Daily cybersecurity intelligence digest from CyberNetSec.io - September 17, 2026
📊 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. Cisco ISE Auth Bypass Zero-Day CVE-2026-76460 Actively Exploited
Cisco has issued an emergency patch for a critical, maximum-severity (CVSS 10.0) zero-day vulnerability in its Identity Services Engine (ISE). The flaw, tracked as CVE-2026-76460, allows a remote, unauthenticated attacker to completely bypass authentication and is confirmed to be actively exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating urgent patching for federal agencies.
2. GitLab Path Traversal Flaw CVE-2026-85706 Actively Exploited
A critical path traversal vulnerability in GitLab, CVE-2026-85706, is being actively exploited in the wild. The flaw, rated CVSS 10.0, allows an unauthenticated, remote attacker to read arbitrary files from self-managed GitLab instances with a single HTTP request. The vulnerability requires no user interaction and can lead to the theft of sensitive credentials, tokens, and other secrets. CISA has added it to its KEV catalog, urging immediate patching.
3. CISA KEV Catalog Updated with Cisco and Acronis Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two actively exploited vulnerabilities to its KEV catalog. The flaws, a critical authentication bypass in Cisco's Identity Services Engine (CVE-2026-76460) and an incorrect permissions flaw in Acronis Backup (CVE-2026-87886), now require remediation by U.S. federal agencies under a binding directive.
4. Gyazo Data Breach Exposes 23.6 Million User Records
The popular image-sharing service Gyazo, operated by Helpfeel, has disclosed a massive data breach affecting 23.62 million user records and 490 million image metadata records. The breach was the result of a remote code execution vulnerability on an image upload server, which gave an attacker access to the service's database. Exposed data includes email addresses, hashed passwords, and social media integration tokens.
5. CISA Releases Guidance on Cyber Decoy Strategies for Defense
CISA has published new guidance to help critical infrastructure organizations and other defensive teams implement cyber decoys. The guide, "Using Cyber Decoys to Strengthen Detection and Response," details how to use techniques like honeytokens, breadcrumbs, and tripwires to detect, observe, and disrupt intruders early in the attack lifecycle, especially those using stealthy living-off-the-land techniques.
6. Manufacturing Ransomware Attacks Surge 40%, Report Finds
A new report from Black Kite reveals that the manufacturing sector continues to be the primary target for ransomware gangs, with attacks increasing by nearly 40% year-over-year in the first half of 2026. The research also highlights a shift in victimology, with attackers increasingly targeting smaller companies and expanding their geographic focus, particularly in Europe. The ransomware landscape itself is also evolving, with new groups like 'The Gentlemen' becoming highly active.
7. Fake AI Trading Bots Used to Distribute Crypto-Stealing Malware
A new HP threat report details a campaign where cybercriminals exploit interest in Agentic AI tools to trick users into downloading malware. One campaign used a fake AI trading bot to deploy an info-stealer called Needle Stealer. The malware replaces legitimate cryptocurrency wallet browser extensions, such as MetaMask and Coinbase Wallet, with malicious versions designed to harvest credentials and drain funds.
8. Japan Ransomware Attacks Rise, 'The Gentlemen' Group Most Active
A Cisco Talos report reveals that ransomware incidents in Japan increased by 4.7% in the first half of 2026 compared to the previous year. The ransomware group known as 'The Gentlemen' has emerged as the most active threat actor, primarily targeting small-to-medium enterprises (SMEs), which accounted for 80% of all victims. The group operates a Ransomware-as-a-Service (RaaS) model and employs double-extortion tactics.
📌 Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)