HeadFlash

Security

Cisco Email Gateway Zero-Day Exploited; ScreenConnect Worm Patch Urged

Cisco Secure Email Gateway zero-day under attack, ConnectWise patches worm-exploited ScreenConnect flaw, and a Redis botnet hit 3,562 servers.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Cisco Warns Zero-Day in Secure Email Gateway Actively Exploited

Cisco disclosed that a zero-day in Secure Email Gateway appliances, tracked as CVE-2026-76461 with a CVSS score of 9.8, has been exploited in the wild. The flaw is an email parsing issue in AsyncOS that allows unauthenticated remote attackers to execute arbitrary commands with root privileges, and it affects both physical and virtual deployments in any configuration. Cisco’s PSIRT learned of exploitation in September 2026 but has not detailed the attacks or attributed them. CISA added the bug to its KEV catalog and ordered federal agencies to remediate by September 17. Secure Email and Web Manager and Secure Web Appliance are not impacted.

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation - SecurityWeek →

ConnectWise Patches ScreenConnect Flaw Used in Worm-Like Attacks

ConnectWise released urgent patches for CVE-2026-84869, a critical ScreenConnect vulnerability rated 9.9/10 that has been exploited in worm-like attacks. The missing authorization and improper privilege management flaw lets files be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. Huntress warned the bug had been exploited since August 20, with attackers using social engineering to run rogue ScreenConnect clients that pushed VBScript payloads for persistence and propagation. ConnectWise fixed it in version 26.6.5 and recommends disabling the TransferFiles permission as a temporary mitigation. CISA added it to the KEV catalog, giving federal agencies three days to patch.

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks - SecurityWeek →

Redis Cryptomining Botnet Compromised 3,562 Servers, Operator Files Reveal

An exposed open directory on port 80 revealed a Redis cryptomining operation that compromised 3,562 distinct Redis servers across two runs against a shared 12,966-host list, a 22 to 26 percent success rate, according to campaign logs first indexed by Hunt.io on June 21, 2026. Victims spanned Redis 2.8.17 through 7.2.0 and Linux from end-of-life RHEL/CentOS 6 to current Ubuntu kernels, indicating missing authentication rather than a version-specific bug. The main technique abused Redis master-replica replication to write a cron payload. A Monero wallet in the toolkit also appeared in a separate February 2026 open directory, extending the operator’s known activity by at least five months.

Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator’s Own Files →

North Korean APT Hits South Korean Media and Automotive Firms

Rapid7 attributed stealthy attacks on South Korean automotive and media companies to North Korean APT groups with medium confidence, citing targets, simple obfuscation, and command-and-control servers matching APT37, also known as InkySquid, ScarCruft, and Ricochet Chollima. Some victims have been compromised since early 2025. The group compromised open source load balancer HAProxy to install a Linux toolkit called TED, gaining access to decrypted traffic, harvesting credentials, redirecting users, and scrubbing log counters to hide activity. Rapid7 said the media focus suggests information control and counterintelligence, while automotive targets point to manufacturing technology intelligence. It warned organizations in South Korea and Asia-Pacific to scrutinize load balancers and network appliances.

Cyber Op Targets South Korean Media & Automotive Sectors →

Frappe LMS Flaws Chain Student Access to Remote Code Execution

Rhino Security Labs found vulnerabilities in open source Frappe LMS, including a chain letting a student user reach remote code execution on the server. CVE-2026-39405 is a path traversal in SCORM package upload: an unsanitized chapter title such as ../../../../../apps/lms extracts a malicious ZIP over api.py, adding a backdoor to a guest-accessible endpoint that runs shell commands. CVE-2026-34606 is a stored XSS in the profile bio, where BeautifulSoup’s get_text() concatenates harmless text nodes into a working script payload. Frappe fixed the issues by March 30, 2026, and the blog post was published September 15, 2026. Exploitation requires admin privileges but chains with the XSS.

Multiple Vulnerabilities in Frappe LMS Leading to Remote Code Execution - Rhino Security Labs →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches