K Kyro9 News

Cybersecurity Briefing — September 17, 2026

The day's most significant cyber-security stories, curated from 50+ sources.

Google Project Zero Vulnerabilities 203d ago
A Deep Dive into the GetProcessHandleFromHwnd API
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application. This API looked interesting so I…
Also covered by Dark Reading, AWS Security Blog, Bitdefender Labs
CISA Known Exploited Vulnerabilities Threat Intelligence 3d ago
CVE-2026-76461 added to CISA KEV — Cisco Secure Email Gateway
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
Also covered by CSO Online, Rapid7 Blog
WeLiveSecurity (ESET) Threat Intelligence 8d ago
Safe word: What is it and why do you need one?
AI scams are now hyper-realistic. But there’s one simple way to see through them.
Also covered by Graham Cluley, Qualys Blog
Check Point Research Threat Intelligence 16d ago
31st August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East…
Also covered by Wordfence, Red Canary
Unit 42 (Palo Alto) Threat Intelligence 23d ago
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic…
Also covered by Check Point Research, Elastic Security Labs
SANS Internet Storm Center Threat Intelligence 8h ago
ISC Stormcast For Thursday, September 17th, 2026 https://isc.sans.edu/podcastdetail/10098, (Thu, Sep 17th)
Also covered by Rapid7 Blog
Canadian Centre for Cyber Security Advisories 16h ago
Android security advisory – September 2026 monthly rollup (AV26-920) – Update 1
Also covered by Qualys Blog
The Hacker News News 22h ago
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a…
Also covered by BleepingComputer
Kaspersky Securelist Threat Intelligence 1d ago
NightEagle targets Russian companies
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.
Also covered by Citizen Lab
BleepingComputer News 1d ago
Google fixes actively exploited Android zero-day on Pixel devices
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...]
Also covered by Malwarebytes Labs
The Hacker News News 1d ago
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload…
Also covered by Wordfence
Zero Day Initiative Vulnerabilities 1d ago
ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The…
Also covered by Reddit r/netsec
Zero Day Initiative Vulnerabilities 1d ago
ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.…
Also covered by Elastic Security Labs
Zero Day Initiative Vulnerabilities 1d ago
ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of…
Also covered by Cisco Talos
The Hacker News News 1d ago
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly…
Also covered by Infosecurity Magazine
Check Point Research Threat Intelligence 2d ago
14th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after…
Also covered by Wordfence
CISA Known Exploited Vulnerabilities Threat Intelligence 6d ago
CVE-2026-84869 added to CISA KEV — ConnectWise ScreenConnect
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host…
Also covered by SC Media
JPCERT/CC (Japan) Advisories 8d ago
Security Alert: Microsoft Releases September 2026 Security Updates
Also covered by Qualys Blog
CISA Known Exploited Vulnerabilities Threat Intelligence 8d ago
CVE-2026-19490 added to CISA KEV — Citrix NetScaler
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy,…
Also covered by Rapid7 Blog
Cisco Talos Threat Intelligence 8d ago
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
Also covered by CrowdStrike
Kyro9 — AI-native cloud securitySee what's actually exploitable in your cloud. Fix it fast. Self-hostable, no lock-in.
Explore the platform Book a live demo