ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardDaily Briefing › 16 Sept 2026

Daily Briefing

Today's outlook

CISA flags two actively exploited flaws in Cisco ISE and Acronis Backup; Google patches six critical Chrome bugs

Good morning. CISA says it added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog "based on evidence of active exploitation": a Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability and an Acronis Backup Incorrect Default Permissions Vulnerability. If you run Cisco ISE or Acronis Backup, apply the available vendor updates and prioritise these two over routine patching, since CISA states they are being exploited now.

The Hacker News reported that a critical flaw in Issabel Framework, the web-based front end for the open-source unified-communications PBX, has come under active exploitation and lets an unauthenticated remote attacker execute arbitrary OS commands. Anyone exposing an Issabel management interface should restrict it to trusted networks and apply any vendor update.

Google's advisory lists six flaws fixed in Chrome 153.0.8010.47, each carrying the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H and a base score of 9.6: CVE-2026-91738, CVE-2026-91729, CVE-2026-91728, CVE-2026-91718, CVE-2026-91716 and CVE-2026-91710. Google lists Chrome up to the fix in 153.0.8010.47 as affected. Update to that build and confirm managed fleets have restarted to apply it.

Help Net Security reported a Parallels Desktop flaw dubbed "ParaShells" that lets any local user on a Mac gain root on the host, with a proof of concept from JFrog; Help Net Security says the danger is highest on developer laptops. Apply any available Parallels Desktop update on Macs running the product.

BleepingComputer reported that Microsoft is investigating the Windows 11 KB5124008 security update breaking domain trust relationships on some enterprise systems, preventing logins with valid domain credentials. Test KB5124008 before wide deployment and watch Microsoft's release-health notes.

On threats: BleepingComputer reported that government agencies warn Iranian state-linked hackers are using Windows malware named CHOSEN BRICK against dissidents, activists and journalists, and separately that a banking-malware toolkit named KREMLIN force-installs malicious Chrome and Edge extensions to steal credentials and session tokens. SecurityWeek reported Spanish regulators say an AI agent chained a login, vulnerability discovery and access to personal data. Schneier on Security described fake-CAPTCHA scams that trick users into running malicious programs. The Record reported the Coast Guard and FBI boarded a Gulf of Mexico tanker after an apparent attack by "foreign cyber actors."

Zoom out: CISA added two actively exploited flaws to its catalog the same day The Register reported the agency will retire its weekly vulnerability bulletin on 28 September.

Vulnerability in focus

CVE-2026-91738 — Google. CVSS 9.6

Affected: chrome.

What to do: Follow the vendor advisory for the fixed release and any interim mitigation.

What we're tracking

  • The Register: AI agents can modify themselves without humans telling them to do so Read it
  • The Record: Key lawmaker suggests action on AI safety legislation will wait until 2027 Read it
  • BleepingComputer: Windows 11 KB5124008 update breaks domain trust for some users Read it
  • Krebs on Security: Data Broker Radaris Loses Domains in Privacy Fight Read it

Sources

Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.

All briefings →