K Kyro9 News

Cybersecurity Briefing — September 18, 2026

The day's most significant cyber-security stories, curated from 50+ sources.

Google Project Zero Vulnerabilities 204d ago
A Deep Dive into the GetProcessHandleFromHwnd API
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application. This API looked interesting so I…
Also covered by Dark Reading, AWS Security Blog, Bitdefender Labs
The Record (Recorded Future) Threat Intelligence 17h ago
China’s FamousSparrow hackers target Latin America with new backdoor
Alleged Chinese hackers are breaking into government agencies across Latin America using a new backdoor that researchers are calling “SparroWocky.”
Also covered by The Hacker News, Dark Reading
CISA Known Exploited Vulnerabilities Threat Intelligence 4d ago
CVE-2026-76461 added to CISA KEV — Cisco Secure Email Gateway
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
Also covered by CSO Online, Rapid7 Blog
WeLiveSecurity (ESET) Threat Intelligence 9d ago
Safe word: What is it and why do you need one?
AI scams are now hyper-realistic. But there’s one simple way to see through them.
Also covered by Qualys Blog, Graham Cluley
Check Point Research Threat Intelligence 17d ago
31st August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East…
Also covered by Wordfence, Red Canary
Unit 42 (Palo Alto) Threat Intelligence 24d ago
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic…
Also covered by Check Point Research, Elastic Security Labs
BleepingComputer News 33m ago
New Check Point flaw lets hackers execute code with root privileges
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. [...]
Also covered by The Hacker News
SANS Internet Storm Center Threat Intelligence 8h ago
ISC Stormcast For Friday, September 18th, 2026 https://isc.sans.edu/podcastdetail/10100, (Fri, Sep 18th)
Also covered by Rapid7 Blog
Canadian Centre for Cyber Security Advisories 16h ago
AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460
Also covered by CISA Known Exploited Vulnerabilities
Check Point Research Threat Intelligence 19h ago
AI Threat Landscape Digest: July–August 2026
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature…
Also covered by Kaspersky Securelist
The Hacker News News 1d ago
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated,…
Also covered by Infosecurity Magazine
Zero Day Initiative Vulnerabilities 1d ago
ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the…
Also covered by Reddit r/netsec
Canadian Centre for Cyber Security Advisories 1d ago
Android security advisory – September 2026 monthly rollup (AV26-920) – Update 1
Also covered by Qualys Blog
Kaspersky Securelist Threat Intelligence 2d ago
NightEagle targets Russian companies
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.
Also covered by Citizen Lab
Zero Day Initiative Vulnerabilities 2d ago
ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.…
Also covered by Elastic Security Labs
Zero Day Initiative Vulnerabilities 2d ago
ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of…
Also covered by Cisco Talos
Zero Day Initiative Vulnerabilities 2d ago
ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of MindsDB. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are…
Also covered by Wordfence
Check Point Research Threat Intelligence 3d ago
14th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after…
Also covered by Wordfence
CISA Known Exploited Vulnerabilities Threat Intelligence 7d ago
CVE-2026-84869 added to CISA KEV — ConnectWise ScreenConnect
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host…
Also covered by SC Media
CERT-EU Advisories 7d ago
2026-012: Critical Vulnerabilities in Check Point Products
On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access…
Also covered by SecurityWeek
Kyro9 — AI-native cloud securitySee what's actually exploitable in your cloud. Fix it fast. Self-hostable, no lock-in.
Explore the platform Book a live demo