Critical Cisco Secure Email Gateway zero-day gives attackers root access
CSO Online 15.09.2026 19:56
Cisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over the device by simply sending malicious crafted emails to users. The flaw was already being exploited in the wild when the fixes were released.
Tracked as CVE-2026-76461, the vulnerability is described by Cisco as an SQL injection caused by insufficient validation in the product’s email parsing code. Parsing incoming email messages for threats is this appliance’s main job, which means the attack vector is trivial.
Exposed Vite servers are being probed for AWS and Azure credentials
CSO Online 15.09.2026 14:36
Attackers have opened a new front in their war on software developers: Vite servers, which they are probing for sensitive data including cloud credentials, infrastructure configuration and environment files.
Vite was created as a build tool for Vue, a JavaScript framework for building user interfaces and web applications, but has now become a widely used development server and build tool across the JavaScript ecosystem.
Confidential Computing gebrochen: DDRop-Angriff ermöglicht Datenklau in der Cloud
Golem 15.09.2026 10:55
Ein kleines Gerät für nur 159 US-Dollar lässt Angreifer verschlüsselte Daten aus dem RAM fremder Cloud-Instanzen abgreifen. Einen Patch gibt es nicht. (Sicherheitslücke, Prozessor)
Dringend aktualisieren: iOS 27, macOS 27 und Co. stopfen viele Lücken
Heise Security 15.09.2026 08:48
iOS 27, Golden Gate und Co. sind auch aus Sicherheitsgründen relevant. Apple hat nun seine Fix-Liste geliefert. Auch ältere Betriebssysteme bekommen Updates.
Microsoft Releases Emergency Patch to Fix RDS Vulnerability
Infosecurity Magazine 15.09.2026 08:40
Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday
Softwareprojekte in Gefahr: BSI warnt vor laufenden Angriffen auf Gitlab
Golem 15.09.2026 08:39
Angreifer haben es auf Gitlab-Instanzen abgesehen. Durch eine kritische Path-Traversal-Lücke können sie unter anderem Zugangsdaten abgreifen. (Sicherheitslücke, API)
Angreifer missbrauchen SQL-Schwachstelle in Ciscos Secure E-Mail-Gateway
Heise Security 15.09.2026 08:30
Cisco warnt vor laufenden Angriffen auf eine kritische SQL-Injection-Lücke im Secure E-Mail Gateway. Updates stehen bereit, auch das BSI warnt mittlerweile.
Außer der Reihe: Microsoft fixt Probleme und Lücken nach Windows-Updates
Heise Security 15.09.2026 07:06
Microsoft hat ungeplante Updates für Windows außer der Reihe veröffentlicht. Sie stopfen Sicherheitslecks und beheben Probleme.
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
The Hacker News 15.09.2026 06:11
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
The Hacker News 15.09.2026 05:31
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.
Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.
"The