IT Security Newsletter

IT Security Newsletter - 9/15/2026

Written by Cadre | Tue, Sep 15, 2026

Malicious actors already using critical GitLab flaw, CISA and others warn

Hackers have begun exploiting a serious vulnerability in a popular software development tool, the Cybersecurity and Infrastructure Security Agency is warning. CISA on Friday listed the vulnerability in GitLab's development platform in its Known Exploited Vulnerabilities catalog, giving federal agencies until Monday to mitigate the risks associated with the flaw. The vulnerability involves a lack of authentication requirements and a lack of restrictions on where users can place files. READ MORE...

Thai Broadband Provider Hacked via Fortinet Vulnerability

A threat actor targeted multiple vulnerabilities in Fortinet and F5 products to gain access to Thai broadband provider 3BB's systems, Hunt.io reports. The attack was discovered after the hackers left their intrusion arsenal in an open directory hosted on infrastructure in Thailand. The directory contained 298 files across 30 subdirectories: multiple exploitation scripts, brute-force and privilege escalation tools, credential harvesting scripts, an inventory of compromised machines, etc. READ MORE...

240,000 Hit by Data Breach at Japan's Digital Agency

Japan's Digital Agency has disclosed a data breach affecting the personal information of approximately 240,000 individuals. The incident, it says, was discovered in late June, after the hackers accessed files from its Government Solution Service (GSS) using a maintenance and operations employee's account. In July, the investigation determined that a vulnerability in a VPN product had been exploited to access the system. READ MORE...

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. Security researchers at Hudson Rock and ADAMnetworks analyzed the campaign and say the verified u/hbomax Reddit account was hijacked and used to launch 108 malicious advertisements over about 48 hours. The ads used a social engineering technique known as ClickFix. READ MORE...

Five alleged leaders of Black Axe's operations in South Africa extradited to US

Five alleged leaders of the South African wing of Black Axe, a global cybercrime group with operations spanning dozens of countries, were extradited to the United States Friday to face multiple charges, the Justice Department said. Officials accuse the five people, all originally from Nigeria, of running romance scams and advance fee scams from at least 2011 until they were all arrested in South Africa in 2021. READ MORE...

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday. The vendor's Product Security Incident Response Team became aware of active exploitation of this vulnerability in September 2025, and has shared indicators of compromise that organizations can look for to check whether they've been hit. READ MORE...

Microsoft releases emergency Windows updates to fix RDS failures

Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. The September 2026 security updates caused Remote Desktop Services (RDS) to become unstable on affected systems, leading to RDP connection and sign-in failures and, in some cases, unresponsive servers. READ MORE...

Google's new search redirects make links harder to check before you click

Google is changing how some links in its search results work. Instead of linking directly to the destination, Google has started routing some search result links through opaque google.com/goto?url=... redirects. The url parameter does not show a readable version of the destination but uses a custom, Google-specific encoding. The most likely reason is to make bulk extraction of destination URLs from Google search results more difficult and costly. READ MORE...

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

A likely Russian threat actor is deploying a sophisticated malware implant capable of harvesting credentials, scanning internal networks, and capturing live traffic on compromised devices by chaining two vulnerabilities in Cisco's Firewall Management Center (FMC) technology. In separate reports, Sophos and Cisco identified the malware as a new version of Cyclops Blink, a modular botnet and backdoor that US and UK government agencies have previously linked to Sandworm. READ MORE...

New hardware device can RAM into encrypted memory, expose your data

Computer security researchers have identified a design flaw in modern encryption hardware that allows access to protected memory in notionally confidential computing environments. But the attacker would need physical access to the victim system. Boffins affiliated with KU Leuven, ETH Zurich, Durham University, and Google have found that scalable memory encryption hardware fails to check whether the data in memory is fresh. READ MORE...

  • ...in 1857, 27th President William Howard Taft is born in Cincinnati, Ohio.
  • ...in 1858, the new Overland Mail Company sends out its first two stages, inaugurating government mail service between the eastern and western regions of the nation.
  • ...in 1928, jazz saxophonist Julian Edwin "Cannonball" Adderley ("Mercy, Mercy, Mercy") was born in Tampa, FL.
  • ...in 1978, boxer Muhammad Ali defeats Leon Spinks at the Louisiana Superdome in New Orleans to win the world heavyweight championship.