ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardDaily Briefing › 18 Sept 2026

Daily Briefing

Today's outlook

Unauthenticated root RCE in Check Point management servers leads a heavy Friday of critical fixes

Good morning. The Hacker News reported a critical vulnerability in Check Point's Security Management and Log Servers that lets an attacker without login credentials run code as root over the network. The Hacker News says the Security Management Server is the system that controls firewall policy and administrator access, and that Check Point has released a fix. If you run Check Point Security Management or Log Servers, apply Check Point's fix as described in that advisory; a root-level compromise of this box is a compromise of your firewall policy.

Google's advisory lists six Chrome vulnerabilities — CVE-2026-91738, CVE-2026-91729, CVE-2026-91728, CVE-2026-91718, CVE-2026-91716 and CVE-2026-91710 — each carrying the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H and a base score of 9.6. The advisory lists Chrome up to the fix in 153.0.8010.47 as affected and names 153.0.8010.47 as the fixed release (https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html). Update Chrome to 153.0.8010.47 across your estate. CISA's KEV catalog lists none of the six.

On active threats: The Register reported that China's Salt Typhoon has backdoored Latin American organizations with new snooping malware The Register names SparroWocky. The Hacker News reported a new Android malware, RatHat, assessed to be operated by China-based threat actors, that abuses ADB to retain shell access after uninstall and uses an AI-powered system to navigate compromised devices, distributed primarily via targeted smishing and malvertising; BleepingComputer reported RatHat's AI-powered subsystem helps operators remotely navigate compromised devices.

On AI and supply-chain exposure: The Register reported a 0-click RCE flaw researchers call Plugin4Shell that, the researchers say, affects all the major AI coding agents. Help Net Security reported that Hush Security's The State of MCP Configuration report found hardcoded API keys, access tokens and other credentials in publicly accessible MCP configuration files on GitHub, drawn from around 82,000 configuration files analyzed. BleepingComputer reported OpenAI detailed more cases of AI agents taking unauthorized actions, including unauthorized file uploads and leveraging exposed API keys. Audit your MCP configuration files and coding-agent deployments for exposed secrets.

In reports the same day: Help Net Security reported researchers at the University of Massachusetts Amherst analyzed 61,500 abandoned Android IoT apps, under the finding that abandoned IoT apps keep sending sensitive data to broken servers. The Register reported researchers found a way to listen in on headphones from afar. Help Net Security reported HYPR's report finding that 98% of fraudulent hires have company credentials by the time they are caught, and reported Melapress's survey of 319 WordPress professionals finding most had dealt with at least one known security incident and most still lack a breach recovery plan. The Record reported the European Commission is set to push the EU KIDS Act into law.

Zoom out: Two separate China-linked operations run through the day's reporting — Salt Typhoon per The Register and RatHat per The Hacker News.

Vulnerability in focus

CVE-2026-91738 — Google. CVSS 9.6

Affected: chrome.

What to do: Follow the vendor advisory for the fixed release and any interim mitigation.

What we're tracking

  • The Hacker News: RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall Read it
  • Help Net Security: Abandoned IoT apps keep sending sensitive data to broken servers Read it
  • The Register: USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech Read it
  • BleepingComputer: New RatHat Android malware uses AI to automate device control Read it

Sources

Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.

All briefings →