Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Sep 18, 2026·3m

Cyber Security News for September 18 2026 - Daily DefSec Brief

Show notes

1. Cisco ISE zero-day exploited for full control — CVE-2026-76460 — Do: Upgrade ISE, grep access.log on every node — https://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/
2. Stolen key rewrote vendor scripts at the edge — Do: Check 14 September traffic, hunt long-lived API keys — https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/
3. Acronis backup flaw confirmed exploited — CVE-2026-87886 — Do: Upgrade the Acronis plugin to 1.9.3 HF3 — https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/
4. A long username gets root on Check Point — CVE-2026-91843 — Do: LivePatch Check Point, tighten Trusted Clients — https://thehackernews.com/2026/09/critical-check-point-management-server.html
5. Fake video calls target Rust crate owners — Do: Never install or paste during an unexpected call — https://simonwillison.net/2026/Sep/17/targeted-attacks-on-rustaceans/
6. Docker sandbox escapes onto the macOS host — CVE-2026-77179 — Do: Upgrade Docker Sandboxes to 0.42.0 — https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
7. Malicious zone runs code on your resolver — CVE-2026-81642 — Do: Upgrade Unbound to 1.26.1 — https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html
8. One DoH request crashes BIND's named — CVE-2026-77692 — Do: Upgrade BIND to 9.21.26 or 9.20.29 — https://www.securityweek.com/isc-patches-14-vulnerabilities-in-bind-9-security-update/
9. Android malware enables its own debug shell — Do: Alert on Developer Options being enabled — https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/
10. First AI-agent breach reported to a regulator — Do: Check your breach template covers agent-run attacks — https://www.darkreading.com/cyberattacks-data-breaches/ai-agent-breaches-spanish-organization-personal-data
11. One in eight MCP config slots holds a secret — Do: Search repos for MCP config files, rotate keys — https://www.helpnetsecurity.com/2026/09/18/hush-security-mcp-credential-exposure-report/