THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Fake Voicemail Transcript Emails Target 7,800+ Organizations in Large-Scale Credential Phishing

Attackers are weaponizing a familiar enterprise workflow—automated voicemail transcription notifications—to trick users into visiting credential-harvesting pages. The campaign uses SVG-based delivery that redirects victims after execution of the malicious content, blending into normal collaboration communication. The scale (thousands of organizations) underscores that “routine” email formats are increasingly being abused for high-conversion credential theft.

Source: Check Point Blog


CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild (CISA KEV Added)

GitLab fixed CVE-2026-85706, a critical path traversal flaw in the repository commits API (CWE-22) that can allow unauthenticated attackers—under certain conditions—to read arbitrary files. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with a remediation due date of September 14, 2026, signaling real-world abuse. If you run self-managed GitLab, treat this as an emergency patch and follow forensic triage guidance due to the KEV designation.

Source: Rapid7


Apple Patches a Record 261 Vulnerabilities Across All Operating Systems

Apple released its annual security updates covering new features and a broad set of fixes, patching 261 vulnerabilities across its ecosystem. The total is the highest the company has ever patched, reinforcing that organizations should not rely on “fewer patches” assumptions when assessing vendor update cadence. Security teams should prioritize patching the highest-risk components first while ensuring endpoint and mobile fleets are fully updated.

Source: SANS ISC


Revolut Data Breach: Government Impostor Used a Legitimate Email Domain to Obtain IDs and Records

Revolut confirmed that an attacker impersonating a government agency obtained sensitive customer data after sending an emergency request from a legitimate-looking government email domain. Exposed data reportedly included birth dates, contact details, and identity document copies. The incident highlights how “credentialing the request” (domain lookalikes, plausible urgency, and process abuse) can bypass defenses that focus purely on system intrusions.

Source: RecordedFuture


Cisco Secure Email Gateway Root RCE Zero-Day Under Active Exploitation

A critical Cisco Secure Email Gateway vulnerability (CVE-2026-76461) is being exploited in the wild, enabling unauthenticated remote attackers to execute commands with root privileges through malicious email handling paths. A root-level remote command execution flaw in an email gateway is particularly dangerous because it can rapidly turn one inbound message into full system compromise. Organizations using affected AsyncOS deployments should treat this as urgent remediation and validate whether exploitation indicators are present.

Source: Security Week


ClickFix Campaign: HBO Max Reddit Account Used to Push Malware via Fake “Browser Action” Pages

Security researchers report that a compromised HBO Max Reddit account has been leveraged in a multi-day malvertising operation pushing victims to ClickFix-style pages. These pages attempt to trick users into making browser interactions that result in malware installation attempts on macOS and Windows. The recurring pattern: attackers compromise a trusted brand/channel, then weaponize user confusion at the “last click” stage.

Source: TechCrunch Security


ENISA Activates CRA “Single Reporting Platform” for Actively Exploited Vulnerabilities

The EU cybersecurity agency ENISA has launched the Cyber Resilience Act (CRA) single reporting platform for manufacturers to submit reports of actively exploited vulnerabilities and severe incidents. Reporting obligations began binding on September 11, 2026, with ENISA running the portal operationally under Article 16. For security leaders and vendors, this is a meaningful policy shift that may improve timeliness and transparency of exploit-in-the-wild disclosures across the EU supply chain.

Source: Help Net Security


You May Also Be Interested In...

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

WhatsApp Restricted Chat Locks a Conversation to Your Primary Phone

Cybersecurity — September 15, 2026 | Briefing24