Gyazo disclosed a breach exposing 23.62 million user records and 490 million image metadata records.
Editorial Analysis
Cisco's third maximum-severity disclosure in as many weeks points to a recurring exposure across its enterprise infrastructure. CVE-2026-76460, a CVSS 10.0 authentication bypass in Identity Services Engine, was already under active exploitation when disclosed, following the Secure Email Gateway flaw reported days earlier and the FMC and Nexus Dashboard issues disclosed this week. ISE sits at the centre of identity and network policy, so a successful bypass provides root-level access to a system that also controls how devices and users are authorised across the network.
Two other stories today concern operations that have had time to adapt. NightmareStresser had been running since at least 2022 and generated hundreds of thousands of attacks before its domains were seized under Operation PowerOFF. FamousSparrow, meanwhile, has replaced its well-documented SparrowDoor implant with the new SparroWocky backdoor, incorporating heavier anti-analysis techniques and open-source hooking and call-stack-spoofing libraries directly into the malware. The difference is notable: one operation survived through persistence of its infrastructure, while the other is adapting its tooling as defenders become more familiar with the old one.
Highlights of the Day
Cisco Warns of Actively Exploited Maximum-Severity ISE Flaw
Cisco disclosed CVE-2026-76460, a critical authentication bypass in Identity Services Engine and ISE-PIC scoring a perfect 10.0 on CVSS. Attackers can exploit an insufficiently authenticated API endpoint with crafted requests to bypass the web management interface, potentially gaining root-level command execution. Cisco confirmed active exploitation in the wild and has released patched software, noting no workarounds exist beyond restricting access via infrastructure access control lists.
FBI Seizes Domains Behind Long-Running NightmareStresser DDoS Service
The FBI, working with the Royal Canadian Mounted Police, seized domains linked to NightmareStresser, a DDoS-for-hire "booter" service. The service reportedly launched hundreds of thousands of attacks against targets worldwide since 2022, including schools, government agencies and gaming platforms. The action forms part of Operation PowerOFF, an ongoing international effort targeting DDoS-for-hire infrastructure and its operators.
CISA Issues Guidance on Using Cyber Decoys for Threat Detection
CISA published guidance helping defensive teams plan and deploy cyber decoy strategies to strengthen detection and response capabilities. The document addresses tripwires, breadcrumbs and honeytokens, using MITRE Engage and MITRE ATT&CK frameworks to detect adversaries using legitimate credentials and living-off-the-land techniques. The guidance targets organizations adopting Zero Trust models across varying levels of cybersecurity maturity.
China-Linked FamousSparrow Deploys New SparroWocky Backdoor
ESET Research identified SparroWocky, a modular C++ backdoor deployed by China-aligned group FamousSparrow since August 2025. The group has almost exclusively targeted governmental organisations across Latin America, replacing its previous SparrowDoor implant. SparroWocky supports command execution, file exfiltration, screenshot capture, and loading of Beacon Object Files, using anti-analysis techniques including call-stack spoofing.
Iran-Linked HEAVYGRAM Backdoor Uses Telegram for Command Control
Group-IB identified 29 new samples of HEAVYGRAM, a Windows backdoor attributed with moderate confidence to Iran-linked group Handala Hack. Active since Fall 2023, the malware targets journalists and Iranian dissidents, delivering itself via messaging apps disguised as legitimate software. HEAVYGRAM relies on Telegram bots for command execution, screen capture and data exfiltration, with infrastructure remaining active on the platform as of 2026.
Phishing Campaign Impersonates ChatGPT Billing Notifications
Cofense identified a phishing email impersonating OpenAI, using a fake subscription invoice to steal ChatGPT account credentials. The message spoofs OpenAI branding and urges recipients to update payment details within 48 hours via a spoofed domain. Clicking the link routes victims through a Google API redirect to a fake login page that harvests entered credentials.
Daily Coverage