September 15, 2026 by sig9
Hacker Wars - September 15, 2026
Your daily dose of infosec chaos
Email gateways are having the worst week, nation-state crews are chaining bugs like speedrunners, and Microsoft is patching its own patches. Cisco’s mail gateway is being root-popped by an actively exploited zero-day, Sandworm dragged a 2022 botnet out of cryostorage, and one shared hosting account can now own the whole server. Brew something strong.
Cisco Email Gateway Zero-Day Hands Attackers Root
Cisco warns that CVE-2026-76461, a CVSS 9.8 flaw in AsyncOS for Secure Email Gateway, is being exploited in the wild - unauthenticated arbitrary command execution, with root privileges, on the underlying OS. The appliance that’s supposed to filter malware is now the malware delivery mechanism, which is a special kind of irony.
What to do: Patch immediately, restrict management access to trusted networks, and hunt logs for unexpected command execution on the appliance.
Chinese APT Chains Chrome And Windows Bugs To Drop GRIMWEDGE
Volexity attributes a spear-phishing campaign to China-linked cluster UTA0560, chaining recently patched Chrome and Windows flaws to deliver a JavaScript backdoor dubbed GRIMWEDGE. Browser bug for the foothold, OS bug for escalation - the classic two-step, and every patch needed to stop it already shipped.
What to do: Force-update Chrome across the fleet, confirm Windows patch levels, and treat JavaScript from email lures as hostile by default.
Sandworm Revives Cyclops Blink Botnet Via Chained Cisco Flaws
Russia’s Sandworm is chaining Cisco vulnerabilities to spread an upgraded Cyclops Blink, the botnet the FBI disrupted back in 2022. Turns out taking down a botnet is more of a suggestion than a verdict when the operator has spare infrastructure and a long memory.
What to do: Patch Cisco edge devices, audit them for unexpected binaries and persistence, and remember GRU implants are built to survive cleanup.
LiteSpeed Bug Turns One Hosting Account Into Server Root
cPanel warns that a critical LiteSpeed Web Server Enterprise flaw lets a low-privilege website user escalate to root on shared hosting servers. On shared hosting, tenant isolation was the entire product promise - now one compromised $3-a-month account means game over for every site on the box.
What to do: Update LiteSpeed Enterprise now, and audit shared servers for privilege escalation artifacts across all tenants.
Microsoft Ships Emergency Fixes For Its Own September Patches
Microsoft released out-of-band Windows updates to repair Remote Desktop Services failures caused by this month’s Patch Tuesday releases, along with Hyper-V and USB audio issues - and yes, a separate Excel update silently breaks copy and paste. Somewhere in Redmond, a regression dashboard is on fire and the coffee machine is empty.
What to do: Deploy the OOB updates to RDS hosts first, then brief the helpdesk before users conclude the network is down again.
That’s a wrap. Back tomorrow with more digital warfare.
Brought to you by sig9 - sig9.ch | Protecting the unseen, securing the unknown
This bulletin is provided for informational purposes. Contact us for tailored security analysis.