Vulnerabilities
Tue 15 Sep
Acronis security advisory SEC-10986 / update UPD-2609-3d72-20a7 (wired by BleepingComputer 15 September 2026) covers CVE-2026-87886, a high-severity Linux local privilege escalation in Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk. Acronis assigns severity 7.8. A low-privileged attacker can raise privileges on a vulnerable Linux host without user interaction; further exploit detail withheld while patches propagate. Acronis says exploitation has been detected in the wild in limited, targeted attacks against cPanel & WHM plugin deployments (assessment based on a single report from a potentially affected customer; no public IoCs released). Affected: cPanel & WHM plugin builds earlier than 1.9.3.1021 (fixed 1.9.3 HF3); Plesk extension builds earlier than 1.8.11.638 (fixed 1.8.11). Apply those updates immediately. Primary: Acronis SEC-10986; wire: BleepingComputer 15 Sep. UPDATE 16 September 2026: CISA added CVE-2026-87886 to KEV (same alert as Cisco ISE CVE-2026-76460). Distinct from desk card cve-2026-60004 (Gitea / Red Heron).
Acronis SEC-10986 — CVE-2026-87886
vulnerabilities cloud
Developer Janis Elsts (adminmenueditor.com) reports that on 14 September 2026 an attacker gained access to the plugin's distribution site and pushed malicious Admin Menu Editor Pro updates. Version 2.35 (available ~06:00–13:00 UTC) dropped includes/wp-user-consent.php (web shell) and created a hidden wp_-prefixed user; a same-day clean 2.36 push was also compromised while the attacker retained access. Update-server logs: ~230 customers, malicious build installed on at least 1,500 sites (multiple sites per customer); several hundred more downloads in the window may be affected. Free Admin Menu Editor and 2.34 believed clean. IoCs per developer: includes/wp-user-consent.php under admin-menu-editor-pro; new /wp-content/object-cache/; wp_ users hidden from the dashboard; wp_ocache* options. Remediation: restore from a backup before 14 Sep 2026, or remove the plugin, delete /wp-content/object-cache/, and purge the listed DB artefacts; site sales/updates offline pending rebuild. Primary: developer incident notice; wire: BleepingComputer 15 Sep.
Admin Menu Editor — developer incident notice (site offline; 14 Sep 2026)
breaches cloud
Joint advisory published 15 September 2026 by the UK NCSC, US FBI, and Netherlands AIVD details Windows malware the FBI calls HEAVYGRAM and NCSC calls CHOSEN BRICK, attributed to Iran's Ministry of Intelligence and Security (MOIS). Operators build rapport on messaging apps, then deliver trojanised installers (lures include Pictory, KeePass, Telegram, RunwayML, Norton, Adobe Flash, and MRI-scan themed files), often starting on work devices before pivoting to personal ones. Malware is controlled via Telegram and can copy emails/chat messages, take screenshots, and activate the microphone; NCSC dates use from at least 2025 against people in the UK, US, Netherlands and elsewhere (FBI dates the wider campaign to autumn 2023). Victim details have appeared on pro-Iranian leak sites, raising personal-safety risk. FBI IC3 CSAs (260915 / 260915-2) expand a March 2026 alert with further TTPs and IoCs. Primary: NCSC advisory + FBI/IC3; wire: The Hacker News 15 Sep.
NCSC — Iranian cyber targeting / CHOSEN BRICK advisory (15 Sep 2026)
tech identity
Vulnerabilities
Tue 15 Sep
BleepingComputer (15 September 2026) relays Wordfence/Defiant telemetry that attackers are actively exploiting CVE-2026-27540 in the premium WooCommerce Wholesale Lead Capture WordPress plugin. Unauthenticated AJAX action wwlc_file_upload_handler accepts a user-controlled file_settings allowlist, letting attackers permit .php uploads and drop webshells (researcher: Teemu Saarentaus). Affected: versions 2.0.3.1 and older; fixed in 2.0.3.2 (released 20 February). Wordfence reports 100,000+ blocked attacks with spikes around 4–17 June, 1 July, and 30 August 2026; The Hacker News (16 September) cites CVSS 9.8 and lists recent attacker IPs (including 92.241.13.213, 31.59.129.150, 92.241.13.140, 23.137.105.214, 23.180.120.140, 104.194.9.138, 187.75.114.36, 114.10.43.203, 37.114.144.209 and IPv6 2a0f:85c1:840:5389::1). Hunt admin-ajax.php calls to wwlc_file_upload_handler, unexpected PHP under uploads (e.g. shell.php), and unknown admin accounts; upgrade to 2.0.3.2+. Primary wire: BleepingComputer; UPDATE 17 Sep: CVSS + IoCs from THN/Wordfence.
BleepingComputer — WooCommerce Wholesale Lead Capture CVE-2026-27540 (15 Sep 2026)
vulnerabilities cloud
BleepingComputer (15 September 2026) reports Houston-based utility CenterPoint Energy confirmed in an SEC filing that an unauthorized third party obtained personal information for a portion of its customers through an external-facing system. A threat actor alias “4d722e4d656f77” told BleepingComputer they exfiltrated about 7.49 million customer records (names, phones, service/billing addresses, account numbers, billing amounts, partial SSNs) by iterating IDs on a public API alleged to lack rate limiting/WAF. CenterPoint says electric and gas services were not impacted and does not expect a material business effect; it activated IR, engaged third-party experts, hardened systems, and notified law enforcement/regulators. Class-action complaints filed in US federal courts allege the incident window was about 17 August–1 September 2026. Company has not publicly matched the actor’s record count or data-type claims in the SEC text cited by the wire. Primary wire: BleepingComputer; company confirmation: SEC filing as cited there.
BleepingComputer — CenterPoint Energy confirms customer data stolen (15 Sep 2026)
breaches ot ics
Lumen Black Lotus Labs (report titled “The Banana Stand…”, summarised by The Hacker News and BleepingComputer on 15 September 2026) documents BambooToken, a previously under-reported malware family active since at least February 2023, with activity seen through July 2026 against organisations in Asia and South America (mobile apps, legal/financial, software development). Operators abuse DLL sideloading via Tendyron OnKey-related binaries (OnKeyToken_KEB.dll) without evidence the vendor’s code-signing cert/build was compromised; later variants use MQTT brokers (including Cloudflare-routed paths) for C2 plugin load/stop and host control on Windows and, from late 2025, Linux. Initial access vector undetermined. Hunt for unexpected OnKey-related DLL sideloads, MQTT client beacons to unfamiliar brokers, and related IoCs in the Lumen write-up. Primary: Lumen Black Lotus Labs; wires: THN / BleepingComputer.
Lumen Black Lotus Labs — The Banana Stand / BambooToken MQTT C2
tech network
Microsoft AI published a draft “Humanist AI Code of Conduct” for MAI Models (primary: microsoft.ai/code-of-conduct; SecurityWeek 15 September 2026). Absolute Constraints block producing working exploit code, attack tooling, planning/targeting methodologies, intrusion/evasion procedures, or other assistance that would enable or improve a cyberattack — including when requests are reframed — and operators/users cannot override those limits. Defensive and lawful work remains in scope (vulnerability discovery, malware analysis, PoC exploit development/testing, educational attack material). Authority follows a Chain of Command (code of conduct → operator policies → user preferences); tool outputs, files, webpages, and other AI messages are not treated as authoritative instructions. SecurityWeek notes a dedicated review track for cybersecurity and specialised uses, and a six-week public consultation before a revised version; current MAI models are not yet trained on the draft document. Primary: Microsoft AI CoC; wire: SecurityWeek.
Microsoft AI — Humanist AI Code of Conduct (draft)
ai
Vulnerabilities
Tue 15 Sep
WA Cyber Security Unit advisory 20260915001 (15 September 2026, TLP:CLEAR) highlights CVE-2026-69829, a Critical remote code execution flaw in Microsoft Windows Shell with CVSS 9.8. WASOC states successful exploitation could allow an unauthenticated attacker to execute arbitrary code and potentially fully compromise affected systems. Affected products/versions are as listed by Microsoft on the MSRC update-guide entry for CVE-2026-69829 (JS-rendered; versions not mirrored here beyond vendor listing). WASOC reports no exploitation observed on Western Australian Government networks at time of writing and recommends applying Microsoft’s fixes per normal patch timeframes. Primary: Microsoft MSRC CVE-2026-69829; AU wire: WASOC 20260915001.
Microsoft MSRC — CVE-2026-69829 (Windows Shell RCE)
vulnerabilities australia
Vulnerabilities
Tue 15 Sep
WA Cyber Security Unit advisory 20260915003 (15 September 2026, TLP:CLEAR) relays Canonical LXD updates for eight Critical issues (CVE-2026-66897, CVE-2026-66898, CVE-2026-63300, CVE-2026-63299, CVE-2026-63297, CVE-2026-63296, CVE-2026-63294, CVE-2026-62420), each listed at CVSS 9.9. Successful exploitation can let a remote attacker achieve root command execution on the LXD host. Affected lines per WASOC: LXD 6.x prior to 6.10; 5.21.x prior to 5.21.7; 5.0.x prior to 5.0.9; all versions prior to 4.0.13. Canonical GitHub advisory GHSA-q39m-8fx9-42fv (CVE-2026-66897 example) documents instance template path traversal to arbitrary host file write as root, with patched versions including 4.0.13, 5.0.9, 5.21.7, 6.9-ab8fad2, and 6.10; related LXD GHSAs cover further path-traversal / privilege issues in the same wave. WASOC reports no exploitation observed on Western Australian Government networks at time of writing. Patch to vendor-fixed LXD builds; review Canonical LXD security advisories for the full set. Primary: Canonical LXD GHSA index; AU wire: WASOC 20260915003.
Canonical LXD GitHub Security Advisories (patched 4.0.13 / 5.0.9 / 5.21.7 / 6.10)
vulnerabilities australia cloud
BleepingComputer (15 September 2026) reports five alleged leaders of the Black Axe cybercrime syndicate — Perry Osagiede, Franklyn Osagiede, Osariemen Clement, Collins Otughwor, and Musa Mudashiru — were extradited to the United States to face wire fraud and money-laundering charges. Prosecutors allege a Cape Town–based internet fraud campaign (about 2011–2021) using romance and advance-fee scams, aliases, dating sites, and VoIP numbers to target US victims, including coercion via threats to publish sensitive photos. US Attorney’s Office for the District of New Jersey press release linked from the wire: “Five Prominent Black Axe Members Extradited for Conspiring to Engage in Internet Scams and Money Laundering.” Law-enforcement action / charging story; not a fresh organisational data-breach notice. Primary: DOJ USAO-NJ PR; wire: BleepingComputer.
DOJ USAO-NJ — Black Axe members extradited (linked 15 Sep 2026 wire)
breaches
Spain’s Agencia Española de Protección de Datos (AEPD) blog (14 September 2026; Francisco Pérez Bes) reports the agency’s first notification of a personal-data breach in which the incident was allegedly executed by an AI agent using a known large language model. Per the notifier: the agent searched generic files for vulnerabilities, successfully logged in, then autonomously hunted application flaws, modified personal data, and accessed invoices. AEPD stresses the claim is from the organisation’s notification and still requires analysis; use of a given model does not imply the provider’s model or infrastructure was compromised or purpose-built for crime. Framing: shift from AI-assisted attacker tools (phishing copy, vuln search) toward agentic chaining of attack phases at machine speed — with implications for identity/credential controls, detection, and response timing. National Cryptologic Center (CCN) paradigm-shift context noted in wire coverage. Primary: AEPD blog; secondary: BleepingComputer 16 Sep 2026.
AEPD — primera notificación brecha por agente de IA (14 Sep 2026)
ai identity
Brevo status write-up (and BleepingComputer 17 September 2026) confirms that on 14 September 2026 an attacker used a compromised long-lived Cloudflare API key (hardcoded in Brevo application source; first misuse indicated late August) to deploy a Cloudflare Worker that rewrote responses at the CDN edge for about five and a half hours (approx. 16:07–20:30 UTC). Affected: brevo.com, sendinblue.com, login/account/my/onboarding.brevo.com, sibforms.com, plus Brevo forms script, Conversations widget, and SDK loader that customers embed. The Worker stripped CSP and served a fake Cloudflare “verify you are human” ClickFix lure (Win+R / Ctrl+V / Enter) downloading malware on Windows; on WordPress sites with a logged-in admin, Sansec/Bleeping also report attempted silent install of a malicious “Web Media Optimizer” plugin backdoor. Not affected per Brevo: app.brevo.com, API, email delivery, and customer account data held in Brevo. Remediation: Worker/routes/hostnames removed, key revoked, hardcoded credential removed, Vault + Cloudflare audit alerting planned. Distinct from Brevo’s earlier 9–10 September SSO boundary incident (Trezor phishing wave). Primary: Brevo status write-up; wire: BleepingComputer; Sansec first flagged customer-site impact (up to ~100k sites cited).
Brevo status — Cloudflare Worker ClickFix write-up (14 Sep 2026 incident)
breaches cloud