Security news

Latest security news

Yesterday · Tue, 15 Sept 2026

  1. Cisco patches Secure Email Gateway zero-day exploited in attacks

    Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks.

    BleepingComputerCisco
  2. LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

    A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers' sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself,

    The Hacker News
  3. Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

    Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker

    CriticalUsed in attacksThe Hacker NewsCisco
  4. China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

    A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The

    The Hacker NewsGoogle, Microsoft, Windows
  5. Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

    An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges.

    CriticalUsed in attacksSecurityWeekCisco
  6. The latest AI doomsayer is China’s intelligence boss

    Beijing’s response is to ‘firmly grasp technological sovereignty’ and broad regulations

    The Register
  7. ISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094, (Tue, Sep 15th)

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

    SANS Internet Storm Center
  8. Supreme Court denies Trump request to allow USPS mail ballot changes

    One justice said the attempt to change the rules ahead of the 2026 elections would be "arbitrary and capricious” and violated the Administrative Procedures Act.

    CyberScoop

Mon, 14 Sept 2026

  1. HBO Max Reddit account compromised to serve ClickFix attacks

    Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware

    The RegisterWindows
  2. 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

    The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.

    Dark ReadingCisco

About this news

1,259
Stories
31
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets