SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefFriday, September 18, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Active Zero-Day Exploit in Cisco ISE (CVE-2026-76460) | CRITICAL |
|
5 C2 IPs | 80 OTX IOCs | 40 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is dominated by a critical, actively exploited zero-day vulnerability (CVE-2026-76460) in Cisco Identity Services Engine (ISE) and a critical heap overflow in NLnet Labs Unbound DNS resolvers. Additionally, supply-chain attacks are escalating, as seen in the Brevo compromise where stolen Cloudflare API keys were used to inject malicious ClickFix scripts. On the espionage front, China-aligned threat actor FamousSparrow is actively targeting Latin American governments using a new backdoor called SparroWocky. |
|
■ CRITICAL STORIES Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Cisco has warned of a maximum-severity auth bypass vulnerability (CVE-2026-76460) in its Identity Services Engine (ISE) that is being actively exploited in the wild, allowing unauthenticated remote attackers to gain root-level access. |
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Every release of NLnet Labs Unbound before 1.26.1 contains a critical heap overflow in its DNSSEC validator, allowing remote attackers controlling a malicious zone to achieve remote code execution (RCE). |
Brevo supply-chain attack injected ClickFix scripts on customer sites Attackers stole a Cloudflare API key from Brevo to inject malicious ClickFix scripts into customer-facing JavaScript files, distributing malware via a trusted email marketing platform. |
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America The state-sponsored group FamousSparrow has been targeting Latin American government entities since at least August 2025 using a newly discovered backdoor named SparroWocky to conduct espionage. |
|
■ CVEs IDENTIFIED CVE-2026-76460 Cisco Identity Services Engine (ISE) — Authentication bypass exploited in active attacks, allowing unauthenticated remote attackers to gain unauthorized access. |
[CVE-TBD] (NLnet Labs Unbound) NLnet Labs Unbound — Heap overflow in DNSSEC validator prior to version 1.26.1, allowing remote code execution (RCE) via a malicious DNS zone. |
[CVE-TBD] (ISC BIND 9) ISC BIND 9 — 14 vulnerabilities, including an unauthenticated crash over DNS-over-HTTPS (DoH) and resource exhaustion. |
[CVE-TBD] (Cisco FMC/Nexus) Cisco Firepower Management Center & Nexus Dashboard — Flaws leading to root access, command execution, bypasses, SQL injection, and remote code execution. |
|
■ THREAT ACTORS China-aligned state-sponsored threat actor deploying the "SparroWocky" backdoor to target government organizations in Latin America. |
BlackCore | Private Contractor |
Israeli influence-for-hire company training Angolan officials in online influence operations and fake persona creation. |
NightmareStresser Operators | Cybercriminals |
Operators of the NightmareStresser DDoS-for-hire platform seized by the FBI. |
|
|
|
■ ATT&CK TTPs | T1195.002 | | Supply Chain Compromise: Compromise of Software Dependencies and Environments | Injected ClickFix scripts on Brevo customer sites. |
| T1566.001 | | Phishing: Spearphishing Attachment | LausivLoader distributed via malspam message. |
| T1566.002 | | Phishing: Spearphishing Link | Phishing texts targeting Revolut and T-Mobile customers. |
| T1219 | | Remote Access Software | RatHat Android malware utilizing AI to automate device control. |
| T1110.002 | | Password Cracking | Gyazo breach exposing password hashes. |
| T1078 | | Valid Accounts | Abuse of stolen Cloudflare API key in Brevo supply-chain attack. |
|
■ PATCH PRIORITY CRITICAL — Cisco Identity Services Engine (ISE) — Actively exploited CVSS 10.0 auth bypass (CVE-2026-76460) — THN |
CRITICAL — NLnet Labs Unbound — Heap overflow in DNSSEC validator allowing RCE — THN |
HIGH — ISC BIND 9 — 14 vulnerabilities including unauthenticated crash over DoH — THN |
HIGH — Cisco Firepower Management Center (FMC) & Nexus Dashboard — Multiple flaws leading to root access/RCE — SW |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately patch Cisco Identity Services Engine (ISE) to address the actively exploited CVE-2026-76460 authentication bypass vulnerability. |
| 2 | [P1] Upgrade NLnet Labs Unbound DNS resolvers to version 1.26.1 or later to mitigate the critical DNSSEC validator heap overflow RCE flaw. |
| 3 | [P1] Apply BIND 9 security updates (9.20.29 / 9.21.26) to remediate 14 vulnerabilities, including the unauthenticated DoH crash. |
| 4 | [P2] Audit and rotate all Cloudflare API keys and third-party integrations for Brevo to ensure malicious ClickFix scripts are completely purged. |
| 5 | [P2] Deploy the Microsoft-provided temporary workaround for Windows 11 domain login issues resulting from the September 2026 security updates. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |