ZeroHour

Search: “U.S. federal civilian agencies”

4 stories in the last 3d

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Cisco warns CVE-2026-76461 in Secure Email Gateway AsyncOS is actively exploited, letting unauthenticated attackers run root commands via crafted emails.

Cisco disclosed CVE-2026-76461, a CVSS 9.8 flaw in AsyncOS for Cisco Secure Email Gateway caused by insufficient validation in email parsing, allowing unauthenticated remote attackers to execute arbitrary SQL statements leading to root command execution. Active exploitation began in September 2026, and CISA added the flaw to its KEV catalog, requiring FCEB agencies to patch by September 17, 2026. Fixes are available in AsyncOS 15.5.5-0141, 16.0.4-302, and 16.5.0-780, with no workarounds. Cisco also contacted Secure Email Cloud customers where malicious activity was detected, and the article separately notes large-scale credential attacks on Fortinet VPN appliances generating tens of millions of authentication failures.

The Hacker Newsupdated · 1d agofirst · 2d agoExploit / PoC in the wild 17 sourcesCVE-2026-76461

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacksnew

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.

Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far

TechCrunch's 2026 roundup covers SSA data exposure, Iranian water-utility attacks, Klue breach hitting ~200 firms, and Meta AI chatbot account hijacks.

TechCrunch's mid-year roundup highlights a whistleblower claim that DOGE uploaded a live Social Security database copy to an unsecured third-party server, which House Democrats called potentially the largest US breach in history. CISA reported Iranian hackers targeted over 100 US water providers over the summer, while Russian-linked attacks hit Polish, Swedish, and Norwegian energy and water infrastructure. Market research firm Klue was breached via a stale 2022 pilot credential, exposing cloud keys of ~200 customers including Jamf, HackerOne, and LastPass to extortion gang Icarus. Separately, tens of thousands of Instagram accounts were hijacked by abusing Meta's AI chatbot to trigger password resets to attacker-controlled emails.

TechCrunch · Security · 1d agoData breach in the wild

America’s cyber strategy overlooks the infrastructure that actually keeps the military moving

Op-ed argues US cyber strategy underweights Iranian threats to ports, rail, utilities and other commercial infrastructure sustaining military operations.

The author, a former Navy intelligence officer, argues that a prolonged Iran conflict means sustained Iranian cyber operations targeting many smaller systems like water utilities, manufacturers and transportation providers. He cites mapping of 130 documented techniques across five Iranian threat groups and warns destructive attacks such as wipers and ransomware could hit the defense industrial base. The piece urges defensive wargames now and flags the pause in CMMC implementation as particularly concerning.

CyberScoop · 4h agoIndustry