grc-scanSecurity & governance
News digest18 September 2026Archived edition

Cybersecurity News

This edition was published on 18 September 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest digest for the current picture.

The takeaway

Everything significant this week turned on proving you belong: a login check bypassed on an appliance, a remote-support session used against its owner, and a phone call from a fake IT help desk.

  • Tell staff plainly that IT will never ring and ask them to re-register MFA or a passkey — hang up, call back on a known number.
  • Patch anything that authenticates people or handles email in the week a fix lands, not the month.
  • Ask your IT provider and your web host, in writing, which of this week's fixes they have applied.

Cybersecurity News — 2026-09-18

Generated: 2026-09-18 | Sources: CISA, Cisco, Microsoft, Google, Acronis, ConnectWise, ISC, US Department of Justice, The Hacker News, SecurityWeek, BleepingComputer, Help Net Security, Rapid7, Qualys, Huntress, Shadowserver, CyberScoop, The Register


1. A Flaw in Remote-Support Software Lets an Attacker Push Files Onto Every Machine in a Session

ConnectWise ScreenConnect is remote-support software — the tool that puts the little icon in your system tray so an IT technician can take over your screen and fix something. A flaw in it (CVE-2026-84869, rated 9.9 out of 10) means that once a remote session is open, someone with only basic privileges can send a file to the connected computer and run it, without the person at the keyboard being asked to approve the transfer. Security firm Huntress reported three incidents in which attackers used exactly that to push malicious scripts onto newly connected machines. ConnectWise published a temporary workaround on 7 September (turn off the file-transfer permission) and a full fix in ScreenConnect 26.6.5; America's Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its list of vulnerabilities known to be under attack on 11 September. The Shadowserver Foundation still counts more than 1,000 exposed instances that have not been updated.

Why it matters for your business: the danger here is not the software, it is the trust. A remote-support session is one you deliberately allowed, so nothing looks wrong while it is happening. Ask whoever supports your IT whether they use ScreenConnect and whether they are on 26.6.5 or later. And adopt one habit that costs nothing: only accept a remote-support session you asked for, in a call you started, and close it the moment the work is finished rather than leaving it running in the background.


2. A Single Crafted Email Can Take Over Cisco's Email Security Appliance

Cisco Secure Email Gateway is the box that mail passes through on its way into a company — the thing that is supposed to strip out the spam and the malware before anyone sees it. Cisco disclosed on 14 September that a flaw in how it reads incoming messages (CVE-2026-76461, rated 9.8) lets an attacker send one specially built email and, through it, run commands on the appliance itself with the highest level of access. No login is needed and nobody has to open the message — the damage is done by the gateway simply processing it. Cisco said its incident response team learned of the flaw because it was already being exploited, and CISA added it to the known-exploited list the same day. Fixed versions are 15.5.5-014, 16.0.4-302 and 16.5.0-780.

Why it matters for your business: if you use Microsoft 365 or Google Workspace for email you do not run this appliance and there is nothing to patch — but plenty of accountants, law firms and manufacturers you deal with run mail on their own kit. The general lesson is worth more than the specific fix: security products are software too, and a device whose whole job is to open hostile input is an unusually attractive target. If anyone runs an on-premises mail gateway for you, ask today which version it is on.


3. Cisco Rushed Out an Emergency Patch for a Login System Attackers Were Already Inside

Cisco Identity Services Engine (ISE) is the system that decides who and what is allowed onto a corporate network — the gatekeeper for staff logins, laptops and other devices. A flaw in it (CVE-2026-76460) earns the maximum severity rating of 10.0: an API endpoint did not check authentication properly, so an attacker who can reach the box over the network can send crafted requests and get in without any credentials at all. Cisco found the flaw while working a customer's support ticket, meaning someone was already inside a live deployment before the company knew the hole existed. Fixes are in ISE and ISE-PIC 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11 and 3.1 Patch 12; restricting which addresses can reach the device reduces the risk but is not a substitute for patching. CISA added it to the known-exploited list on 16 September with a three-day federal patch deadline.

Why it matters for your business: most small firms do not run ISE, but almost every one of them runs something that decides who gets in — a VPN appliance, a Wi-Fi controller, a firewall login page, a remote desktop gateway. Make a short list of everything at your business that authenticates a person or a device, and make sure each one is on a supported version and set to update. Those are the boxes worth patching first when time is short, because a bypass there hands over everything behind them at once.


4. A Backup Plugin on Shared Web Hosting Is Being Used to Grab Control of the Server

Acronis Backup ships as a plugin for cPanel & WHM and an extension for Plesk — the control panels most small business websites are managed through. A flaw in it (CVE-2026-87886, rated 7.8) comes down to files being installed with permissions that are too generous, which lets someone who already has a limited account on that Linux server raise themselves to much higher privileges. Acronis has confirmed the flaw is being exploited in real attacks against cPanel installations, and CISA added it to the known-exploited list on 16 September. Fixed builds are 1.9.3 HF3 for the cPanel plugin and 1.8.11 for the Plesk extension. It is important to be precise about the risk: this is not a flaw an anonymous attacker on the internet can use to break in from nothing — they need a foothold on the server first. On shared hosting, that foothold is the other customers.

Why it matters for your business: if your website sits on shared hosting, your neighbours are part of your security. Email your host and ask two questions: whether they use the Acronis Backup plugin, and whether it is on the fixed build. While you are there, ask how they separate one customer's site from another's — a host that answers that clearly is worth keeping, and one that cannot is telling you something useful.


5. Criminals Are Phoning Staff Pretending to Be the IT Help Desk and Asking Them to "Re-Register" Their Passkey

Microsoft published research on a campaign that has been running since May 2026 in which attackers research a company and its employees, then telephone or text a member of staff — often on their personal mobile — claiming to be the internal IT help desk. The story is always urgent: you must update your passkey, multi-factor authentication or single sign-on setting right now or you will lose access. The victim is sent to a copy of the Microsoft sign-in page, and once the attacker is in, they add their own authentication method to the account, so the access survives a password change. Microsoft then observed bulk downloads from SharePoint and OneDrive and mailboxes being harvested through Microsoft's own programming interfaces. Microsoft attributes the initial break-ins to several tracked criminal groups it labels Storm-3121 and Storm-3032, among others; these are Microsoft's own assessments rather than proven findings, and the technique is what matters more than the label.

Why it matters for your business: this is the same idea as the two Cisco flaws above, one layer up — instead of tricking a system into believing the attacker is authorised, it tricks a person. That is the through-line of the week: a bypassed check in an appliance, a hijacked remote-support session, and a convincing phone call all end in the same place. Agree one rule with every member of staff and write it down: nobody from IT will ever ring you out of the blue and ask you to change an MFA or passkey setting. If someone does, hang up and call back on a number you already have. Then check your Microsoft 365 or Google account security settings today for any sign-in method you do not recognise.


6. Google Patched a Pixel Phone Flaw That Needed No Click at All

Google's September update for Pixel phones fixes a flaw in the device's cellular modem — the component that talks to the mobile network (CVE-2026-58704, rated 8.0). Because the modem processes network traffic before any app or person is involved, the flaw can be triggered without the owner tapping a link, opening a message or doing anything at all; it lets an attacker bypass permission checks and gain elevated control of the phone. Google says it has seen "limited, targeted exploitation" and has not attributed the attacks to anyone. Patches shipped on 15 September and CISA added the flaw to its known-exploited list the following day. The "limited and targeted" framing usually signals a small number of deliberately chosen victims rather than a mass campaign — which is reassuring for most people and no comfort at all if you are one of them.

Why it matters for your business: the practical action is dull and works. Check the phones that open your work email: Settings → Security → System update on Android, and the equivalent on iPhone, and install what is waiting. Do the same for any handset still on a model the manufacturer no longer supports — a phone that stopped receiving updates is not a cheap phone, it is an unpatched computer holding your business mailbox.


7. A Utility Confirmed a Breach After an Attacker Claimed Millions of Customer Records Came From an Exposed Interface

CenterPoint Energy, a large US utility, told the US financial regulator in a filing on 14 September that an unauthorised third party had obtained personal information about some customers through an external-facing system. The disclosure followed a post on a criminal forum in which someone claimed to hold roughly 7.49 million records and said they had come from an application programming interface — a machine-to-machine doorway into the company's systems — that they alleged lacked proper authentication and rate limiting. CenterPoint has confirmed a breach but has not confirmed that figure or that the published dataset is genuine, so treat the number as the attacker's claim rather than an established fact. Fields listed in the claim include names, addresses, account numbers, billing details, email addresses and partial identification numbers. Electricity and gas supply were unaffected.

Why it matters for your business: APIs are the part of a modern website nobody looks at. Your booking system, your online shop, your customer portal and your accounting integration all talk to each other through interfaces that were never designed for a human to visit — and they are frequently protected far less carefully than the login page beside them. Ask whoever built or maintains your site a direct question: which parts of it can be called without logging in, and what stops someone calling them ten thousand times in an hour?


8. Law Enforcement Seized One of the Longest-Running "Attack for Hire" Services

The FBI, working with the Royal Canadian Mounted Police, seized the domains behind NightmareStresser, a service that sold distributed denial-of-service attacks — flooding a website or network with junk traffic until it falls over — to anyone willing to pay. The US Department of Justice says the service was used in hundreds of thousands of actual or attempted attacks since 2022 against victims including schools, government bodies, gaming platforms and ordinary businesses. The takedown, announced on 17 September, is part of an ongoing international effort against these "booter" services. Services like this are the reason denial-of-service attacks are cheap and common: they remove all the skill from it, leaving only a subscription fee.

Why it matters for your business: the useful question is not whether you are a target but what happens if your website is unreachable for a day. If you take bookings or orders online, know in advance where your site is hosted, whether it sits behind a service that can absorb this kind of traffic (most mainstream hosts and content delivery networks offer one), and who you would call. Fifteen minutes spent finding that out now is worth more than any amount of panicking on the day.


9. The Software Behind Much of the Internet's Address Book Got a Large Batch of Fixes

The Internet Systems Consortium released BIND 9.20.29 and 9.21.26 on 16 September, fixing 14 vulnerabilities in BIND — the most widely used software for running DNS, the system that turns a name like yourbusiness.co.uk into the numeric address a computer actually connects to. Eight of the flaws are rated high severity. Some allow an unauthenticated attacker to crash or exhaust a DNS server remotely; more seriously, several enable cache poisoning, where forged answers are slipped into a server's memory so that it confidently sends visitors to the wrong place. ISC said it was not aware of any of these being exploited when it published. Unlike most of the entries above, this one is a fix that arrived ahead of the attacks rather than behind them.

Why it matters for your business: you almost certainly do not run BIND — your domain registrar, hosting company or internet provider does, and this is their job to apply. The part that is yours is smaller and more important: make sure nobody can change your DNS records but you. Turn on two-factor authentication at your domain registrar, check who else has access to that account, and make sure the renewal contact is an address someone still reads. An attacker who can edit your DNS does not need to poison anything — they can simply point your domain and your email wherever they like.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Summaries are compiled from public threat-intelligence feeds and security news sources. This digest is for awareness purposes only and does not constitute professional security advice.