Why Should I Care? β 2026-09-15 | π΄ 1 HIGH Β· π‘ 0 MEDIUM Β· π΅ 20 RADAR Β· βͺ 74 FILTERED
π Briefing β 2026-09-15
21 vendor intel items scanned | π΄ 1 HIGH | π‘ 0 MEDIUM | π΅ 20 RADAR | βͺ 74 FILTERED
π΄ Critical β action required:
- CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-76461) β Yes, if you run Cisco Secure Email Gateway versions 5.0.0 to 5.2.3: This SQL injection vulnerability could allow attackers to gain full control over your email gateway.
Everything else can wait.
π΅ 15 items on the radar β see below β
Why Should I Care? π΄ HIGH β Handle Now
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Advisories [CISA KEV] | CVSS 9.8 | CVE-2026-76461
β Why Should I Care?
Yes, if you run Cisco Secure Email Gateway versions 5.0.0 to 5.2.3: This SQL injection vulnerability could allow attackers to gain full control over your email gateway.
π― Affected versions: 5.0.0 to 5.2.3
Not affected: 5.2.4 and later
π In plain English:
This vulnerability means that an attacker could inject malicious SQL code into your email gateway, potentially giving them full control over it. For example, they could read, modify, or delete all emails passing through the gateway.
π§ Prerequisites:
- Running Cisco Secure Email Gateway versions 5.0.0 to 5.2.3
- No proper input validation or sanitization
β± Urgency: High urgency due to active exploitation and the potential for full control over the email gateway.
β Fixed in: 5.2.4, 5.3.0
π‘ Context: The root cause is a lack of proper input validation or sanitization in the SQL queries used by the Cisco Secure Email Gateway.
Why Should I Care? π‘ MEDIUM (0)
None.
Why Should I Care? π΅ On the Radar (20)
- Japan's Digital Agency says VPN flaw exposed 246,000 personnel records (BleepingComputer) β A flaw in a Japanese government agency's VPN exposed personal data of 246,000 government employees. This shows that unpatched vulnerabilities in remote access tools can lead to significant data breaches.
- Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries (The Hacker News) β A Chinese threat actor, Red Heron, exploited a Gitea vulnerability to compromise 13 organizations across six countries. This attack highlights the rapid exploitation of newly disclosed vulnerabilities and the importance of timely patching.
- 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials (The Hacker News) β A hacker used MeshCentral, a legitimate IT management tool, as a backdoor to gain root access in 3BB's network, targeting subscriber credentials. This shows how trusted tools can be exploited and the need to secure remote access points like FortiGate SSL-VPN.
- Hackers hijack HBO Max Reddit account to push malware in ClickFix ads (BleepingComputer) β Hackers compromised HBO Max's Reddit account to spread malware through fake ads, targeting both Windows and macOS users. This attack could steal your personal information and infect your device.
- Hackers target exposed Vite dev servers to steal AWS, Azure secrets (BleepingComputer) β Hackers are exploiting vulnerabilities in Vite development servers to steal sensitive cloud credentials and configurations from AWS and Azure. This can lead to unauthorized access to your cloud resources and potential data breaches.
- Revolut discloses data breach exposing financial info, passports (BleepingComputer) β Revolut, a major fintech company, has disclosed a data breach where sensitive customer information, including financial details and passports, was exposed to a threat actor impersonating a government agency. This impacts a limited number of customers but could affect high net worth individuals.
- Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users (The Hacker News) β A malicious browser extension for Twitch has leaked OAuth tokens from nearly 31,000 users, potentially compromising their accounts. The extension, 'Twitch Enhanced Viewer | JeetBot,' sends OAuth tokens to a proxy server, which can be used to access users' chat, private messages, and account settings.
- CISA: Hackers now exploit max severity GitLab flaw in attacks (BleepingComputer) β Hackers are exploiting a critical vulnerability in GitLab that allows them to read sensitive information. This affects over 50% of Fortune 100 companies and 30 million users. GitLab has released patches for versions 19.3.2, 19.2.6, and 19.1.
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports (The Hacker News) β A flaw in Telegram Desktop allowed hidden JavaScript to be embedded in HTML exports, potentially exfiltrating chat messages to an attacker-controlled server. This affects users who have exported chats to HTML using versions of Telegram Desktop from 4.15.1 to 6.9.3.
- New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing (The Hacker News) β A new hardware attack, DDRop, can bypass the memory protection in Intel TDX and AMD SEV-SNP by silently dropping writes to memory, leading to the processor reading old encrypted data as if it were current. This can allow attackers to read and modify protected data.
- Twitch extension with 30K installs exposes usersβ OAuth tokens (BleepingComputer) β A popular Twitch extension, Twitch Enhanced Viewer | JeetBot, is leaking users' OAuth tokens, which can be used to hijack accounts. This affects over 30,000 users and could lead to unauthorized access to their Twitch accounts.
- Microsoft: September updates cause RDS failures on Windows Server (BleepingComputer) β Microsoft's September 2026 security updates are causing RDS failures on Windows Server systems, impacting connectivity and requiring hard resets to restore functionality. This affects Windows Server 2012 and later, as well as Windows 10 and 11 devices.
- WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution (The Hacker News) β WordPress introduces automated security reviews for plugins.
- Homebrew 7.0.0 gets built-in GUI, better security controls (BleepingComputer) β Homebrew 7.0.0 release with new features.
- AWS Security Reference Architecture: A deep dive into PCI DSS compliance (AWS Security Blog) β New guide for PCI DSS compliance on AWS.
βͺ 74 low-priority items filtered.
π¦ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV