Cisco has confirmed that attackers are actively exploiting a zero-day SQL injection vulnerability, tracked as CVE-2026-76461, in its Secure Email Gateway appliances. The company's Product Security Incident Response Team became aware of the exploitation in September 2025 and has since provided indicators of compromise for organizations to check for potential breaches.
In a separate incident, Cisco also confirmed that another flaw, CVE-2026-76460, is being targeted. This vulnerability is an authentication bypass bug within an API of Cisco Identity Services Engine (ISE), a system designed to manage user identity, device profiling, security posture checks, access control, and logging.
Meanwhile, the financial technology company Revolut has confirmed a data breach. An individual impersonating a government agency, using an email address from that agency's domain, successfully obtained sensitive customer records. Revolut acknowledged the incident on Saturday, September 12.
Acronis, a backup and recovery company, has issued a warning about a Linux privilege escalation vulnerability, CVE-2026-87886, affecting its backup extensions for cPanel, WebHost Manager (WHM), and Plesk. Attackers are reportedly leveraging this flaw in targeted attacks.
Another significant vulnerability, CVE-2026-90894, dubbed "ParaShells," has been disclosed in Parallels Desktop. This flaw could allow any local user on a Mac to gain root privileges on the host system. The risk is particularly high for developer laptops, where a compromised Homebrew formula or malicious npm preinstall script could escalate from local user access to full system control, and on shared university or corporate machines with multiple local accounts.
In other cybersecurity developments, the EU Agency for Cybersecurity (ENISA) launched the Cyber Resilience Act's Single Reporting Platform on September 11, 2026, coinciding with the start of the law's reporting obligations for manufacturers. ENISA is responsible for the platform's development and daily operations, as mandated by Article 16(1) of the CRA.
CISA has released new guidance titled "Using Cyber Decoys to Strengthen Detection and Response," aiming to make cyber deception more accessible to critical infrastructure organizations and smaller security teams. This initiative addresses the challenge many organizations face in detecting adversaries who utilize legitimate credentials, built-in administrative utilities, and living-off-the-land (LOTL) techniques.
The Debian project has released Debian 13.7, codenamed "trixie," which incorporates fixes from 92 previously published security advisories. The update also includes corrections to 106 source packages and a rebuilt installer.
WhatsApp is developing a "Restricted Chat" setting for its Android beta (version 2.26.36.5), which will allow users to keep a chosen conversation exclusively on their primary mobile device, preventing it from syncing to linked devices like WhatsApp Web or secondary phones.






