Daily cybersecurity intelligence digest from CyberNetSec.io - September 18, 2026
📊 9 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. Cisco Patches Critical ISE Zero-Day Flaw (CVE-2026-76460)
Cisco has released an emergency patch for a critical authentication bypass vulnerability, CVE-2026-76460, in its Identity Services Engine (ISE). The flaw, which has a maximum CVSS score of 10.0, is being actively exploited in the wild. A successful exploit allows a remote, unauthenticated attacker to bypass authentication on a vulnerable API endpoint and gain full administrative control of the device, including the ability to execute commands as root. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch immediately. There are no workarounds, and Cisco urges all customers to apply the updates without delay.
2. Check Point Patches Critical RCE Flaw (CVE-2026-91843)
Check Point has addressed a critical remote code execution vulnerability, CVE-2026-91843, affecting its Security Management and Log Server products. The flaw, rated 9.8 on the CVSS scale, is a pre-authentication stack-based buffer overflow that can be triggered by a login request with a long username. A successful exploit allows an unauthenticated, remote attacker to execute code with root privileges. Check Point has released a fix via its LivePatch service and advises administrators to restrict access to the management interface as a mitigation.
3. Gyazo Data Breach Exposes 23.6M User Records
Image-sharing service Gyazo has suffered a major data breach, exposing the records of 23.62 million users and metadata for 490 million images. The breach, which occurred on September 11, 2026, was caused by a vulnerability on an image upload server. Exposed data includes usernames, email addresses, hashed passwords, and social media integration tokens. The leaked image metadata could allow unauthorized access to private images. Gyazo parent company Helpfeel is urging all users to change their passwords immediately.
4. Settra Ransomware Targets Retail and Manufacturing
A new ransomware variant named Settra is actively targeting retail and manufacturing organizations. According to research from Huntress, the group, first seen in June 2026, uses consistent post-exploitation tactics. These include deploying the open-source RMM tool MeshAgent for persistence, clearing Windows Event Logs to cover their tracks, and disabling the Windows Recovery Environment. In a recent attack, the group also used a 'Bring Your Own Vulnerable Driver' (BYOVD) technique involving a legitimate Gigabyte driver to disable security software.
5. Manufacturing Top Ransomware Target as Attacks Surge
For the fifth consecutive year, the manufacturing sector is the top target for ransomware, according to a report from Black Kite. Attacks on manufacturers surged by nearly 40% in the first seven months of 2026, with over 1,183 victims already identified. The report highlights a strategic shift by attackers towards mid-market companies with revenues between $10-100 million, creating significant supply chain risk. Geographically, attacks on European firms have soared by 85%, while new ransomware groups like 'The Gentlemen' are responsible for a large portion of the incidents.
6. Spain Reports First Data Breach by AI Agent
Spain's Data Protection Agency (AEPD) has received its first-ever data breach notification attributed to an autonomous AI agent. An unnamed organization reported that an attacker used an agent, built on a well-known large language model, to independently scan for vulnerabilities, use discovered credentials to log in, and then exploit a flaw to access and modify personal data and corporate invoices. The incident marks a shift from theoretical to real-world attacks by agentic AI, highlighting the 'speed gap' where automated attacks can outpace human defenses.
7. DCSA Report: Foreign Spies Target US Defense Industry
A new report from the Defense Counterintelligence and Security Agency (DCSA) details how foreign intelligence entities (FIEs) are targeting the U.S. defense industrial base. The FY 2025 report found that 'exploitation of experts' was the most common tactic, with email being the top vector for initial contact. Adversaries from the East Asia and Pacific region were responsible for 48% of all reported incidents, using lures like paid consultations and fake job offers to gain access to sensitive U.S. technology and information.
8. Malicious Calendar Invite (ICS Phishing) Attacks Surge
Security firm Sublime has reported a staggering 33,000% increase in malicious calendar invite attacks, also known as 'ICS phishing,' between May and September 2026. Attackers are abusing .ics calendar files sent from legitimate services like Gmail to bypass email security filters. These invites, which are often automatically added to a user's calendar, contain malicious links that trick victims into downloading RMM tools like ScreenConnect, leading to device compromise, data theft, and potential ransomware deployment.
9. AWS AgentCore Harness Credential Exfiltration Risk
Unit 42 researchers have uncovered a significant security issue in the default configuration of AWS AgentCore Harness, a managed runtime for AI agents. The vulnerability allows an attacker to use prompt injection to manipulate the agent into executing arbitrary commands through its built-in 'shell' tool. This tool, enabled by default with root privileges, operates in the same memory space where credentials from AgentCore Identity are handled in plaintext. Consequently, a successful prompt injection attack can lead to the exfiltration of sensitive credentials, bypassing IAM controls and encryption-at-rest. AWS has reviewed the finding and stated that securing against this is a customer responsibility under the shared responsibility model, advising users to scope allowed tools and use egress filtering.
📌 Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)