Daily Briefing
Today's outlook
CISA flags an actively exploited Cisco email-gateway flaw as a ClickFix malvertising blitz hits Windows and Mac
Good morning. CISA added one new vulnerability to its Known Exploited Vulnerabilities Catalog on 14 September, describing it as a Cisco Secure Email Gateway SQL Injection Vulnerability and stating the addition was based on evidence of active exploitation. CISA's alert says Binding Operational Directive 26-04 establishes the vulnerability-management requirements that apply. What to do: identify any Cisco Secure Email Gateway appliances in your estate, apply the vendor's fixes or mitigations, and — if you are a federal agency — remediate on the BOD 26-04 timeline. The catalogue is at https://www.cisa.gov/known-exploited-vulnerabilities-catalog.
The Register and BleepingComputer both report that attackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks, infecting Windows and macOS devices with information-stealing malware. The Register describes it as part of a "massive 48-hour malvertising blitz." ClickFix relies on getting the user to run the attacker's command themselves, so the defence is user-facing: warn staff that a prompt to copy, paste or run a command to "fix" or "verify" something is the attack, and that a verified brand account is no guarantee of safety here.
Two intrusions were disclosed. BleepingComputer reports that Japan's Digital Agency found a data breach that exposed around 246,000 record rows containing personal information of government employees, tied to a VPN flaw. The Hacker News reports that threat-intelligence firm Hunt.io found an attacker operating inside 3BB, one of Thailand's largest broadband providers, maintaining remote control of internal machines through the legitimate management tool MeshCentral and targeting subscriber credentials. Audit your environment for unauthorised MeshCentral or similar remote-management tooling.
On the client side, BleepingComputer reports that a browser extension called "Twitch Enhanced Viewer | JeetBot," carried in the official Chrome and Firefox stores with about 30,000 installs, sends users' Twitch OAuth session tokens to a commercial bot service — remove it. The Register reports a new hardware device that can read encrypted DDR5 memory and expose data, noting the attacker needs physical access to the server. BleepingComputer reports Homebrew 7.0.0 shipped with a built-in vulnerability scanner and stronger security controls, and Help Net Security reports Apple's overhauled child-safety controls went live on 14 September, requiring iOS 27, iPadOS 27 or macOS 27.
In enforcement news, The Record reports that five alleged members of the "Black Axe" group were extradited from South Africa over a 2021 indictment accusing them of romance scams that stole from more than 100 people.
Zoom out: The Register and BleepingComputer both trace the day's Windows and macOS endpoint infections to a malvertising campaign pushed through a compromised HBO Max Reddit account, which The Register puts at 48 hours.
Vulnerability in focus
CVE-2026-87491 — Google. CVSS 8.8 CISA lists it as known to be exploited.
Affected: chrome.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
What we're tracking
- The Register: HBO Max Reddit account compromised to serve ClickFix attacks Read it
- Help Net Security: Apple parental controls in iOS 27 let kids ask before opening new websites Read it
- BleepingComputer: Microsoft releases emergency Windows updates to fix RDS failures Read it
- The Record: Members of ‘Black Axe’ cybercriminal group extradited from South Africa Read it
Sources
- HBO Max Reddit account compromised to serve ClickFix attacks The Register
- Apple parental controls in iOS 27 let kids ask before opening new websites Help Net Security
- Microsoft releases emergency Windows updates to fix RDS failures BleepingComputer
- Members of ‘Black Axe’ cybercriminal group extradited from South Africa The Record
- Upcoming Speaking Engagements Schneier on Security
- 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials The Hacker News
- Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development SecurityWeek
- CISA Adds One Known Exploited Vulnerability to Catalog CISA
- Cybersecurity jobs available right now: September 15, 2026 Help Net Security
- Japan's Digital Agency says VPN flaw exposed 246,000 personnel records BleepingComputer
- Homebrew 7.0.0 gets built-in GUI, better security controls BleepingComputer
- Twitch extension with 30K installs exposes users’ OAuth tokens BleepingComputer
- Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer
- New hardware device can RAM into encrypted memory, expose your data The Register
Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.