> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> InfoSec News Nuggets – 09/18/2026

[SOURCE] AboutDFIR [AUTHOR: Mary] [DATE: 18/09/2026 12:57] [LANGUAGE: EN]
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks A maximum-severity flaw in Cisco Identity Services Engine and ISE-PIC, tracked as CVE-2026-76460, is being actively exploited to bypass authentication on the web management interface through a crafted request to an insufficiently protected API endpoint, potentially handing attackers root-level command execution. Cisco has released patched versions across the 3.1 through 3.5 branches and warns there are no workarounds, only mitigations like restricting management traffic with access control lists, while CISA has ordered federal agencies to patch by September 19.   Critical ScreenConnect flaw now actively exploited in attacks A missing-authorization vulnerability in ConnectWise ScreenConnect, CVE-2026-84869, is now being exploited in the wild to transfer and execute files during active remote sessions without needing host confirmation, prompting CISA to add it to its known-exploited-vulnerabilities catalog and give federal agencies a tight remediation window. The bug is fixed in ScreenConnect 26.6.5 and later, but researchers still count more than a thousand unpatched, internet-exposed instances, a platform historically favored by both ransomware crews and state-backed hacking groups.   Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom Hackers spent roughly five months posing as a government agency to convince Revolut’s Lithuanian banking subsidiary to hand over customer files, ultimately obtaining personal and financial data on about 680 high-net-worth accounts, many belonging to cryptocurrency figures selected through blockchain wallet analysis. The attackers gained their foothold by compromising a government employee’s email through an infostealer infection, and a group calling itself IAmNotAVillain is now demanding a $3 million ransom while threatening to sell the records.   Severe TP-Link Tapo camera flaw lets hackers watch live feed from your home Researchers uncovered a trio of vulnerabilities in the widely sold TP-Link Tapo C200 home security camera, including a replay-based authentication bypass that lets an attacker on the same network gain administrator access without the owner’s password in just a few minutes, exposing live video, night vision, and two-way audio. A second disclosed flaw can crash the camera’s management service and lock out the legitimate owner, while a third, more serious network-takeover issue is being withheld until TP-Link finishes a fix; updated firmware addressing the disclosed bugs has already been released.   Windows 11 KB5124008 Update Breaks Active Directory Domain Trust and Blocks User Logins Microsoft is investigating reports that its September 8 cumulative update for Windows 11 24H2 and 25H2 is severing the secure channel between domain-joined machines and on-premises Active Directory controllers, leaving users unable to log in with valid credentials despite the update’s release notes not listing the issue. The trouble traces to Credential Guard’s Machine Identity Isolation feature failing to complete machine authentication after a restart, and administrators have found relief only through community workarounds like disabling the feature via Group Policy or rejoining affected machines to the domain, with no official vendor fix yet available. The post InfoSec News Nuggets – 09/18/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
[messages.read_original_source] →