Security news
Latest security news
Yesterday · Tue, 15 Sept 2026
- ISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094, (Tue, Sep 15th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
SANS Internet Storm Center - Supreme Court denies Trump request to allow USPS mail ballot changes
One justice said the attempt to change the rules ahead of the 2026 elections would be "arbitrary and capricious” and violated the Administrative Procedures Act.
CyberScoop
Mon, 14 Sept 2026
- HBO Max Reddit account compromised to serve ClickFix attacks
Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware
The RegisterWindows - 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.
Dark ReadingCisco - Microsoft releases emergency Windows updates to fix RDS failures
Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions.
BleepingComputerMicrosoft, Windows - Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees.
BleepingComputer - Maximum Severity GitLab Flaw Puts Supply Chains at Risk
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
CriticalUsed in attacksDark ReadingGitLab - Homebrew 7.0.0 gets built-in GUI, better security controls
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface.
BleepingComputer - Members of ‘Black Axe’ cybercriminal group extradited from South Africa
Prosecutors unsealed a 2021 indictment accusing the five men of conducting lucrative romance scams that stole thousands of dollars from more than 100 people.
The Record - Cisco security advisory (AV26-921)
Serial Number: AV26-921 Date: September 14, 2026 As of September 14, 2026, Cisco is affected by vulnerabilities in the following products: Cisco AsyncOS for Cisco Secure Email Gateway Prior to 15.5.5-014 Prior to 16.0.4-302 Prior to 16.5.0-780 Cisco Secure Email Gateway Prior to 15.5.5-014 Prior to 16.5.0-780 Cisco Secure Email and Web Manager Prior to 15.5.5-006 Prior to 16.5.0-429 On September 14, 2026, Cisco stated that CVE-2026-76461 is being actively exploited. On September 14, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76461 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Cisco Secure Email Gateway SQL Injection Vulnerability Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 Cisco Security Advisories CISA KEV: CVE-2026-76461
CriticalUsed in attacksCanadian Centre for Cyber SecurityCisco
About this news
- 1,263
- Stories
- 35
- Added in the last 24 hours
- 16
- Critical in the last 7 days
- 4
- Reported by several outlets