CISA flags an actively exploited Cisco email-gateway flaw as a ClickFix malvertising blitz hits Windows and Mac
Monday brought one new actively-exploited vulnerability onto CISA's catalogue and a two-day malvertising campaign, run through a hijacked HBO Max Reddit account, aimed at both major desktop platforms.
CISA added one new vulnerability to its Known Exploited Vulnerabilities Catalog on 14 September, describing it as a Cisco Secure Email Gateway SQL Injection Vulnerability and stating the addition was based on evidence of active exploitation. CISA's alert says Binding Operational Directive 26-04 establishes the vulnerability-management requirements that apply. What to do: identify any Cisco Secure Email Gateway appliances in your estate, apply the vendor's fixes or mitigations, and — if you are a federal agency — remediate on the BOD 26-04 timeline. The catalogue is at https://www.cisa.gov/known-exploited-vulnerabilities-catalog.
The Register and BleepingComputer both report that attackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks, infecting Windows and macOS devices with information-stealing malware. The Register describes it as part of a "massive 48-hour malvertising blitz." ClickFix relies on getting the user to run the attacker's command themselves, so the defence is user-facing: warn staff that a prompt to copy, paste or run a command to "fix" or "verify" something is the attack, and that a verified brand account is no guarantee of safety here.
Two intrusions were disclosed. BleepingComputer reports that Japan's Digital Agency found a data breach that exposed around 246,000 record rows containing personal information of government employees, tied to a VPN flaw. The Hacker News reports that threat-intelligence firm Hunt.io found an attacker operating inside 3BB, one of Thailand's largest broadband providers, maintaining remote control of internal machines through the legitimate management tool MeshCentral and targeting subscriber credentials. Audit your environment for unauthorised MeshCentral or similar remote-management tooling.
On the client side, BleepingComputer reports that a browser extension called "Twitch Enhanced Viewer | JeetBot," carried in the official Chrome and Firefox stores with about 30,000 installs, sends users' Twitch OAuth session tokens to a commercial bot service — remove it. The Register reports a new hardware device that can read encrypted DDR5 memory and expose data, noting the attacker needs physical access to the server. BleepingComputer reports Homebrew 7.0.0 shipped with a built-in vulnerability scanner and stronger security controls, and Help Net Security reports Apple's overhauled child-safety controls went live on 14 September, requiring iOS 27, iPadOS 27 or macOS 27.
In enforcement news, The Record reports that five alleged members of the "Black Axe" group were extradited from South Africa over a 2021 indictment accusing them of romance scams that stole from more than 100 people.
Sources
- The Register — HBO Max Reddit account compromised to serve ClickFix attacks
- Help Net Security — Apple parental controls in iOS 27 let kids ask before opening new websites
- BleepingComputer — Microsoft releases emergency Windows updates to fix RDS failures
- The Record — Members of ‘Black Axe’ cybercriminal group extradited from South Africa
- Schneier on Security — Upcoming Speaking Engagements
- The Hacker News — 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
- SecurityWeek — Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development
- CISA — CISA Adds One Known Exploited Vulnerability to Catalog
- Help Net Security — Cybersecurity jobs available right now: September 15, 2026
- BleepingComputer — Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
- BleepingComputer — Homebrew 7.0.0 gets built-in GUI, better security controls
- BleepingComputer — Twitch extension with 30K installs exposes users’ OAuth tokens
- BleepingComputer — Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
- The Register — New hardware device can RAM into encrypted memory, expose your data