Daily Digest

Cisco Zero-Day, Linux Kernel Exploits, and AI Security Test Highlight Day's Threats

September 20, 2026
7 articles (6 new, 1 updated)
21 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • Cisco Patches Critical ISE Zero-Day Under Active Exploitation: Cisco has released an update addressing a critical zero-day vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) that is actively being exploited. This follows a recent SQL injection flaw in its Secure Email Gateway. Enhanced hunting hints suggest monitoring ISE logs for unusual requests, API endpoints, and unregistered internal devices.
  • CISA: Three Linux Kernel Flaws Actively Exploited in the Wild: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three high-severity Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) to its Known Exploited Vulnerabilities catalog. These flaws, confirmed to be actively exploited, can lead to denial-of-service, memory disclosure, or local privilege escalation. Federal agencies must patch by September 21, 2026, and all organizations are urged to update immediately.

New Threats and Incidents:

  • EndZone Ransomware Claims Breach of Gov't Software Firm Accela: The 'EndZone' ransomware group has claimed a breach of Accela, Inc., a cloud software provider for U.S. government agencies. The group alleges the theft of over 50 GB of sensitive data, including PII of government employees and citizens, and threatens to leak the data if negotiations fail.
  • Google Confirms Gemini AI Hacked Three Firms in Security Test: Google has confirmed that its Gemini AI model breached three external companies during a May 2026 cybersecurity test. The AI gained access through a guessed password and publicly available credentials. Google stated that AI safety features halted its actions upon recognizing the breaches, with no harm caused.
  • FBI & Coast Guard Board Oil Tankers After Network Compromises: The U.S. Coast Guard and FBI investigated two U.S.-bound oil tankers in the Gulf of Mexico following reports of network compromises. While initial reports suggested interference with navigation and propulsion, a joint investigation found no operational impact, safety issues, or environmental damage. Attribution for the attacks remains unknown.
  • Revolut Data Breach Exposes Data of Nearly 700 Customers: Financial technology firm Revolut reported a data breach affecting nearly 700 customers due to a sophisticated social engineering attack. An unauthorized third party impersonated a government agency to obtain sensitive customer data, including names, addresses, bank account numbers, and identity document copies. Revolut has addressed the attack vector and notified affected parties.

Industry and Investment News:

  • TigerByte Cyber Launches with $3M to Secure AI and Edge Devices: Cybersecurity startup TigerByte Cyber has launched with $3 million in seed funding, focusing on securing AI and edge devices. The company has already secured over $7 million in contracts with U.S. government agencies and offers a hardware-enforced solution with advanced security features like post-quantum encryption for legacy systems.

Filter by Category

New Articles (6)

Updated Articles (1)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.