> InfoSec News Nuggets – 09/17/2026
[AUTHOR: Mary]
[DATE: 17/09/2026 11:09]
[LANGUAGE: EN]
Spain Gets Its First Taste of AI-Aided Cyber Attack
Spain’s data protection agency, the AEPD, has logged the country’s first personal data breach attributed to an autonomous AI agent, with the agency’s president confirming an individual deployed an agent built on a known large language model to carry out a multi-stage attack against an organization. The agent scanned generic files, logged into the target’s systems, ran vulnerability scans to find flaws granting read/write access to files containing personal data, then modified records and accessed invoices — chaining together multiple attack phases with minimal human steering at each step. Neither the affected organization nor the specific AI model has been publicly identified, and the AEPD has not independently verified the notification through forensic investigation, but the filing marks the first time a national data protection authority has formally logged an AI agent as the named attacker in an official breach record.
Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
Cisco disclosed CVE-2026-76461, a critical SQL injection flaw in the email-parsing logic of Cisco AsyncOS for Secure Email Gateway, that attackers were already exploiting before public disclosure to gain root command execution with no authentication or user interaction required. An attacker simply sends a crafted email containing malicious SQL statements through an affected gateway, triggering arbitrary SQL execution that escalates to full root-level OS command execution — Cisco found the flaw while resolving a customer support case rather than through routine internal review, and has confirmed no workaround exists. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and gave federal agencies a three-day remediation window; administrators should check mail_logs for suspicious SQL statements and treat any affected internet-facing gateway as a priority patch.
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-Day Exploits in Chrome & Windows
Volexity identified at least two Chinese threat clusters, UTA0560 and JungleBamboo (APT31), independently exploiting the same three-vulnerability Chrome-Windows zero-day chain — dubbed BlueMoon — to compromise NGOs starting September 1, with attacks beginning during the narrow window between when Chromium patches a flaw upstream and when it reaches released Chrome builds. The chain starts with a spear-phishing email linking to a legitimate university website vulnerable to reflected XSS, which redirects victims into a sequence that gains arbitrary read/write inside the V8 sandbox, escapes the browser sandbox, then injects code into the Chrome process for full arbitrary code execution. UTA0560 deployed a JScript backdoor called GRIMWEDGE for host reconnaissance and command execution, while JungleBamboo used a separate loader to install a credential-stealing Chrome extension — both groups reusing identical shellcode, suggesting the tight patch-gap window forced shared tooling rather than independent development.
Third-Party WooCommerce Plugin Hits WordPress Sites With PHP Backdoor Abusing Recently Patched Vulnerability
Attackers are actively exploiting CVE-2026-27540, an unauthenticated arbitrary file-upload flaw in WooCommerce Wholesale Lead Capture — a premium plugin with roughly 6,000 active installs — to plant PHP webshells on WordPress sites, despite a patch having been available since February. Wordfence has blocked more than 100,000 exploitation attempts since June by tracking a single unauthenticated request to an AJAX action that improperly validates uploaded file types, allowing attackers to smuggle a PHP shell that reports host details and offers a browser-based interface for planting further malicious files. Because a webshell planted before patching can persist even after the vulnerable upload path is closed, site administrators running an affected version should update to 2.0.3.2 immediately and separately check their uploads directory and access logs for signs of prior compromise.
TP-Link Cameras 0-Day Vulnerabilities Allow Attackers to Spy on Users
OPSWAT researchers disclosed two zero-day vulnerabilities in TP-Link’s widely deployed Tapo C200 smart camera, commonly used for home security, baby monitoring, and small-office surveillance, that could let a network-adjacent attacker either bypass authentication entirely or crash the device’s management service. The more serious flaw, CVE-2026-15315, exploits a replay weakness in the camera’s challenge-response authentication to establish a valid administrative session without ever knowing or recovering the password — granting full access to live video, stored recordings, and device configuration. Both flaws were patched in firmware V5_1.4.6 released August 18, and OPSWAT says it’s still working with TP-Link on a third, more severe vulnerability that could allow full device compromise and use the camera as a foothold into the rest of the local network.
The post InfoSec News Nuggets – 09/17/2026 appeared first on AboutDFIR - The Definitive Compendium Project.