Daily Digest

Critical Exploits, Ransomware Surge, and New Defense Guidance

September 17, 2026
8 articles (6 new, 2 updated)
24 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • Cisco ISE Zero-Day (CVSS 10.0) Under Active Attack, Bypasses Auth: Cisco has released an emergency patch for a critical zero-day vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE). This flaw allows unauthenticated attackers to bypass authentication and is actively being exploited. CISA has added it to its KEV catalog, mandating urgent patching for federal agencies.
  • CISA Adds Actively Exploited Cisco and Acronis Flaws to KEV Catalog: CISA has added two actively exploited vulnerabilities to its KEV catalog: CVE-2026-76460, a critical authentication bypass in Cisco ISE, and CVE-2026-87886, an incorrect permissions flaw in Acronis Backup. Remediation is now required for U.S. federal agencies.
  • GitLab CVSS 10.0 vulnerability exploited one day after disclosure: A critical vulnerability in GitLab (CVE-2026-85706) with a CVSS score of 10.0 was exploited shortly after its disclosure. The vulnerability could lead to the exfiltration of SSH keys and cloud credentials. New detection strategies include monitoring specific log files and observing unusual user activity.

Ransomware Trends and Targeted Attacks:

  • [UPDATE] Ransomware Attacks Hit 2026 High in July, NCC Group Reports: Manufacturing remains the top ransomware target, with attacks increasing 39.7% year-over-year in H1 2026. Europe, particularly Germany, has seen a significant rise in victims, while the US share has decreased. Small-to-medium enterprises (SMEs) are increasingly targeted, and the group 'The Gentlemen' is highly active.
  • Ransomware Attacks in Japan Rise; 'The Gentlemen' Group Dominates: Cisco Talos reports a 4.7% increase in ransomware incidents in Japan during H1 2026. The 'The Gentlemen' ransomware group is the most active, primarily targeting SMEs, which constitute 80% of their victims. This group utilizes a Ransomware-as-a-Service model and double-extortion tactics.

New Threats and Defense Strategies:

  • Gyazo Screenshot Tool Breach Exposes 23.6M User Records, Image Data: The image-sharing service Gyazo has disclosed a breach affecting 23.62 million user records and 490 million image metadata records. The incident stemmed from a remote code execution vulnerability on an image upload server, exposing email addresses, hashed passwords, and social media tokens.
  • Scammers Use Fake AI Trading Bots to Steal Crypto Wallets: Cybercriminals are leveraging interest in AI tools by distributing malware through fake AI trading bots. One campaign deployed the Needle Stealer info-stealer, which replaces legitimate cryptocurrency wallet extensions with malicious versions to harvest credentials and drain funds.
  • CISA Publishes Guide for Using Cyber Decoys to Detect Intruders: CISA has released new guidance on implementing cyber decoys to enhance detection and response capabilities. The guide outlines techniques like honeytokens, breadcrumbs, and tripwires to identify, observe, and disrupt intruders early in their attack lifecycle, particularly those employing stealthy methods.

Filter by Category

New Articles (6)

Updated Articles (2)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.