DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - September 15, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - September 15, 2026


📊 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. Cisco Patches Zero-Day Flaw in Email Gateway (CVE-2026-76461)

Cisco has released emergency patches for a critical SQL injection zero-day vulnerability, CVE-2026-76461, in its Secure Email Gateway appliances. The flaw is being actively exploited in the wild, allowing unauthenticated attackers to compromise devices by sending a specially crafted email. The vulnerability affects both on-premises and cloud versions of the product. In response to the active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply the patches by September 17, 2026. Cisco urges administrators to patch immediately and review network logs for signs of compromise, such as unexpected data transfers from affected gateways.

📖 Read full report →


2. Accela Data Breach Disclosed After 9-Month Delay

Accela, Inc., a provider of cloud software for government agencies, has reported a data breach that occurred in December 2025, a full 277 days before the public notification. The ransomware group Everest has claimed responsibility, asserting they exfiltrated 1 terabyte of the company's internal data. The breach involved an unauthorized actor gaining access to a secure file transfer portal and acquiring files containing the personal information of California residents, including names and Social Security Numbers. Accela is offering identity monitoring services to affected individuals, but the significant delay in disclosure has raised concerns.

📖 Read full report →


3. ConnectWise ScreenConnect Flaw Exploited (CVE-2026-84869)

ConnectWise has issued an urgent patch for a critical vulnerability (CVE-2026-84869) in its ScreenConnect remote access software. The flaw, rated 9.9 on the CVSS scale, allows an attacker to transfer and execute files on a target system during a remote session without authorization. Security researchers at Huntress observed the flaw being exploited in worm-like attacks starting in August 2026, where a rogue client propagates a VBScript payload to other connected systems. CISA has added the vulnerability to its KEV catalog, mandating a three-day patching window for federal agencies. ConnectWise has released version 26.6.5 to fix the issue.

📖 Read full report →


4. GitLab Path Traversal Flaw Exploited (CVE-2026-85706)

GitLab is urging users to patch a critical path traversal vulnerability, CVE-2026-85706, which has been assigned a CVSS score of 10.0. The flaw affects both Community and Enterprise Editions and allows an unauthenticated attacker to read arbitrary files from a vulnerable server, including credentials and configuration files. The vulnerability is being actively exploited in the wild, with security firms observing probes for vulnerable servers shortly after disclosure. CISA has added the flaw to its KEV catalog, requiring federal agencies to patch by September 16.

📖 Read full report →


5. Iranian MOIS Uses HEAVYGRAM Malware via Telegram C2

A joint advisory from the U.S., U.K., and Netherlands has exposed a cyber-espionage campaign by Iran's Ministry of Intelligence and Security (MOIS). The campaign uses a Windows malware called HEAVYGRAM (or CHOSEN BRICK) to spy on Iranian dissidents, journalists, and activists. A key feature of the malware is its use of the Telegram messaging app for command-and-control (C2), allowing operators to exfiltrate data and send commands covertly. The malware can copy emails, capture screenshots, and record audio, with the stolen information reportedly being published on pro-Iranian leak sites to intimidate victims.

📖 Read full report →


6. AI Drives New Cybersecurity Spending Priorities

A new report from research firm IANS and executive search firm Artico Search indicates that Artificial Intelligence is now the number one priority for new cybersecurity investments. Despite modest overall budget growth of just 5% in 2026, 69% of the 500+ CISOs surveyed are allocating new funds to AI-powered security tools. The primary areas of investment are security operations automation and identity and access management. The report also suggests AI is reshaping, not eliminating, security jobs, with 81% of CISOs expecting AI to create new roles and 91% believing it will make their current teams more productive.

📖 Read full report →


7. Tencent Sogou IME Flaw Exploited for RCE (CVE-2026-51990)

A critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method, a popular Chinese-language tool for Windows used by hundreds of millions, has been actively exploited by a Chinese threat actor. The flaw allows for one-click remote code execution. Researchers at Gen Threat Labs report that the attack chains three weaknesses: an argument injection flaw in a custom protocol handler (sgbiz://), unrestricted URL navigation, and an outdated, un-sandboxed Chromium engine. This combination allows an attacker to trick a user into clicking a malicious link to deploy a backdoor on their system.

📖 Read full report →


8. NIST Publishes Final Guidance on Access Token Protection

The U.S. National Institute of Standards and Technology (NIST) has published its final guidelines for securing digital identity and access tokens. The guidance, driven by major breaches where attackers used forged tokens to access government data, is aimed at cloud service providers and their customers, especially federal agencies. The final version is more outcome-based regarding cryptographic key protection, includes expanded advice on key management, and adds new considerations for securing AI systems and migrating to post-quantum cryptography (PQC). The document was developed in collaboration with industry partners through the Joint Cyber Defense Collaborative.

📖 Read full report →


📌 Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)