Why Should I Care? โ 2026-09-17 | ๐ด 2 HIGH ยท ๐ก 1 MEDIUM ยท ๐ต 24 RADAR ยท โช 76 FILTERED
๐ Briefing โ 2026-09-17
27 vendor intel items scanned | ๐ด 2 HIGH | ๐ก 1 MEDIUM | ๐ต 24 RADAR | โช 76 FILTERED
๐ด Critical โ action required:
- CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-76460, CVE-2026-87886) โ Yes, if you run Cisco Identity Services Engine or Acronis Backup, you need to update immediately to prevent unauthorized access and control.
- CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-58704) โ Yes, if you run Google Pixel devices with the affected versions: Immediate action is required to prevent unauthorized access.
Everything else can wait.
๐ก Medium โ review when time permits:
- Atomic macOS (AMOS) Stealer Activity โ Yes, if you run any version of macOS and have downloaded or installed any cracked software or followed suspicious setup guides: you are at risk of AMOS stealer infection.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA Advisories [CISA KEV] | CVE-2026-76460, CVE-2026-87886
โ Why Should I Care?
Yes, if you run Cisco Identity Services Engine or Acronis Backup, you need to update immediately to prevent unauthorized access and control.
๐ฏ Affected versions: Cisco Identity Services Engine versions prior to the latest, Acronis Backup versions prior to the latest
๐ญ In plain English:
These vulnerabilities allow attackers to misuse privileged APIs or default permissions to gain unauthorized access and control over your systems. For example, an attacker could use this to take over your network management or backup systems.
๐ง Prerequisites:
- Running affected versions of Cisco Identity Services Engine or Acronis Backup
- No proper access controls in place
โฑ Urgency: High urgency due to active exploitation and potential for total control of affected systems.
โ Fixed in: Latest versions of Cisco Identity Services Engine and Acronis Backup
๐ก Context: The root cause involves improper handling of permissions and API usage, allowing unauthorized access.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Advisories [CISA KEV] | CVSS 8.8 | CVE-2026-58704
โ Why Should I Care?
Yes, if you run Google Pixel devices with the affected versions: Immediate action is required to prevent unauthorized access.
๐ฏ Affected versions: Google Pixel devices running versions 10.0 to 11.1
Not affected: Google Pixel devices running versions 12.0 and above
๐ญ In plain English:
This vulnerability allows attackers to gain unauthorized access to your Google Pixel device, potentially taking full control of it. For example, an attacker could remotely access your device, steal your personal data, and even control your device's functions.
๐ง Prerequisites:
- Device running an affected version
- No proper authorization checks in place
โฑ Urgency: High urgency due to active exploitation and the risk of total control over the device.
โ Fixed in: 12.0, 12.1, 13.0
๐ก Context: The root cause is a flaw in the authorization checks, allowing unauthorized users to bypass authentication mechanisms.
Why Should I Care? ๐ก MEDIUM (1)
Atomic macOS (AMOS) Stealer Activity
Palo Alto Unit 42
โ Why Should I Care?
Yes, if you run any version of macOS and have downloaded or installed any cracked software or followed suspicious setup guides: you are at risk of AMOS stealer infection.
๐ฏ Affected versions: All versions of macOS
๐ญ In plain English:
AMOS stealer is a type of malware that steals your login credentials and sensitive data from your macOS device. For example, an attacker could use this malware to steal your banking passwords or cryptocurrency wallet information.
๐ง Prerequisites:
- User interaction to download and run malicious scripts
- Administrative privileges to install the malware
โฑ Urgency: High urgency due to the potential for significant data loss and unauthorized access to sensitive information.
๐ก Context: The root cause is the user downloading and executing malicious scripts from untrusted sources, often disguised as legitimate software installation guides.
Why Should I Care? ๐ต On the Radar (24)
- Spain's data agency gets first report of AI-powered data breach (BleepingComputer) โ The Spanish Data Protection Agency (AEPD) received a report of a data breach allegedly carried out by an AI agent. The AI searched for flaws, logged into systems, and modified personal data. This indicates that AI can now be used to automate and scale cyberattacks, making them faster and harder to defend against.
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution (The Hacker News) โ A serious flaw in Issabel Framework lets attackers run commands on your system without needing a login. This can lead to full control over your infrastructure.
- Critical ScreenConnect flaw now actively exploited in attacks (BleepingComputer) โ A critical vulnerability in ConnectWise ScreenConnect is being actively exploited by attackers, allowing unauthorized file transfers and executions. This can lead to serious security breaches without requiring user interaction.
- Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens (The Hacker News) โ A critical flaw in WSO2 API Manager lets attackers bypass JWT authentication and potentially take over admin accounts. This affects multiple versions of WSO2 products, including API Manager, API Control Plane, Traffic Manager, and Universal Gateway.
- Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells (The Hacker News) โ A critical security flaw in the WooCommerce Wholesale Lead Capture plugin allows attackers to upload malicious files and take control of your WordPress site. This affects over 6,000 active installs.
- Google fixes actively exploited Android zero-day on Pixel devices (BleepingComputer) โ Google has fixed a serious security flaw in Pixel devices that could let attackers take control of your device if you're on the same network as them. This flaw was being actively exploited, so it's important to update your device.
- Windows 11 KB5124008 update breaks domain trust for some users (BleepingComputer) โ The Windows 11 KB5124008 update is causing domain trust issues, preventing users from logging in with valid credentials. This affects systems with domain trust relationships, especially those using the Machine Identity Isolation feature.
- Malware bypasses browser checks to force install Chrome, Edge extensions (BleepingComputer) โ A new malware named KREMLIN can install malicious extensions on Chrome and Edge browsers without user approval, stealing sensitive data like credentials and session tokens. This affects users who open suspicious files disguised as legitimate documents.
- Iranian hackers use CHOSEN BRICK Windows malware to spy on targets (BleepingComputer) โ Iranian state-linked hackers are using a new Windows malware called CHOSEN BRICK to spy on dissidents, activists, and journalists. The malware can steal emails, Telegram, and WhatsApp communications, take screenshots, and record audio. It's a significant threat if your work involves sensitive communications or operations related to these groups.
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix (The Hacker News) โ A flaw in Parallels Desktop allows non-admin users to gain root access on Macs, which could lead to unauthorized access and control over the system. This is particularly critical for Intel Mac users who cannot upgrade to the fixed version.
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories (The Hacker News) โ An attacker hijacked an AI coding assistant session, spreading malware across 100 internal code repositories. This compromised the company's source code and secrets, highlighting the risks of AI-assisted development.
- One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude (The Hacker News) โ A single browser extension can hijack AI assistants in several Chromium-based browsers and extensions, potentially giving attackers control over your AI assistant and access to sensitive data like files, camera, and microphone.
- Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks (The Hacker News) โ A critical security flaw in Acronis Backup plugin for cPanel & WHM and Plesk on Linux allows attackers to escalate their privileges and potentially run unauthorized code. This could impact the confidentiality and integrity of your data.
- Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation (The Hacker News) โ Google has fixed a serious flaw in Pixel phones that could let attackers take control of the device without the user doing anything. This is a big deal because it means your phone could be compromised without you even knowing.
- Windows Server 2022 reaches end of mainstream support next month (BleepingComputer) โ Windows Server 2022 is ending its mainstream support next month, meaning fewer updates and features will be available. After October 2026, you'll only get security updates until October 2031. If you're running this version, you should consider upgrading to Windows Server 2025 to stay current with support and features.
โช 76 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV