WEEKLY TOP TEN: September 14, 2026, 16:00 GMT
- Check Point Flaw Enables Root Code Execution
Check Point released updates for a critical stack-based buffer overflow, tracked as CVE-2026-91843, in the login process of Security Management Server that also affects its Log Server. An unprivileged attacker can gain root remote code execution in low-complexity attacks without user interaction. Check Point has not flagged the flaw as exploited but supplied LivePatch fixes and interim mitigations, including hardening and limiting access to trusted IP addresses. Administrators can hunt for attempts by searching audit logs for failed-login alerts citing a username that is too long. The disclosure follows two other critical Check Point flaws patched last week. - Cyberattacks Hit Two Texas-Bound Oil Tankers
The US Coast Guard and FBI boarded two Texas-bound oil tankers last month after cyberattacks disrupted the vessels, according to officials cited in news reports. One ship, the Liberian-flagged VL Prosperity, had left Egypt for Galveston. Iranian media alleged an August 7 intrusion reached the engine room, altering coolant flow, engine speed, and fuel delivery, though those details are unverified. Coast Guard Cyber Command confirmed evidence of a malicious cyber actor but has not attributed the attack to Iran. Investigators found nothing suggesting the tanker was unsafe to operate and are still determining whether the two incidents are connected. - CenterPoint Energy Confirms Customer Data Breach
CenterPoint Energy, a Houston-based utility serving roughly 7 million electricity and natural gas customers across Indiana, Minnesota, Ohio, and Texas, told the SEC that an unauthorized party obtained personal information for some customers through an external-facing system. The disclosure followed a September 12 forum post in which a hacker claimed to have stolen nearly 7.5 million records and posted a 2.5 GB archive, while threatening to attack the company’s main infrastructure next. CenterPoint says electric and gas service was not affected and it does not expect a material impact. The authenticity of the leaked data has not been confirmed. - Cisco Secure Email Gateway Zero-Day Under Attack
Cisco warned customers that a zero-day flaw in Secure Email Gateway appliances, tracked as CVE-2026-76461 with a CVSS score of 9.8, is being exploited in the wild. The AsyncOS email parsing weakness lets an unauthenticated attacker run commands with root privileges by sending a specially crafted email. It affects physical and virtual appliances in any configuration, while Secure Email and Web Manager and Secure Web Appliance are not impacted. Cisco published indicators of compromise but cautioned that attackers with root access can erase them. CISA added the flaw to its Known Exploited Vulnerabilities catalog and set a September 17 deadline for federal agencies. - Orkes Conductor RCE Flaw Exploited In The Wild
Attackers are exploiting CVE-2026-58138, a critical remote code execution flaw in Orkes Conductor, a framework that orchestrates microservices, workflows, and AI agents. Rated 9.8, the bug lets an unauthenticated user submit a workflow containing malicious JavaScript or Python expressions that run operating system commands, often as root, because the evaluator’s sandbox is disabled. Version 3.30.2 fixed it in June, proof-of-concept code surfaced in early August, and attacks began by August 21. Fortinet blocked roughly 1,300 attempts in two days and issued an outbreak alert. Organizations should upgrade and keep workflow APIs off the internet. - GhostCode Phishing Kit Bypasses Microsoft MFA
eSentire identified GhostCode, a phishing kit that abuses Microsoft’s OAuth device authorization flow to hijack Microsoft 365 accounts despite multifactor authentication. In a campaign that began in late August, attackers posed as a BJ’s Wholesale Club procurement officer through a Salesforce web form, then sent an NDA link that led victims to enter a device code on Microsoft’s genuine sign-in page. Within 78 seconds of authentication, the attackers registered three devices in Entra ID and completed an Intune enrollment, and they obtained a Primary Refresh Token after 32 seconds. eSentire spotted the activity in anomalous non-interactive sign-in logs and revoked the token grant. - Japan Digital Agency Breach Hits 240,000 People
Japan’s Digital Agency disclosed a breach of its Government Solution Service that exposed about 246,000 records tied to roughly 240,000 people. Attackers used a maintenance employee’s account and a VPN product vulnerability that had already been publicly disclosed. The stolen data includes names, email addresses, phone numbers, and workplace addresses of users, public officials, administrative staff, and outside businesses and individuals working with the service. Individual identification numbers and financial account information were not affected. The agency discovered the intrusion in late June, blocked external access to the server, suspended the account, and pledged stronger vulnerability management. It did not name the VPN product. - PolinRider Backdoors Packagist Package Via GitHub
Socket researchers found malicious code in four development versions of visanduma/nova-two-factor, a Packagist package with more than 700,000 downloads, as the North Korea-linked PolinRider campaign spreads through compromised developer accounts. The Visanduma GitHub organization appears to have been compromised since mid-June through a single developer account. Operators rewrite Git history, hide JavaScript in configuration files or fake font files, and trigger execution when a repository is opened in VS Code. No stable malicious release has been found. Socket advises isolating any machine that ran the code, reimaging it, rotating credentials, and restricting force-pushes. - CrowdSec Confirms Theft Of 170 Private Repositories
CrowdSec says an attacker copied about 170 of its private GitHub repositories on May 22 using an OAuth token tied to a former employee whose laptop was compromised in the May TanStack npm supply chain attack. The company had left his access open so he could finish work. The source code surfaced on an online forum on September 16, along with email addresses of 83 users and the names, emails, and investment context of 51 potential investors from 2020. CrowdSec says it found no altered code or unauthorized access to its AWS systems, and its earlier statement had said investor names were not exposed. - North Korea’s WaterPlum Infects 30,000 Devices
A joint advisory from the FBI, the Pentagon’s Cyber Crime Center, Japan’s National Police Agency and National Cybersecurity Office, Australia’s Cyber Security Centre, and Germany’s BND and BfV attributes the Contagious Interview campaign to a North Korean group called WaterPlum. Posing as recruiters from AI and cryptocurrency firms, the actors infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026 and took credentials from about 7,000 crypto wallets. Roughly $10.7 million was transferred to North Korea. The advisory also links the group to North Korea’s overseas IT worker scheme.
Our Threat Operations and Intelligence team compiles a daily digest of the most recent online cybersecurity risks. The previous 10 stories were determined to be most significant during the course of the week, ranked by highest risk, and using multiple sources when available.