Cybersecurity News Digest — September 17, 2026
A CVSS 10.0 Cisco ISE bypass hits the KEV catalog, a crafted email gives root on Cisco's mail gateway, and Iran's CHOSEN BRICK spyware targets journalists.
Read source →Curated cybersecurity news and emerging threats relevant to startups, SMBs, and growing teams.
Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.
Each item includes our perspective on why it matters to your security posture.
A CVSS 10.0 Cisco ISE bypass hits the KEV catalog, a crafted email gives root on Cisco's mail gateway, and Iran's CHOSEN BRICK spyware targets journalists.
Read source →CISA sets a same-day patch deadline for a maximum-severity Cisco firewall manager bug already tied to Sandworm and Qilin, GitLab's CVSS 10 file-read flaw draws active probing, and attackers chain JFrog Artifactory bugs to plant Rust backdoors.
Read source →CISA adds an unauthenticated MikroTik router takeover chain to its KEV catalog, the EU's Cyber Resilience Act reporting deadline goes live today, and Anthropic discloses a fourth incident of an AI model breaching real systems.
Read source →ShinyHunters breaches Florida's DMV database and proves it with Jeffrey Epstein's own record, CISA adds four actively exploited network-edge flaws to its KEV catalog in one day, and a third Windows Defender zero-day bypass lands right after Patch Tuesday.
Read source →A CVSS 10.0 Magento zero-day backdoors stores before Adobe's fix ships, Microsoft's record Patch Tuesday closes two exploited zero-days, and a default FreeIPA config lets anonymous LDAP clients become domain admins.
Read source →A maximum-severity RMM flaw gets its fourth hotfix in five weeks, ScreenConnect clients spread malware worm-style, and a Git config trick lets attacker code run inside AI coding agents.
Read source →AI agents run a full ransomware attack chain in under 10 hours, infostealer malware hijacks Claude login sessions to drain accounts, and mass exploitation hits two WordPress plugins.
Read source →A Chrome V8 zero-day lands on CISA's KEV list days after patching, a public exploit surfaces for a Microsoft Exchange auth-bypass bug still open on 22,000 servers, and a 12-year-old PostgreSQL flaw turns replication access into a server backdoor.
Read source →A dark-web breach exposes 153 million driver's licenses tied to IDScan.net, a critical Citrix NetScaler auth bypass moves from patch advisory to active exploitation, and a phishing campaign hides lure words inside invisible Unicode.
Read source →An unauthenticated root RCE hits Cisco Nexus 9000 switches, Thomson Reuters discloses a five-month-old breach that exposed sealed court records across a dozen jurisdictions, and a Microsoft Teams vishing campaign nets 150+ victims.
Read source →