Breaking: Cisco Email Gateway 0-Day Exploited, Revolut Data Breach Exposed
Latest cybersecurity developments highlight critical vulnerabilities, emerging threats, and strategic responses across the industry.
Revolut Breach
A breach at Revolut involved unauthorized access to customer data through a spoofed government agency communication. Attackers used a domain associated with a legitimate organization to impersonate officials and extract sensitive information. The bank confirmed the incident on September 12, 2026, though details about the scope and specific data compromised remain undisclosed.
Cisco Vulnerabilities
Cisco addressed an actively exploited zero-day vulnerability (CVE-2026-76461) in its Secure Gateway appliances. The flaw, a SQL injection vulnerability, was identified in September 2025, with indicators of compromise (IOCs) shared to help organizations detect potential breaches. A separate vulnerability (CVE-2026-76460) in Cisco Identity Services Engine (ISE) also saw exploitation, allowing unauthorized access to the management interface.
Other Security Updates
Other notable security updates include a privilege escalation flaw (CVE-2026-87886) in Acronis’ cPanel, WHM, and Plesk backup extensions, which attackers are leveraging in targeted campaigns. Parallels Desktop users face a critical risk via CVE-2026-90894, a vulnerability enabling local users to gain root access on macOS systems.
Cyber Resilience Act
The European Union Agency for Cybersecurity (ENISA) launched the Cyber Resilience Act’s Single Reporting Platform on September 11, 2026, requiring manufacturers to report active vulnerabilities.
AI Security Challenges
AI-related security challenges continued to dominate discussions. The EU’s Ursula von der Leyen called for slower development of frontier AI systems, advocating for collaborative efforts with global partners to establish security frameworks. Researchers highlighted risks in AI-driven open-source project maintenance, where automated tools introduce complexity without adequate oversight.
A zero-day remote code execution (RCE) vulnerability affected four major AI coding agents, including Claude Code, GitHub Copilot, and Gemini CLI. While some vendors have released patches, two remain unaddressed as of September 2026.
Threat Actor Activity
In the realm of threat actor activity, Iranian state-sponsored groups deployed CHOSEN BRICK malware to target dissidents and journalists via social messaging apps. Additionally, a breach at CenterPoint Energy was reported following claims on a hacking forum, though the company has not yet disclosed specifics.
Cybercriminal Tactics
Cybercriminals also exploited high-profile platforms, such as HBO Max’s verified account, to distribute malware through a ClickFix campaign. Scammers are increasingly using AI to create polished fake antivirus renewal pages, as noted by Malwarebytes.
Law Enforcement Actions
The FBI dismantled NightmareStresser, a long-running DDoS-for-hire service, and AWS acknowledged permanent data loss in its Middle East regions due to Iranian drone strikes.
IoT and AI Governance
Abandoned IoT apps continue to pose risks, with 75% of analyzed Android IoT applications containing vulnerable dependencies. Organizations are also grappling with AI governance. Experts stress the need for proactive oversight of AI agents, emphasizing that prompt-based instructions alone cannot prevent unintended behaviors.
Industry Responses
Google introduced an agent security system to detect misuse, while Microsoft outlined new guidelines for AI model development.
Conclusion
As the cybersecurity landscape evolves, enterprises must prioritize patch management, threat intelligence, and adaptive security strategies to mitigate emerging risks.
