πŸ›‘οΈ InfoSec Blue Team Briefing

Thursday, September 17, 2026

🎧 Audio Briefing

Download MP3

Security news from the BlueTeamSec community for Thursday the 17th of September 2026, with eight stories to get through.

CISA have added a critical authentication bypass in Cisco's Identity Services Engine to the Known Exploited Vulnerabilities catalogue. The flaw lets unauthenticated attackers gain full admin access through a REST API endpoint without credentials, and it's being exploited in the wild against internet-facing instances. Patches must be applied by the nineteenth, and organisations should check whether their management interfaces are exposed to the public internet.

Cisco have also disclosed a critical SQL injection vulnerability in their Secure Email Gateway that allows unauthenticated remote attackers to achieve root-level command execution by sending crafted emails. Active exploitation has been confirmed, and there are no workarounds available β€” physical and virtual appliances are both affected.

And another exploit in the wild: Acronis have written up a campaign by the Chinese-speaking threat actor Red Heron, who weaponised a critical Gitea remote code execution flaw within days of its disclosure back in July. The attackers deployed a new Linux rootkit across seven countries, targeting government, defence, aerospace, energy, and election infrastructure, with confirmed lateral movement to Proxmox clusters.

The National Cyber Security Centre, in coordination with the FBI and Dutch intelligence, have published an advisory on Iranian state-affiliated actors using the CHOSEN BRICK malware family to target dissidents, journalists, and activists in the UK, US, and Netherlands. The malware is delivered via social engineering on WhatsApp and Telegram, enabling espionage through data theft, surveillance, and system sabotage β€” activity that's been ongoing since at least 2025.

Wiz have published research on attackers exploiting Microsoft Entra device registration to join rogue devices that bypass Conditional Access policies and establish persistent access. Nearly one in seven Entra environments showed signs of this abuse over ninety days, and attackers are increasingly using AI-generated device identifiers and user agents to evade detection.

CISA and NIST have released implementation guidance for federal agencies and cloud service providers on protecting authentication tokens and assertions from forgery, theft, and misuse. The report addresses attacks targeting single sign-on, federation, and API-based access in hybrid and multi-cloud environments β€” one for anyone managing identity infrastructure at scale.

Trail of Bits have critiqued 1Password's AI patching benchmark, finding the methodology artificially restrictive with biased instructions. When re-analysed excluding flawed conditions, AI-generated patches successfully blocked exploits eighty-six percent of the time versus 1Password's reported twenty-six percent. The report warns that misleading benchmarks may discourage adoption of AI-driven vulnerability remediation tools.

And a technical analysis of RedHive Stealer malware, covering its attack chain, command and control infrastructure, and indicators of compromise β€” useful if you're doing threat hunting or building detections for stealer families.

That's everything for today from BlueTeamSec. The articles are the work of their original authors β€” the analysis here was automated.

πŸ“° Articles Covered