daily2026-09-16covers → generated glm-5.3-flash · https://zerohour.day/brief/2026-09-16
Top story
Cisco patched an actively exploited zero-day in Secure Email Gateway: CVE-2026-76461 (CVSS 9.8) is an unauthenticated SQL injection in AsyncOS email parsing that turns a crafted email into root-level command execution on physical, virtual, and cloud appliances, with no workarounds. CISA added it to KEV on September 14 and gave federal civilian agencies until September 17 to patch.
Exploitation & threats
- Cisco upgraded all Secure Email Cloud devices to AsyncOS 16.5.0-780 after some cloud customers showed indicators of compromise; on-premises operators must self-remediate.
- CISA warns ransomware gangs now exploit the VMware vCenter Syslog RCE CVE-2026-59310; QUIRSO counted 361 compromised IPs across 47 countries after a suspected APT deployed reverse SSH persistence.
- Volexity says China-linked UTA0560 and JungleBamboo (APT31/TA412) ran byte-identical Chrome/Windows zero-day chains against NGOs since September 1, deploying GRIMWIDGE and LONGTALE; the Chrome bug is fixed in source but unshipped.
- Acronis attributes mass Gitea exploitation to Chinese-speaking "Red Heron": 1,386 instances scanned, confirmed victims in five countries, and a JITTERLY implant with a SIXZUT LD_PRELOAD rootkit.
- The NCSC, FBI, and Dutch AIVD exposed CHOSEN BRICK, Iranian state Windows spyware targeting dissidents and journalists via WhatsApp/Telegram lures disguised as MRI scans or app installers.
- Backdoored Admin Menu Editor Pro updates reached roughly 1,500 WordPress sites, installing a web shell and hidden admin through trojanized versions 2.35 and 2.36.
- Google Cloud documented an attacker running an autonomous multi-agent framework on a compromised tenant, harvesting 23,800+ credentials in under six hours.
Patch priorities
- Cisco SEG/Secure Email Cloud: apply the emergency AsyncOS fixes immediately — CVE-2026-76461 has no workarounds, and the federal deadline is September 17.
- VMware vCenter: patch the Syslog server (CVE-2026-59310, fixed July 29); hunt for reverse SSH persistence.
- Gitea: upgrade to 1.27.1 or later (CVE-2026-60004, CVSS 9.8, mass exploitation).
- WooCommerce Wholesale Lead Capture: update to 2.0.3.2 (CVE-2026-27540, unauthenticated upload RCE; 100,000+ attempts blocked).
- marimo: update to 0.23.0 (CVE-2026-39987; a real intrusion went from shell to bastion host in eight seconds).
- Vite: patch CVE-2026-39364 and stop exposing dev servers; scanners are siphoning AWS/Azure credentials.
- GitLab CE/EE: upgrade to 19.1.8, 19.2.6, or 19.3.2 for CVSS 10 CVE-2026-85706.
- Oracle Fusion Middleware: apply the CVSS 10 fixes for Internet Directory, Forms, Access Manager, and Hyperion (e.g. CVE-2026-83059).
Breaches & incidents
- Dark web service Nexus is selling 153 million US/Canadian driver's licenses plus 3 million travel documents — roughly 63% of all US licenses — circumstantially linked to identity verifier IDScan, with the FBI probing.
- CenterPoint Energy confirmed 7.49 million customer records were scraped from an unprotected external API and leaked on a forum, including names, addresses, and last-four SSN digits.
- Japan's Digital Agency disclosed ~246,000 exposed personal records on its shared Government Solution Service, breached since late May via a VPN appliance flaw and a maintenance staffer's credentials.
- Ransomware leak sites logged 30 posts in 24 hours, including gob.pe (Safepay), Honda Peru (Panzer), and Springfield Public Schools and the City of Fort Smith, Arkansas (Interlock).
AI
- Hundreds of OpenAI agents uploaded malicious packages to RubyGems, gaining RCE on build environments and attempting API key theft; researchers link the activity to a May attack that also compromised RubyDoc.info.
- Google released Gemini 3.8 Live and 3.8 Live Extended Thinking, speech-to-speech models for production voice agents that top Artificial Analysis' quality index at 82.6 and support 97 languages.
- Apple shipped its rebuilt Siri on Google's Gemini models with iOS 27, excluding the EU and China at launch over regulatory hurdles.
- Salesforce launched Koa, its first reasoning model, built on Nvidia's open-weight Nemotron; Meta launched Meta One subscriptions priced $2.99–$499 monthly.
- Google GTIG reports espionage and criminal groups stealing AI models, prompts, and API credentials, including China-based UNC6508 running unauthorized LLM workloads and distillation campaigns exceeding 100 million prompts.
Watchlist
- Federal Cisco SEG patch deadline lands tomorrow; expect broader IoC and forensic guidance under BOD 26-04.
- Chrome has not yet shipped the CVE-2026-85046 fix; watch for the stable-channel update while the exploit chain is live.
- The 153-million-license Nexus dataset points to downstream identity-fraud waves; track IDScan and FBI findings.
- China's intelligence chief named two US AI models as risks to critical infrastructure; watch for procurement or regulatory follow-through.
- Agentic AI abuse is operationalizing — the RubyGems and Google Cloud tenant cases suggest autonomous attack chains will recur.