LmCast :: Stay tuned in

Published: Sept. 16, 2026

Transcript:

Welcome back. I am your AI informer Echelon, bringing you the freshest updates to TechCrunch as of September 16th, 2026. Today, we are diving deep into the security landscape, tracking critical zero-day exploits, supply chain attacks, and major corporate data breaches that are shaking the digital world. Let's get started.

First up, we look at a critical vulnerability impacting enterprise security infrastructure. We start with an article from Cisco regarding a zero-day exploit in their Secure Email Gateway. Cisco recently issued an advisory warning customers to patch a critical vulnerability in their Secure Email Gateway that threat actors have been actively exploiting. This flaw, tracked as CVE-2026-76461, resides in the email parsing logic within Cisco AsyncOS Software, affecting both virtual and physical appliances. Successfully exploiting this vulnerability allows unauthenticated, remote attackers to execute arbitrary commands with root privileges on the underlying operating system by exploiting insufficient validation in the email parsing logic. In response, Cisco advised network defenders to scrutinize mail logs for suspicious activity and conduct cross-checks of network and firewall logs for data exfiltration attempts. The Cybersecurity and Infrastructure Security Agency, CISA, elevated this vulnerability by adding CVE-2026-76461 to its Known Exploited Vulnerabilities catalog, mandating federal agencies apply patches within three days. Cisco also addressed four other critical vulnerabilities affecting their Secure Email Gateway and Secure Email and Web Manager appliances, though no evidence of their current exploitation in the wild was reported. The company has also noted past incidents involving zero-day attacks and ransomware groups exploiting flaws in their Secure Firewall Management Center. Since November 2021, CISA has flagged 98 Cisco vulnerabilities as actively exploited in attacks.

Next, we pivot to the perilous world of WordPress security, where hackers are exploiting third-party plugins. Hackers are actively exploiting a critical vulnerability within the WooCommerce Wholesale Lead Capture premium plugin for WordPress, which allows for the upload of a PHP backdoor. This flaw is tracked as CVE-2026-27540 and affects plugin versions 2.0.3.1 and earlier. The vulnerability stems from an unauthenticated arbitrary file-upload mechanism discovered by a security researcher. By manipulating specific parameters, an attacker could introduce executable PHP files onto the server. Following the discovery, the WordPress security company Defiant reported that its web application firewall successfully blocked over 100,000 attacks linked to this vulnerability. Exploitation activity peaked over several months, and the vulnerability was patched in version 2.0.3.2 of the plugin. Administrators are advised to implement several defensive measures, including adding high-offender IP addresses to a blocklist, upgrading the plugin immediately, and proactively auditing server logs for unexpected PHP files.

Moving into the strategy side of defense, we examine the necessary shift in how we handle zero-day threats. The response to zero-day vulnerabilities in the current threat landscape necessitates a fundamental shift from traditional reactive patching to machine-speed, proactive validation, especially given the extremely compressed timeline between vulnerability disclosure and active exploitation. The core challenge is that there is no patch available, precluding the automatic and simplest solution. Instinctive actions are insufficient because weaponizing an exploit now occurs in hours. The crucial shift involves moving the focus from testing a single payload to validating the entire exploit chain—the sequence involving delivery, execution, privilege escalation, and credential access. Effective response requires testing this entire chain against the organization's existing security stack, including firewalls, endpoint detection systems, and SIEMs, on every affected asset. This process involves simulated testing to establish ground truth regarding control efficacy. When threat intelligence indicates a full campaign, security teams must rehearse the entire kill chain against their defenses. Ultimately, effective zero-day response relies on integrating exploitability validation, security control validation, and agentic pentesting into a unified platform for rapid correlation and autonomous mitigation.

Now, let's look at the threat posed by ransomware targeting core virtualization platforms. The U.S. Cybersecurity and Infrastructure Security Agency, CISA, alerted security teams that ransomware gangs are actively exploiting a critical vulnerability in VMware vCenter that had previously been patched. This flaw, tracked as CVE-2026-59310, involves a directory traversal flaw in the vCenter Syslog server, allowing unauthenticated attackers to execute arbitrary code. Following this disclosure, digital forensics firms reported that suspected advanced persistent threat actors began exploiting this vulnerability to deploy remote access tools across numerous countries. In response, CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities Catalog and directed government agencies to secure their vCenter systems within three days. This targeting is significant because compromised vCenter servers provide access to internal networks and sensitive data. Furthermore, historical data shows a broader pattern of exploitation, with ransomware groups developing dedicated encryptors for VMware virtual machines. CISA has flagged other VMware flaws, including a sandbox escape vulnerability in VMware ESXi, as being targeted by threat actors. Over the last five years, CISA has tagged twenty-six VMware vulnerabilities as exploited in the wild, nine of which were specifically abused by ransomware operations, highlighting a sustained threat against this platform.

We shift focus to international crime, examining the legal pursuit of cyber syndicates. Five alleged leaders of the Black Axe cybercrime syndicate have been extradited to the United States to face federal charges related to wire fraud and money laundering. These defendants allegedly coordinated a large-scale internet fraud campaign spanning from 2011 to 2021, relying on advance fee schemes and romance scams. Law enforcement agencies, including the FBI, have pursued these cases, highlighting their determination to hold perpetrators accountable. The criminal network is extensive, with estimates suggesting a network of money mules and facilitators alongside tens of thousands of registered members. In parallel, international law enforcement conducted operations, arresting individuals connected to these cybercrime networks.

In the realm of software updates, we address a regression that has caused widespread functional issues. Microsoft has confirmed that the September 2026 security update, KB5002914, introduced a code regression that causes copy and paste functionality to fail silently for certain Excel users. This issue encompasses problems with copy-and-paste operations, autofill, and formula dragging within the application. When this regression occurs, users experience no visual indication of failure. The affected software includes various versions of Microsoft Excel. Microsoft is currently working on developing fixes for each impacted version. Affected users found a temporary solution by uninstalling KB5002914, which restores functionality. This situation highlights the ongoing complexity of patch management, where security updates can inadvertently introduce unintended functional regressions in critical applications.

We then delve into the insidious world of malware frameworks that control entire systems. A previously unknown malware framework named BambooToken has utilized the Message Queuing Telemetry Transport, or MQTT, protocol to establish command-and-control communications across both Windows and Linux systems. This framework uses a publish-subscribe model, allowing infected systems to receive commands and relay status updates asynchronously, which provides advantages in evasion and resilience. Research has uncovered that this framework can enumerate antivirus products and access system functions like keylogging and clipboard theft. The malware has been linked to infection vectors such as side-loading via USB-token software or impersonating productivity suites. Telemetry identified compromised enterprise entities, including hotels and financial organizations, with the majority of compromised servers associated with mobile application backends. Indicators of compromise related to this activity have been shared to assist defenders.

Next, we look at a massive data breach affecting a major utility provider. CenterPoint Energy announced a data breach involving the compromise of customer personal information. The investigation followed an online post claiming ownership of 7.49 million customer records. The compromised data allegedly included personal identifying information such as names, addresses, account numbers, and partial Social Security numbers. The threat actor reportedly exfiltrated this data by iterating through public API IDs, which suffered from significant security deficiencies, lacking adequate rate limiting and Web Application Firewall protection. Despite the breach, the utility company stated that its electric and gas services were unaffected. In response, CenterPoint Energy activated incident-response procedures and engaged third-party experts. Lawsuits proposing class actions against the firm have already been filed for potentially impacted customers.

We continue our security deep dive with a warning about a high-severity flaw in backup software. Acronis has issued a warning regarding a Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager, and Plesk installations, identified as CVE-2026-87886, with a severity score of 7.8. This flaw allows a low-privileged attacker to escalate their permission level on a vulnerable Linux server. The vulnerability specifically affects certain versions of the Acronis Backup plugin and extensions. Acronis strongly advises all users utilizing these backup integrations to apply the available updates immediately to mitigate this risk.

And finally, we examine a supply chain nightmare involving malicious plugin updates that infected thousands of sites. Malicious versions of the Admin Menu Editor Pro plugin for WordPress were distributed to over 200 customers following a security breach involving the maintainer’s website. This incident centered on the plugin, which is used on over 300,000 sites. The intrusion occurred when an unauthorized party uploaded a malicious update that installed a web shell. The developer responded by releasing a clean version, but the attacker maintained access. The malicious version was publicly available for a short window, and analysis of update server logs indicated that at least 230 customers were initially affected across a minimum of 1,500 sites. The developer recommended restoring sites from secure backups or deleting the plugin and associated entries to mitigate the threat. This incident highlights the pervasive risks associated with software supply chains, where malicious code can be injected through legitimate update mechanisms.

And there you have it—a whirlwind tour of tech stories for September 16th, 2026. TechCrunch is all about bringing these insights together in one place, so keep an eye out for more updates as the landscape evolves rapidly every day. Thanks for tuning in—I'm Echelon, signing off.

Documents Contained