1. Cisco email gateway zero-day exploited for root — CVE-2026-76461, CVSS 9.8 — Do: Upgrade AsyncOS 16.5.0-780, grep mail_logs — https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploited-to-execute-commands-as-root/
2. Vite dev servers scanned for cloud credentials — CVE-2026-39364, CVSS 7.5 — Do: Upgrade Vite to 7.3.2 or 8.0.5 — https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/
3. AI agents ran a credential campaign in six hours — Do: Shorten cloud key lifetimes and alert on scanning — https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html
4. LiteSpeed flaw takes a hosting account to root — no CVE assigned — Do: /usr/local/lsws/admin/misc/lsup.sh -f -v 6.3.7 — https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html
5. Apple patches 261 flaws across every OS — Do: Update Mac security tools before macOS 27 — https://isc.sans.edu/diary/rss/33336
6. Homebrew 7.0.0 closes a sudo path in casks — Do: Install Homebrew 7.0.0 on developer Macs — https://www.helpnetsecurity.com/2026/09/15/homebrew-7-0-0-security-open-source/
7. MeshCentral used as the backdoor at a broadband ISP — CVE-2024-21762 in the toolkit — Do: Hunt for RMM agents you never deployed — https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html
8. AWS TEAM grants access it was not asked for — CVE-2026-86830, CVSS 7.2 — Do: Upgrade TEAM to 1.5.1, forks included — https://aws.amazon.com/security/security-bulletins/rss/2026-112-aws/
9. An unpatched VPN cost Japan 246,000 records — Do: Alert on bulk file reads by service accounts — https://securityaffairs.com/199090/security/non-zero-day-vpn-flaw-left-japan-government-shared-network-platform-exposed-246000-records-at-risk.html
10. Office update breaks copy and paste in Excel — Do: Warn the help desk about KB5002914 — https://www.bleepingcomputer.com/news/microsoft/microsoft-september-kb5002914-security-update-breaks-excel-copy-and-paste/
11. WordPress scans plugin updates before shipping — Do: Leave WordPress plugin auto-updates on — https://thehackernews.com/2026/09/wordpress-adds-automated-plugin-reviews.html
12. A $159 board defeats confidential computing — no CVE will be assigned — Do: Recheck what you claim confidential computing proves — https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html