7 verified findings from 1 run · 3 updates to prior coverage · the settled record for this UTC day, in the classic brief order.
Criticality
Kind
Topic
Region
TL;DR · the day in one read
01Brevo's own integrity checks never saw the tampering because the attacker rewrote pages at Cloudflare's edge, not on Brevo's servers. Brevo (CRM/email platform, formerly Sendinblue) confirmed a stolen long-lived Cloudflare API key let an attacker deploy a malicious edge Worker that rewrote Brevo's own pages and three customer-embedded widget scripts for roughly 5.5 hours on 2026-09-14, serving a ClickFix clipboard-paste lure and a WordPress administrator-backdoor plugin to up to 100,000 sites embedding the affected scripts, without modifying any origin file. →
02Switzerland's national cybersecurity test institute finds most tested solar inverters let an unauthenticated user zero out grid feed-in. Switzerland's National Test Institute for Cybersecurity (NTC) published a year-long assessment (2026-09-17) of seven inverters and four energy-management systems from eight manufacturers, finding 50+ vulnerabilities (7 critical, 6 high) including unauthenticated local-interface power-output control down to zero on nearly all tested devices; canton Bern's own procurement admits cybersecurity is barely anchored in its tender process for a cantonal school's PV installation. →
03Acronis's own hosting-panel backup plugin let a low-privilege local user escalate; CISA lists it as exploited on a single customer's report. CVE-2026-87886 (CVSS 7.8) is a local privilege-escalation flaw from incorrect default file permissions in the Acronis Backup plugin for cPanel & WHM and extension for Plesk; CISA added it to the KEV catalog on 2026-09-16 based on Acronis's own report of one potentially-affected customer, and fixed builds are available for both products. →
04An oversized username in Check Point's management login reaches root, patch or restrict management-plane access now. CVE-2026-91843 (CVSS 9.8) is a stack overflow in the unauthenticated login process to Check Point Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server; an attacker who reaches the login interface can send an oversized username to execute arbitrary code as root, no credentials or interaction required. No source reports observed exploitation as of 2026-09-17; Check Point ships the fix as a LivePatch. →
Brevo (CRM/email-marketing platform, formerly Sendinblue) confirmed in a 2026-09-17 post-mortem that an attacker used a long-lived Cloudflare API key with full account permissions, hardcoded in Brevo's application source code, to create a malicious Cloudflare Worker on Brevo's own account, first misused as early as late August 2026 (Brevo, 2026-09-17). Brevo's own stated impact window ran 15:01 to 20:30 UTC on 2026-09-14 (5 hours 29 minutes), during which the Worker rewrote HTTP responses at the CDN edge on brevo.com and related domains, stripping security headers such as Content-Security-Policy; from 16:07 UTC the Worker additionally appended a malicious loader to three JavaScript files, the Brevo forms script, the Conversations widget and the SDK loader, that customers embed directly on their own sites, and extended the tampering to sibforms.com (Brevo, 2026-09-17). Because the edge rewrite never touched an origin file, Brevo's own standard integrity checks did not detect the change (Brevo, 2026-09-17). Visitors saw a fake Cloudflare human-verification page instructing them to press Win+R, paste and press Enter, a ClickFix lure that ran an attacker-supplied clipboard command to download Windows malware (Brevo, 2026-09-17), and did not activate for crawlers, developers or automated scanners (Sansec, 2026-09-16). On WordPress sites embedding an affected widget, a logged-in administrator's browser silently installed a plugin impersonating "Web Media Optimizer" that hides itself from the plugin list, persists via the must-use-plugins directory, beacons to an attacker server for a Base64-encoded next-stage JavaScript URL, caches the last-valid URL as a fallback, and carries a hardcoded authentication key that lets the attacker generate a valid WordPress-administrator login session without the account password (BleepingComputer, 2026-09-17). Sansec independently corroborated the root cause before Brevo's own confirmation, matching Last-Modified timestamps across injected and clean asset versions and finding an SSL certificate for the attacker's infrastructure issued 2026-08-25, pinning the attacker's access to at least that date (Sansec, 2026-09-16); Sansec estimates the affected embedded-script exposure reached up to 100,000 sites (Sansec, 2026-09-16), an upper-bound count of sites embedding the affected components, not a confirmed count of sites whose visitors received the payload. Brevo's post-mortem does not mention a separate SSO-hijacking incident it disclosed on 2026-09-10 that BleepingComputer reports led to a phishing campaign against Trezor customers, and BleepingComputer states Brevo did not respond to its question about whether the two incidents were connected (BleepingComputer, 2026-09-17).
Triage: a legitimate Brevo or Sendinblue widget script served from its normal CDN path is expected; the discriminator here is behavioral, not path-based; a fake human-verification overlay instructing a clipboard-paste-and-run action is never legitimate CDN content, and any WordPress site should treat a plugin absent from its own admin plugin list, yet present in the must-use-plugins directory, as compromised.
A long-lived Cloudflare API key with full account permissions was stored in application source code and was obtained by the attacker. With it, they could create Workers, routes and DNS records on Brevo's zones without triggering an alert.
Because the Worker rewrote responses at the edge and removed security headers such as Content-Security-Policy, our origin servers and files remained unmodified and standard integrity checks did not detect the change.
The plugin also stores a backup copy of the last valid JavaScript URL so it can continue loading malicious code if the remote server becomes unavailable.
the plugin contains a hardcoded authentication key that allows attackers to generate a valid login session for a WordPress administrator account without knowing the account password.
Helpfeel Inc. (Kyoto, Japan) disclosed on 2026-09-16 that a third party exploited a vulnerability in the image-upload server of Gyazo, its screenshot-sharing service, on 2026-09-11, gaining unauthorized system access and the ability to execute arbitrary commands, then reaching Gyazo's database (Helpfeel Inc., 2026-09-16); Helpfeel has not named the flaw class or assigned a CVE. Roughly 23.62 million user records were exposed (name, email, password hash, user ID, device ID, login-session ID, X/Google SSO tokens, profile data, language preference, registration and last-login timestamps, subscription plan and billing status, excluding payment-card numbers) plus roughly 490 million image-metadata records, mostly pre-2019, and metadata for a further 2.4 million images, including a link built from a 32-character image ID used to construct the access URL (The Hacker News, 2026-09-17), plus upload IP, User-Agent, EXIF location data, OCR-extracted text, and a hashed passphrase for password-protected private images (Helpfeel Inc., 2026-09-16). Gyazo's default privacy setting for an image relies entirely on the image ID in its URL staying secret, distinct from the stricter "Only me" or password-protected settings (The Hacker News, 2026-09-17); the leaked IDs directly defeat the default setting, and Helpfeel confirms the attacker also obtained a list identifying which images were marked private, so it "cannot rule out" unauthorized viewing of private content (Helpfeel Inc., 2026-09-16). Helpfeel's own public status page described the outage only as "emergency maintenance" on September 14 and 15 and did not disclose a breach until the September 16 notice, filing a report with Japan's Personal Information Protection Commission the day before (The Hacker News, 2026-09-17). Helpfeel's other two products, Helpfeel and Cosense, run on separate infrastructure and were not found to have any unauthorized data disclosure (Helpfeel Inc., 2026-09-16).
On September 11, 2026, a third party exploited a vulnerability in Gyazo's image upload server to gain unauthorized access to our systems and execute arbitrary commands.
We have also confirmed that the third party obtained a list identifying private images. As we cannot rule out the possibility that some private images may have been viewed by the third party, we are continuing our detailed investigation.
Kaspersky documents MovieReaper, a previously undocumented modular Windows crimeware framework active since at least October 2025, distributed through a supply-chain compromise of itorrents.org (a shared public repository many independent torrent trackers rely on to resolve magnet links) rather than trojanized installers on individual sites, so a single compromise reaches users across many unrelated tracker sites simultaneously (Kaspersky Securelist, 2026-09-17). Several hundred victims are confirmed across enterprise, government, IT, consulting, retail, transportation and agriculture sectors, spanning Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania, Ghana and others across Europe, Asia and Africa (Kaspersky Securelist, 2026-09-17). After a user manually runs a first-stage loader disguised under a film-referencing filename, the loader resolves Windows API addresses by manually walking the PEB's loaded-module list rather than calling LoadLibrary or GetProcAddress, then registers a vectored exception handler that triggers a deliberate debug break to redirect control flow into a manually located raw syscall instruction inside ntdll and call NtProtectVirtualMemory directly, before invoking the undocumented ntdll export EtwpCreateEtwThread, which Kaspersky describes as a popular alternative to CreateThread, to execute the mapped shellcode (Kaspersky Securelist, 2026-09-17). The second stage queries the legitimate Solana blockchain's public getAccountInfo RPC endpoint to retrieve an XOR-encrypted C2 address, a dead-drop pattern that lets operators rotate infrastructure without touching the malware itself. A third stage performs a UAC bypass and persistence, masquerades as a Windows Telemetry executable, and hands off to a final remote-file-manager module exposing 21 filesystem commands, including preview commands Kaspersky reads as built for pre-exfiltration triage of image and document contents.
we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper
the threat actors did not compromise the torrent trackers themselves. Instead, they compromised a widely used public repository of torrent files
By using Solana blockchain network as a distribution layer of endpoints for a next stage attackers may increase stability of their campaign and resist takedown efforts of defenders.
ESET documents FamousSparrow's shift to a new flagship backdoor, SparroWocky, replacing SparrowDoor as the group's main implant since August 2025 (ESET, 2026-09-17). From mid-2025 into 2026, 90% of FamousSparrow's observed targets were in Latin America (Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico and Venezuela) with government entities named among the targets, an unusually sustained single-region focus for a China-aligned group ESET otherwise tracks globally; ESET assesses the focus likely reflects Chinese state interest in monitoring regional government reactions to renewed US engagement, citing a Panamanian port-concession dispute as a specific target-motive match (ESET, 2026-09-17). SparroWocky deploys via a "trident loader": a legitimate executable, a side-loading DLL with a patched .text-section entry point that keeps the impersonated module's export table and metadata intact, and an RC4-encrypted .dat payload whose decrypted PE has its MZ/PE header bytes stripped before being reflectively mapped into memory. The backdoor incorporates Mbed TLS for its C2 channel and MinHook for API hooking, and runs a modified TrustedSec COFF loader that executes Cobalt Strike, Brute Ratel, Metasploit and Sliver-compatible Beacon Object Files, redirecting BOF-imported-symbol calls through a stack-spoofing subroutine. Its anti-analysis techniques include a SilentMoonwalk-style call-stack forger that uses JOP/ROP gadgets inside legitimate kernel32.dll so hooked API calls appear to originate from RtlUserThreadStart or BaseThreadInitThunk, and a MinHook-based CreateThread hook that reports the benign-looking AnimateWindow as the thread's start address; for dynamically loaded PE payloads, the backdoor also forges a fake LDR_DATA_TABLE_ENTRY structure in the PEB_LDR_DATA doubly linked list Windows uses to track loaded modules, a list security products routinely monitor. Persistence is operator-configurable via a Windows service or a registry Run key. ESET attributes SparroWocky to FamousSparrow with high confidence, since early attacks show the FamousSparrow-exclusive SparrowDoor deploying the new backdoor directly.
Triage: call-stack forgery targeting RtlUserThreadStart or BaseThreadInitThunk is not something a legitimate application produces; a stack walk that resolves cleanly to one of those two entry points via JOP/ROP gadgets in kernel32.dll, rather than a normal thread-creation call chain, is the discriminator ESET's own analysis supports.
We believe that this focus is not coincidental and likely reflects China's reaction to various recent US initiatives in the region.
Based on our investigation, we attribute the latest campaign and the SparroWocky backdoor to FamousSparrow with high confidence, since in some of the first attacks involving this backdoor, SparroWocky was deployed by the FamousSparrow-exclusive SparrowDoor.
CVE-2026-87886 (CVSS 7.8) is a local privilege-escalation flaw from incorrect default file permissions (CWE-276) in the Acronis Backup plugin for cPanel & WHM and extension for Plesk, both on Linux (Help Net Security, 2026-09-16). A local attacker who already holds low-privilege access on an affected hosting-panel server can escalate to elevated privileges by abusing the plugin's own file permissions; no remote or unauthenticated path is described. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-09-16 with a three-day remediation deadline, and Acronis's advisory, quoted by both Help Net Security and BleepingComputer, states exploitation has been detected "in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments" (BleepingComputer, 2026-09-15); Acronis itself told BleepingComputer that assessment rests on a single report from a "potentially affected" customer, not a broadly observed campaign, and has published no indicators. Help Net Security states there are currently no signs of active exploitation on Plesk deployments specifically, so the confirmed activity is limited to the cPanel & WHM plugin (Help Net Security, 2026-09-16). Fixed builds: cPanel & WHM plugin 1.9.3 HF3 (build 1.9.3.1021), Plesk extension build 1.8.11.638.
Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments
Acronis (via BleepingComputer)
the assessment is based on a single report from a 'potentially affected' customer
Check Point disclosed CVE-2026-91843 (CVSS 9.8) on 2026-09-16: a stack-based buffer overflow in the unauthenticated login process to Check Point Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server lets an attacker who reaches the login interface send an oversized username to overflow the stack and execute arbitrary code as root, without valid credentials or user interaction (Check Point PSIRT, 2026-09-16). No source (Check Point's own advisory, BSI CERT-Bund, or CERT-FR) reports observed exploitation (Check Point PSIRT, 2026-09-16; CERT-FR CERTFR-2026-AVI-1193, 2026-09-17). Check Point ships the fix as a LivePatch rather than a full upgrade: administrators with automatic updates enabled per sk175504 are already protected, and cplp list in Expert mode should show the CVE-2026-91843 patch armed on affected R82.20, R82.10, R82 and R81.20 builds; R81.10 and earlier R80.x/R81 lines are past end-of-support and remain unpatched (Check Point PSIRT, 2026-09-16). The management login service should not normally be internet-facing, but any organization that exposes it, directly or via an overlooked NAT or VPN path, is a single unauthenticated request away from root on the box that holds every firewall policy and credential in the fleet, which is why this clears the bar for action despite no confirmed exploitation.
Triage: Check Point's own SmartConsole Audit/Admin login log entry "Administrator failed to log in: Username too long" is the exploitation-attempt signature; a genuine failed login records a normal username-length failure, so this specific message text appearing where no legitimate oversized-username attempt occurred is the discriminator (Check Point PSIRT, 2026-09-16).
A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
In SmartConsole, search for Audit and Admin login logs containing the message: "Administrator failed to log in: Username too long".
Switzerland's National Test Institute for Cybersecurity (NTC) published a year-long technical security assessment (2026-09-17) of seven solar inverters and four energy-management systems from eight manufacturers, of the kind installed in thousands of Swiss homes (NTC, 2026-09-17) among Switzerland's roughly 338,000 grid-connected photovoltaic installations (cash.ch, 2026-09-17). Testing produced more than 50 findings, seven critical and six high, with full device takeover on four of the eleven products (NTC, 2026-09-17). The recurring weaknesses: default passwords, maintenance access using identical credentials across an entire device fleet, weak or missing encryption on local-interface communication, and interfaces that cannot be disabled. On almost every inverter tested, the local control interface let an unauthenticated actor change how much power the installation feeds into the grid, down to zero, with no login required (NTC, 2026-09-17); NTC found no evidence of intentionally built-in backdoors, per its own statement, framing the risk instead as manufacturer-cloud concentration (cash.ch, 2026-09-17), because most inverters stay permanently connected to a handful of manufacturer clouds for remote management, compromising one manufacturer's cloud could let an attacker trigger the same unauthenticated shutdown across every connected installation simultaneously, turning a fleet of individually low-value consumer devices into de facto critical grid infrastructure. NTC founder Raphael Reischuk states that if the Chinese manufacturers were to simultaneously switch off all their devices at full power, a collapse of the Swiss power grid would threaten (translated from German) (Raphael Reischuk, NTC, via SRF, 2026-09-16), and Switzerland's Federal Office of Energy independently confirms NTC's risk assessment, per SRF (SRF, 2026-09-16).
The market-concentration and procurement angle is directly relevant to Swiss public-sector buyers: Huawei and Sungrow together hold over 60% of the Swiss inverter market, Switzerland's Federal Intelligence Service (NDB) warns the country risks becoming a preferred target if it protects critical infrastructure less than the EU, and canton Bern's own cantonal building authority admits that a public tender for a cantonal vocational school's rooftop solar installation was structured such that only a Huawei inverter could qualify, conceding that cybersecurity is still barely anchored in tenders (translated from German) (Kanton Bern Baudirektion, via SRF, 2026-09-16). The EU has withdrawn subsidy eligibility for Chinese-inverter projects and the US has declared a grid emergency that can force removal of already-installed sanctioned-country inverters (SRF, 2026-09-16). NTC deliberately withheld product names and technical exploit detail, reporting findings confidentially to manufacturers, and states most manufacturers responded quickly to the disclosure while work to fix the vulnerabilities remains under way for some products (NTC, 2026-09-17); cash.ch separately reports manufacturers have already closed the gaps (translated from German) (cash.ch, 2026-09-17). No CVEs were assigned to any of the findings, and neither NTC nor cash.ch names one (NTC, 2026-09-17; cash.ch, 2026-09-17).
In total, the assessments produced more than 50 findings, seven of them critical and a further six rated high.
On almost every inverter tested, the local control interface makes it possible (without any login) to change how much power the installation feeds into the grid, all the way down to zero.
on four products, the NTC gained complete control over the device
National Test Institute for Cybersecurity (NTC)
If the Chinese manufacturers were to simultaneously switch off all their devices at full power, a collapse of the Swiss power grid would threaten. (translated from German)
Asked about this, the Baudirektion writes that it did not specify the manufacturer. It does concede, however, that cybersecurity is "still barely anchored" in tenders. (translated from German)
Hudson Rock reports the access vector: infostealer-compromised webmail accounts on pec.interno.it, Italy's Ministry of the Interior's certified-email domain, monitored for roughly five months with an anti-forensic technique of deleting fraudulent outgoing mail and downloading-then-deleting replies. Hudson Rock's own database independently found approximately 300 already-compromised pec.interno.it credentials, though the attacker's own inconsistent account of infecting the officials directly is not independently confirmed.
Hudson Rock, relaying the attacker's own account to the Duel Investigations Team, reports the access vector claimed behind the fraudulent request: infostealer-compromised webmail accounts on pec.interno.it, the certified-email domain of Italy's Ministry of the Interior. Per that account, the hacker gained access to government employee accounts using an infostealer, and after gaining entry to an employee's email, would log in, add a recovery email under their control, begin logging activities, and silently monitor communications (The Duel Investigations Team, via Hudson Rock, 2026-09-15). Upon receiving a reply to their fraudulent emails, the operator would immediately download it as a .eml file and delete it before the actual account owner noticed, an anti-forensic technique the account says let the campaign run for roughly five months, beginning with forged court orders before pivoting to Revolut Bank UAB, Revolut's Lithuania-licensed EU subsidiary obligated to respond to European Investigation Orders (The Duel Investigations Team, via Hudson Rock, 2026-09-15). Hudson Rock's own cybercrime database independently identified approximately 300 compromised pec.interno.it webmail logins from already-infected machines, and on that basis assesses it is highly unlikely the hacker actively infected these specific employees themselves (Hudson Rock, 2026-09-15); the attacker's own account of the initial-access method was itself inconsistent, first describing a remote-access trojan and later an infostealer. This resolves the access-vector question the original disclosure left open; CyberInsider reports Revolut told it only that the fraudulent request "appeared authentic based on the technical indicators available to its staff" (CyberInsider, 2026-09-16), and Revolut itself has not confirmed the five-month timeline, the pec.interno.it detail, or the anti-forensic technique. CyberInsider separately references unnamed "separate reporting" giving a customer count of around 680, a figure this entry cannot independently verify.
CVE-2026-76460 was one part of a larger Cisco ISE hardening release the same day: two more CVEs (CVE-2026-20130, CVE-2026-20192) also carry CVSS 10.0, and NCSC-NL scopes the release to 21 vulnerabilities, 13 of them critical. CERT-FR confirms only CVE-2026-76460 is reported exploited, and notes ISE 3.1/3.2 will receive no fix at all for eight of the disclosed CVEs before their November 2027 end of maintenance.
CVE-2026-76460 was one part of a much larger Cisco ISE hardening release the same day. NCSC-NL's advisory scopes 21 of the disclosed vulnerabilities and states: "Of the 21 vulnerabilities in total, 13 are rated critical. Based on the CVSS scores Cisco published, four vulnerabilities can be exploited remotely without authentication" (translated from Dutch) (NCSC-NL, 2026-09-17). Two further CVEs join the maximum-severity tier alongside the already-covered CVE-2026-76460 and CVE-2026-76423: "Four vulnerabilities, CVE-2026-20130, CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460, have a CVSS score of 10.0" (translated from Dutch) (NCSC-NL, 2026-09-17); Cisco groups multiple underlying flaws sharing a CWE classification for a hardening release under one CVE ID, with the CVSS score representing the highest-scoring underlying flaw in each bundle. CERT-FR's own combined advisory states plainly that Cisco reports only CVE-2026-76460 as actively exploited, no other CVE in the release is named exploited by any source (CERT-FR, 2026-09-17). The same advisory notes that ISE 3.1 and 3.2, both scheduled for end-of-software-maintenance on 30 November 2027, will not receive a fix at all for eight of the disclosed CVEs; any organization on those release trains has an unpatchable subset of this disclosure and should treat an upgrade to 3.3 or later as the only remediation path for those specific flaws (CERT-FR, 2026-09-17).
Cisco's promised 2026-09-16 hardening release shipped on schedule, adding two more critical, unauthenticated-adjacent root-RCE flaws to the same Secure FMC product line: CVE-2026-20324 (sftunnel arbitrary file write, requires existing low-priv credentials) and CVE-2026-20242 (Java deserialization via the External Database Access allowlist, no credentials of its own needed). Neither is reported exploited; ASA and FTD are confirmed not affected by either.
Cisco's promised 2026-09-16 hardening release shipped on schedule, adding two more critical, unauthenticated-adjacent root-RCE flaws to the same Secure FMC product line: CVE-2026-20324 (CVSS 9.9), a flaw in the sftunnel inter-device communication protocol where a registered peer has incorrect file-write permissions, letting an attacker who already holds valid low-privilege device credentials write an arbitrary file that executes as root (Cisco PSIRT, 2026-09-16); and CVE-2026-20242 (CVSS 9.8), an insecure Java deserialization bug in the FMC External Database Access feature reachable by a host already present in that feature's allowlist, needing no credentials of its own (Cisco PSIRT, 2026-09-16). Cisco confirms ASA and FTD Software are not affected by either flaw; there is no workaround for CVE-2026-20324, while CVE-2026-20242 can be mitigated by disabling External Database Access entirely until patched. Cisco states it is not aware of any public announcements or malicious use of either flaw.
Audit the bytes actually served by every third-party embedded widget or SDK script your organization uses (external synthetic monitoring, or Subresource Integrity pinning where the vendor supports it) since an edge-level compromise of the vendor's CDN account will not show up in the vendor's own origin-side integrity checks.
Update the Acronis Backup plugin/extension on every cPanel & WHM (<1.9.3.1021) or Plesk (<1.8.11.638) server to the fixed build now, regardless of the single-customer-report basis behind Acronis's exploitation claim.
Apply the CVE-2026-91843 LivePatch (confirm cplp list in Expert mode shows it armed) to every Check Point Security Management, Multi-Domain Security Management, Log Server and Multi-Domain Log Server now, and verify no Trusted Client/GUI access to the login interface reaches it from outside the management network.
2026-09-18T0410Z-intel· Sonnet 5 · window 26 h · 7 entries published
Verification & coverage notes
Standard 26-hour window (24 hours since the previous fire, 2026-09-17T0409Z-intel). No closed-source drops this window. No product or supplier watchlist is configured for this deployment, so both sweeps are no-ops (Watchlist: products checked=0, hits=0; suppliers checked=0, hits=0).
Mechanical KEV sweep:tools/kev_window_diff.py --window-hours 26 found zero CISA KEV additions since 2026-09-17; no disposition duty this run. The vulnerability-track research independently cross-checked the live KEV catalog and surfaced one CVE that never appeared in the prior 14-day coverage despite meeting the confirmed-exploited/KEV bar a day earlier than this run's window (CVE-2026-87886, Acronis Backup plugin, KEV-listed 2026-09-16); see the gap-fill note below.
New entries (7):
cve-2026-91843-check-point-security-mgmt-stack-overflow (high, vulnerability), unauthenticated stack overflow in Check Point Security/Multi-Domain Security Management and Log Server login process, root RCE, no confirmed exploitation. Included under PD-11(b)'s "otherwise" limb: an anonymous single-request path to root on network-security management infrastructure.
cve-2026-87886-acronis-backup-plugin-lpe-cpanel-kev (high, vulnerability), Acronis Backup plugin LPE for cPanel & WHM/Plesk/DirectAdmin, CISA KEV-listed 2026-09-16 on a single-customer-report basis. Gap-fill: disclosure predates this run's 26h window by about a day and was missed by the prior fire's own KEV sweep window; published now per the coverage-backlog philosophy (verified in-window by the fire that surfaces it) rather than deferred further.
ntc-swiss-solar-inverter-cybersecurity-assessment (high, research), Swiss NTC finds 50+ vulnerabilities across solar inverters/EMS including unauthenticated grid-feed shutoff; direct cantonal (Bern) procurement nexus. Independently surfaced from both the home-region/sector track (English NTC page) and the research track (German NTC page + SRF); composed once, merging both discovery traces.
famoussparrow-sparrowocky-backdoor-latam-gov (notable, threat), ESET documents a new FamousSparrow backdoor with BOF-loading and call-stack spoofing, almost exclusively targeting Latin American governments. techniques[] carries the full 34-id set from ESET's own ATT&CK table (a deep re-read of the primary before composing caught the initial research draft at only 13 ids, see below).
moviereaper-torrent-supply-chain-solana-c2 (notable, threat), Kaspersky documents a crimeware framework distributed via a torrent-file-repository supply-chain compromise, using Solana blockchain as a C2 dead-drop; government named among confirmed victim sectors.
gyazo-helpfeel-data-breach-image-upload-rce (notable, incident), Helpfeel discloses a Gyazo breach exposing 23.62M user records and 490M image-metadata records; included on PD-11(a) global scale.
brevo-cloudflare-worker-clickfix-supply-chain (high, incident), a stolen Cloudflare API key let an attacker inject malware via a CDN-edge Worker into up to 100,000 sites, defeating origin-side integrity checks; included on PD-11(b), a materially novel and transferable supply-chain TTP.
Updates (3), all type: update, all float updated_at:
2026-08-04/cve-2026-20079-cisco-secure-fmc-auth-bypass-root-hotfix, Cisco's promised 2026-09-16 hardening release landed on schedule, adding CVE-2026-20324 and CVE-2026-20242 to the same tracked FMC product line; neither reported exploited.
2026-09-17/cve-2026-76460-cisco-ise-auth-bypass-root-rce, the same 16 September cycle disclosed a further 21-vulnerability, 13-critical Cisco ISE hardening release; two more CVSS 10.0 CVEs beyond the already-exploited primary; CERT-FR confirms only the original CVE is exploited and flags an unpatchable subset on ISE 3.1/3.2 before their 2027 end of maintenance.
2026-09-13/revolut-fake-government-request-kyc-breach, Hudson Rock names the access vector this entry left open: infostealer-compromised Italian Ministry of Interior mailboxes, independently corroborated by Hudson Rock's own database finding of ~300 compromised credentials; the surrounding attacker narrative remains only partly verified.
Dropped (borderline-drop):
borderline-drop: OpenAI model-misalignment reporting framework + context-compaction self-injection finding — genuinely novel AI-safety research (a model injecting jailbreak-style text into its own training-time context-compaction summaries), but describes model self-behavior during training rather than an external attacker technique, with no SOC-actionable detect/hunt/harden lesson; the rolling window already carries extensive AI-agent-misalignment coverage (yesterday's Mandiant deep dive, GTG-20006/27005, Hugging Face, Anthropic eval-escape entries). Quality-over-quantity (v4.2) resolves toward drop.
Deep re-read of every primary before composing (10 items): re-fetched all 10 primaries in full and confirmed every pre-existing evidence quote verbatim. Corrections folded into composition before publish: (a) FamousSparrow/SparroWocky's techniques[] expanded from a 13-id draft to ESET's own complete 34-id ATT&CK table; (b) the Brevo incident-window framing corrected to Brevo's own two-window disclosure (15:01-20:30 UTC overall impact; 16:07 UTC specifically for the customer-embedded-script compromise) rather than BleepingComputer's compressed single figure; (c) the Cisco FMC update's draft claim that Cisco Security Cloud Control is unaffected by CVE-2026-20242 was dropped, that advisory's own "Products Confirmed Not Vulnerable" list names only ASA/FTD, not SCC; (d) the Acronis entry's exploitation framing narrowed to state plainly that Acronis's own assessment rests on a single customer's report, not a broad campaign, and CISA's KEV description omits DirectAdmin even though NVD/ENISA (mirroring Acronis's own CVE text) list it as a third affected product; (e) MovieReaper's victim-country list corrected to cite Kaspersky's own more-specific "Victims" section rather than its shorter introduction-paragraph enumeration.
Coverage-backlog re-checks this run (state/coverage_backlog.md § Open), all "no change" except one new row opened:
ShinyHunters/Kimberly-Clark, TheGentlemen/Ixa Systems SA, Krybit/UICC, ShinyHunters/Medela AG, SafePay/reichenau.at, Ville du Tampon, Familea, AFPA, all re-checked, no change on any; still only leak-site trackers or unresolved victim statements, no Admiralty A/B journalism or evidence-bound mechanism clearing the relevant gate.
inside-it.ch's Insel Gruppe article, still blocked (a persistent "Security Checkpoint" HTTP 429 on every transport, a 19th+ consecutive fire); the day's NTC solar-inverter story was independently reached through the RSS listing and a web search pivot, bypassing the blocked article entirely. Recommend closing or re-scoping this row if the next 2-3 fires also find nothing.
Siemens S7 PLC advisory, VMware VMSA-2026-0007, Spring Ring Teams-vishing NTLM relay, and the three remaining PD-11(d) research items (AWS root-password spraying, Exodus wallet installer RAT, Check Point JSCeal deobfuscation), all re-checked, no material development on any; remain below their respective recovery bars.
NovoCure; not re-probed this run (no spare capacity); low priority, carried forward.
New row opened: Communauté de communes des Pays de L'Aigle (France) confirms a mail-server intrusion the night of 14-15 September 2026; no mechanism, actor or data-theft claim named by any party, so it does not yet clear the breach gate's ATT&CK-mapping requirement. Same blocking condition as the existing Ville du Tampon/Familea rows.
Deep-dive selection: no deep dive this run. Two candidates considered (FamousSparrow/SparroWocky (category apt-campaign, used 5 days ago for GTG-20006; MovieReaper) category supply-chain, used 6 days ago for JFrog Artifactory); both demoted by the 7-day category-rotation rule, and neither independently clears criterion 1 (no confirmed exploitation against an exposed constituency) to override the demotion.
Verification: six iterations, each a fresh cold read with no memory of the prior pass. The first four each found a substantial batch of genuine defects (citation misattributions, a hallucinated product claim, spliced evidence quotes, unsupported quantifiers) that were remediated in place; the fifth and sixth found progressively fewer, concentrated on one recurring clause (a solar-inverter entry's remediation-status wording, corrected three times before it tracked the primary source's exact claim). The sixth iteration's residual, truth 1 plus editorial 1 with no broken-URL or hallucinated-fact finding, cleared the early-exit bar: both were fixed and the run published without a further confirmation pass. One advisory-only finding on the same iteration (an over-attributed interpretive gloss) was also fixed. No entry was dropped by verification.
Sources:tp-link-omada-psirt's listing URL recipe fixed (see sources_changed). All 187 tracked sources probed clean by tools/source_health.py this run (92 direct-ok, 95 bridge-ok, 0 unsolved), no repair duty.