LIVE · cybersecurity feed
Live wire
CVE-2026-9055 · WordPress Amelia Plugin Flaw Exploited Before CVE PublicationCVE-2026-46331 · Linux Kernel Flaw Exploited After 71 Days, Not on CISA KEVCVE-2026-84434 · CVE-2026-84434 Exploited Before Publication, No Patch WindowCVE-2017-20284 · CVE-2017-20284 Exploited Same Day as PublicationCVE-2026-87886 · Acronis Backup Flaw Exploited Before CVE PublicationCVE-2026-76461 · Week in review: Cisco patches exploited email gateway 0-day, Revolut breachCVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingAgentic security is the billion-dollar challenge for some clever startup to solveCVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCVE-2025-39682 · CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
CVE-2026-76461high

Week in review: Cisco patches exploited email gateway 0-day, Revolut breach

This week's cybersecurity news includes Cisco patching an actively exploited zero-day vulnerability in its Secure Email Gateway and a data breach at Revolut where customer records were obtained by an impersonator. Additionally, new tools and research highlight the growing challenges in securing AI systems, managing open-source software, and the potential for privilege escalation vulnerabilities in popular software like Acronis backup plugins and Parallels Desktop.

zeroday.news ·

Cisco has confirmed that attackers are actively exploiting a zero-day SQL injection vulnerability, tracked as CVE-2026-76461, in its Secure Email Gateway appliances. The company's Product Security Incident Response Team became aware of the exploitation in September 2025 and has since provided indicators of compromise for organizations to check for potential breaches.

In a separate incident, Cisco also confirmed that another flaw, CVE-2026-76460, is being targeted. This vulnerability is an authentication bypass bug within an API of Cisco Identity Services Engine (ISE), a system designed to manage user identity, device profiling, security posture checks, access control, and logging.

Meanwhile, the financial technology company Revolut has confirmed a data breach. An individual impersonating a government agency, using an email address from that agency's domain, successfully obtained sensitive customer records. Revolut acknowledged the incident on Saturday, September 12.

Acronis, a backup and recovery company, has issued a warning about a Linux privilege escalation vulnerability, CVE-2026-87886, affecting its backup extensions for cPanel, WebHost Manager (WHM), and Plesk. Attackers are reportedly leveraging this flaw in targeted attacks.

Another significant vulnerability, CVE-2026-90894, dubbed "ParaShells," has been disclosed in Parallels Desktop. This flaw could allow any local user on a Mac to gain root privileges on the host system. The risk is particularly high for developer laptops, where a compromised Homebrew formula or malicious npm preinstall script could escalate from local user access to full system control, and on shared university or corporate machines with multiple local accounts.

In other cybersecurity developments, the EU Agency for Cybersecurity (ENISA) launched the Cyber Resilience Act's Single Reporting Platform on September 11, 2026, coinciding with the start of the law's reporting obligations for manufacturers. ENISA is responsible for the platform's development and daily operations, as mandated by Article 16(1) of the CRA.

CISA has released new guidance titled "Using Cyber Decoys to Strengthen Detection and Response," aiming to make cyber deception more accessible to critical infrastructure organizations and smaller security teams. This initiative addresses the challenge many organizations face in detecting adversaries who utilize legitimate credentials, built-in administrative utilities, and living-off-the-land (LOTL) techniques.

The Debian project has released Debian 13.7, codenamed "trixie," which incorporates fixes from 92 previously published security advisories. The update also includes corrections to 106 source packages and a rebuilt installer.

WhatsApp is developing a "Restricted Chat" setting for its Android beta (version 2.26.36.5), which will allow users to keep a chosen conversation exclusively on their primary mobile device, preventing it from syncing to linked devices like WhatsApp Web or secondary phones.

vulnerabilities in this storyCVE-2026-76461CVE-2026-87886CVE-2026-90894CVE-2026-76460
vulnerabilitydata breachai securityopen sourcecisco
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Below are detailed descriptions of the flaws: At the time of this writing, there are currently no details

vulnerability

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot […]

CVE-2026-9055critical

WordPress Amelia Plugin Flaw Exploited Before CVE Publication

A critical privilege escalation vulnerability in the WordPress Amelia plugin was exploited before its official CVE publication. CISA has not yet added it to its Known Exploited Vulnerabilities catalog.

CVE-2026-46331high

Linux Kernel Flaw Exploited After 71 Days, Not on CISA KEV

A Linux kernel vulnerability, CVE-2026-46331, has been confirmed as exploited, but remains absent from the US federal CISA Known Exploited Vulnerabilities (KEV) catalogue.

malware

Malicious npm packages evade install-script defenses at runtime

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]

nation-state

AI Hallucinations Nearly Triggered a US-China Military Confrontation

An AI-generated intelligence report falsely identified weapons on a Chinese ship, nearly triggering a US military operation during the Iran war. According to CNN, four sources familiar with the episode say an intelligence report circulated through the military claiming a Chinese vessel in the Middle East was carrying components for a nuclear weapons program. The […]