Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Sep 16, 2026·4m

Cyber Security News for September 16 2026 - Daily DefSec Brief

Show notes

1. WSO2 API gateway takes a forged admin token — CVE-2026-5430 — Do: Apply the WSO2 update level, rotate gateway secrets — https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/
2. Pixel modem zero-day used in targeted attacks — CVE-2026-58704 — Do: Push Pixel to the 2026-09-05 patch level — https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/
3. Malware forges Chrome's extension integrity hashes — Do: Allowlist extensions, alert on developer mode — https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html
4. Logitech Options+ gives a normal user SYSTEM — CVE-2026-12518 — Do: Upgrade Logi Options+ fleet-wide — https://blog.amberwolf.com/blog/2026/september/a-peripheral-path-to-system---exploiting-logi-options+-for-system-shells/
5. GlobalProtect privesc needs a PAN-OS upgrade too — CVE-2026-0307 — Do: Upgrade the app and PAN-OS together — https://security.paloaltonetworks.com/CVE-2026-0307
6. Parallels Desktop gives a local Mac user root — CVE-2026-90894 — Do: Upgrade Parallels Desktop to 27.0.0 — https://jfrog.com/blog/parallels-desktop-turns-appliance-install-into-root-shell/
7. Oracle's September update covers 672 flaws — Do: Patch E-Business Suite first — https://www.tenable.com/blog/oracle-september-2026-critical-security-patch-update-addresses-672-cves
8. Four of 800 hit their recovery target — Do: Run one full restore end to end — https://www.infosecurity-magazine.com/news/four-of-800-clients-hit-ransomware/
9. Gambling sites doubling as C2 infrastructure — Do: Re-examine gambling-domain hits in proxy logs — https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652
10. Fraudulent hires get credentials before detection — Do: Verify identity when credentials are issued — https://www.infosecurity-magazine.com/news/fraudulent-hires-credentials/
11. Most Mythic C2 servers keep the default cert — Do: Alert on O=Mythic certificates and port 7443 — https://censys.com/blog/mythic-c2/