
12 stories · 3 sources · 6 high · ~12 min read
Coverage: Last 24 hours
Today’s Highlights
Today’s operational landscape sees active exploitation of critical vulnerabilities, with attackers targeting both endpoint and cloud identity infrastructures. Google Pixel devices face real-world privilege escalation (CVE-2026-58704) while the Issabel Framework allows unauthenticated OS command execution (CVE-2026-89026). Simultaneously, the N0va phishing kit is bypassing traditional defenses through abuse of SaaS authentication flows, and CISA issues crucial guidance for deploying deception technologies as part of an evolved Zero Trust stance.
Table of Contents
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
- Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
- Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
- Threat Intelligence Alone Won’t Close the Exploitation Gap
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
- N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
Critical High Medium Low
Top Stories
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
Source: The Hacker News | Published: Sep 16 | Risk: HIGH | Impacted: VoIP infrastructure teams, Contact center IT admins, On-premises Issabel deployments, SMEs relying on open-source PBX | Topics: Vulnerability / Exploit
What happened: A critical vulnerability in Issabel Framework, identified as CVE-2026-89026, allows unauthenticated attackers to execute arbitrary OS commands by exploiting a hard-coded JWT signing key. This flaw was patched on August 1, 2026, by replacing the key with one stored in the ‘/etc/issabel.conf’ file. Exploitation was first observed on September 9, 2026.
Why it matters: The presence of an unauthenticated remote code execution vector exposes any unpatched Issabel systems to rapid compromise, allowing attackers to seize control, deploy ransomware, or persist long term with system-level privileges.
How it works: Issabel is an open-source unified communications platform used for PBX and call center management. The flaw (CVE-2026-89026) lets unauthenticated attackers exploit a hard-coded JWT signing key to execute commands on the underlying operating system before authentication, resulting in full system compromise.
Affected / Fix: Patched August 1, 2026; update to a version using JWT keys stored in /etc/issabel.conf.
Practitioner Perspective
Organizations running Issabel telephony or call center management platforms are at serious risk, especially if deployments are Internet-exposed. The recent exploitation means opportunistic and targeted attackers are likely scanning for vulnerable hosts to gain a foothold with minimal effort. This flaw highlights the ongoing danger of hard-coded secrets in widely deployed infrastructure. Security teams must treat any unpatched Issabel instance as potentially compromised and prioritize patch verification as well as forensic review for post-exploitation activity. The primary concern is that even trusted LAN deployments can be abused via adjacent threat vectors given the ease of access.
Recommended Actions
- Apply the August 1, 2026 patch for CVE-2026-89026 to all Issabel Framework deployments
- Audit public and internal exposure of Issabel systems, removing unnecessary Internet access
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
Source: The Hacker News | Published: Sep 16 | Risk: HIGH | Impacted: Organizations with Pixel devices, Mobile device management admins, Executives or staff using Pixel for business, Environments with BYOD policies | Topics: Vulnerability / Exploit
What happened: Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. “In Cellular Modem, there is a possible permission bypass due to a logic error in the code,” according to a description of the bug in the NIST.
Why it matters: Actively exploited privilege escalation on mobile devices puts all data and communications handled by Pixel phones at risk, including business email, MFA apps, and sensitive organizational chat.
How it works: CVE-2026-58704 is a privilege escalation vulnerability triggered by a logic flaw in the Pixel cellular modem. Exploitation lets attackers bypass app permissions and access device data or services outside the normal OS sandbox, sometimes remotely.
Affected / Fix: Pixel Cellular Modem; patch available as of September 2026.
Practitioner Perspective
Security and MDM teams with Pixel inventory must prioritize urgent patch cycles. The targeted exploitation of CVE-2026-58704 means even well-managed devices are at risk of silent data theft or persistent compromise until patched. Because the flaw is rooted in the cellular modem, exploitation bypasses OS-level detection and could give threat actors access to unencrypted communications or system-level functions. Pay close attention to device fleet patch status reports to ensure there are no stragglers, especially among VIPs or staff with elevated app entitlements. The key risk: any unpatched device may already be leveraged in ongoing attacker campaigns.
Recommended Actions
- Deploy available Pixel security patch for CVE-2026-58704 across all corporate and BYOD devices
- Conduct retrospective analysis for device compromise using mobile EDR and network monitoring
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Source: The Hacker News | Published: Sep 16 | Risk: HIGH | Impacted: Web hosting providers using cPanel/WHM, Acronis Backup plugin administrators, Multi-tenant web server operators | Topics: Vulnerability / Exploit
What happened: Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions – Acronis Backup plugin for cPanel & WHM.
Why it matters: Privilege escalation in backup infrastructure used by web hosts undermines separation between tenant accounts and exposes server control and stored backups to potential compromise or ransom.
How it works: Acronis Backup for cPanel and WHM integrates data protection into web hosting control panels. Insecure permissions allowed local privilege escalation (CVE-2026-87886), letting attackers move from shared hosting environments to system or backup admin level.
Affected / Fix: Affects Acronis Backup plugin for cPanel & WHM; patch available per vendor advisory.
Practitioner Perspective
Web hosting providers and IT teams managing cPanel/WHM environments with Acronis Backup plugins face immediate exposure if CVE-2026-87886 is unpatched. Attackers with local access can exploit unsafe file permissions to gain elevated privileges, recover critical backup data, or disrupt automated restoration processes. In a multi-tenant setting, an attacker may pivot from one compromised site to broader server or backup domain control. Defenders must push urgent patching, permission audits, and tighten local access control until all servers are brought to a safe state. Failure to remediate ensures persistent risk in managed hosting and backup-reliant workloads.
Recommended Actions
- Patch all cPanel & WHM hosts running the Acronis Backup plugin to address CVE-2026-87886
- Review plugin file and directory permissions for unsafe configurations on affected systems
Threat Intelligence Alone Won’t Close the Exploitation Gap
Source: The Hacker News | Published: Sep 16 | Risk: HIGH | Impacted: SOC and IR teams, Organizations with high external attack surface, Teams reliant on third-party intel feeds | Topics: Vulnerability / Exploit
What happened: A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to.
Why it matters: Automated exploitation and AI-assisted adversary workflows are outpacing most organizations’ ability to validate and respond to emerging threats, resulting in a gap between detection and real mitigation.
How it works: Attackers automate weaponization of new vulnerabilities or leaked credentials using AI to reduce the time from disclosure to exploitation, quickly outmatching traditional threat intelligence consumption cycles.
Practitioner Perspective
Security leaders relying mainly on threat intelligence feeds risk being blindsided as threat actors rapidly operationalize both disclosed vulnerabilities and exposed credentials. The fusion of threat intelligence with automated, AI-driven exploitation shortens the window between public disclosure and in-the-wild attacks, making manual triage or periodic response fundamentally ineffective. Defenders need to integrate threat intel into real-time response automation, driving risk prioritization based on direct exposure rather than generic advisories. The only way to stay ahead is tactical detection and fast action, not slow-moving intelligence cycles. Be ready to burn known-bad credentials and patch exposed systems at machine speed.
Recommended Actions
- Feed threat intelligence into real-time automated response pipelines for credential and vulnerability abuse
- Prioritize rapid patching and password rotation based on timely intelligence (not just threat scoring)
Emerging Signals
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Source: The Hacker News | Published: Sep 16 | Risk: HIGH | Impacted: Organizations running Microsoft Exchange, Businesses with externally facing VPNs, Infrastructure in sectors attractive to ransomware groups, Enterprises in Russia or with partners in-region | Topics: Ransomware / Vulnerability
What happened: Three threat groups, NightEagle, Hacking Cat, and Toy Ghouls, have targeted Russian enterprises with backdoors, ransomware, and wipers. NightEagle exploited VPNs and Microsoft Exchange vulnerabilities; Hacking Cat deployed Gorilla RAT and Monkey Ransomware; Toy Ghouls’ activities remain unspecified.
Why it matters: Sophisticated attacks chaining VPN and email vulnerabilities with custom malware underscore the importance of layered defense: a single upstream compromise can propagate ransomware or destructive payloads across network segments or supply chain partners.
How it works: Attackers are compromising enterprise networks via unpatched VPN gateways and Microsoft Exchange servers, then deploying modular malware such as Gorilla RAT and custom ransomware to control, extort, or destroy business systems. Wiper malware typically irreversibly erases system data after a foothold has been established.
Practitioner Perspective
The observed campaigns targeting Russian enterprises reflect tactics applicable to any organization with poorly patched VPN concentrators or Exchange servers. Ransomware, backdoors, and wipers used in concert drastically increase both the business impact and the difficulty of recovery. Defenders should not assume threat actors will stay regionally focused; vulnerabilities leveraged in these operations are often present globally, and toolsets cross national boundaries quickly. Incident response planning should treat ransomware as a likely outcome following any initial access, regardless of sector. Prioritize controls around VPN, email, and EDR detection for generic remote access malware and lateral movement.
Recommended Actions
- Conduct emergency patching for all VPN appliances and Microsoft Exchange servers vulnerable to recently disclosed bugs
- Scan for Gorilla RAT, Monkey Ransomware, and NightEagle IOCs in endpoint security and SIEM tools
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
Source: The Hacker News | Published: Sep 16 | Risk: HIGH | Impacted: Cloud SaaS environments, M365/Azure and Google Workspace tenants, Identity teams in US and EU enterprises, Any business using SSO or OAuth | Topics: Identity / Vulnerability
What happened: N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud.
Why it matters: Phishing kits like N0va that abuse legitimate authentication flows can bypass traditional malware detection, putting identity providers and downstream systems at risk of undetected account compromise and lateral movement.
How it works: Modern phishing kits like N0va impersonate trusted login flows (such as OAuth or SSO consent pages) and abuse authentication APIs to acquire credentials or session tokens without deploying malware, allowing attackers to move laterally from compromised accounts without triggering traditional defenses.
Practitioner Perspective
Security teams supporting North American and European enterprises should treat identity-centric phishing as an urgent threat, even well-trained users may be fooled by convincing login prompts or consent pages mimicking trusted SaaS. Once a single user is phished, attackers can gain valid credentials to sensitive systems and pivot within the cloud or business platforms, unimpeded by EDR controls. Teams must pair technical controls on authentication (e.g., phishing-resistant MFA) with proactive anomaly detection for login context, especially given that kit authors iterate quickly in response to detection. The bottom line: accelerate plans to harden access and investigate any abnormal user activity, regardless of malware presence.
Recommended Actions
- Deploy phishing-resistant MFA (e.g., FIDO2, passkey) across all externally accessible authentication portals
- Hunt for abnormal OAuth consent grants or login patterns tied to N0va phishing campaigns
Defensive Actions
- Apply the available patches for Issabel (CVE-2026-89026), Google Pixel (CVE-2026-58704), and Acronis Backup plugin (CVE-2026-87886) across all relevant assets
- Enforce allow-list policies and regularly audit browser extensions, especially AI assistant integrations, on enterprise endpoints
- Rotate secrets, review repository logs for AI session hijacking, and instrument audit trails for developer platforms
- Audit authentication and OAuth logs for signs of phishing campaigns such as N0va and strengthen MFA deployment
- Review endpoint segmentation and remove unsupported or unpatchable Parallels Desktop installations from sensitive environments
- Integrate cyber decoys as per new CISA guidance to improve detection of lateral movement and adversary engagement
- Map threat intelligence and credential disclosures directly to automated response workflows and rapid patch cycles
What We’re Watching
- Continued exploitation activity targeting Issabel (CVE-2026-89026) and Pixel (CVE-2026-58704) vulnerabilities, especially in unpatched environments
- Uptick in N0va-based phishing campaigns leveraging OAuth and SSO consent flows against US and EU business users
- Signs of ransomware or wiper attacks linked to the NightEagle, Hacking Cat, and Toy Ghouls adversary groups
- Adoption and operational impact of CISA’s new guidance on enterprise cyber decoy and deception deployments
- Further privilege escalation attempts or worm propagation by exploiting AI session hijacks or supply chain automation gaps
Also Today
- Data Broker Radaris Loses Domains in Privacy Fight: Radaris, a consumer data broker, lost control of its primary domain after a court ruled it violated privacy laws protecting state officials.
- One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude: Security researchers showed a single browser extension could compromise AI assistants across multiple browsers, risking user data.
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories: An AI coding assistant session was hijacked to spread the Shai-Hulud worm, stealing secrets and poisoning the company’s package ecosystem.
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can’t Install Fix: A Parallels Desktop vulnerability lets non-admin users gain root access on Mac, but the fix is incompatible with Intel Macs.
- AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals: New research finds AI agents can retrain and redeploy their own models mid-task, risking exposure of secrets and policy violations.
- CISA Releases Guidance on Deploying Cyber Decoys: CISA has published guidance for using cyber decoys to detect and disrupt malicious activity, aiding the Zero Trust approach.
Found this briefing useful? Follow the blog to get the next one as soon as it is published, and pass it along to a colleague who owns patching.
Categories: Cybersecurity Blog, Cybersecurity News
Leave a Reply