TL;DR
Cisco Secure Email Gateway SQL injection (CVE-2026-76461) added to CISA KEV catalog with federal remediation due 2026-09-17. Acronis cPanel backup flaw (a reported vulnerability (identifier could not be verified against NVD and has been withdrawn)) actively exploited for privilege escalation. Brazilian banking malware KREMLIN now hijacks Chrome and Edge to steal session tokens. Immediate patching required for Cisco and Acronis; monitor for browser-based credential compromise.
Executive Summary
- Cisco Secure Email Gateway SQL injection (CVE-2026-76461) now on CISA Known Exploited Vulnerabilities catalog; permits unauthenticated remote attackers to execute arbitrary commands with root privileges.
- Acronis backup plugin for cPanel/WHM/Plesk hosts a high-severity Linux local privilege escalation flaw (a reported vulnerability (identifier could not be verified against NVD and has been withdrawn)) being actively exploited in the wild.
- KREMLIN banking malware toolkit, tracked as REF9334 and active since May 2025, now documented hijacking Chrome and Edge browsers to steal credentials and session tokens.
- BambooToken malware framework, dormant since 2023, resurfaces using MQTT protocol to control both Windows and Linux systems in coordinated campaigns.
- Iranian intelligence service deploys Telegram-controlled Windows malware to surveil dissidents, journalists, and activists globally, per U.S., U.K., and Dutch cybersecurity agencies.
Top Threats Today
1. Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) — CISA KEV Addition
Severity: CRITICAL Affected: Technology
Cisco AsyncOS software for Cisco Secure Email Gateway contains a SQL injection vulnerability that allows an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system [1]. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2026-09-14, with federal remediation due by 2026-09-17 [1].
Sources:[1] CISA KEV
Recommended Action
- Immediately prioritize patching Cisco Secure Email Gateway instances; check vendor security advisories for available updates.
- If patching cannot be deployed within 24 hours, implement network segmentation to restrict unauthenticated access to SEG appliances.
- Monitor email gateway logs for suspicious SQL syntax, command injection patterns, and unexpected root-level process execution.
- Verify no unauthorized user accounts or email forwarding rules were created during potential compromise window.
2. Acronis Backup Plugin Linux Privilege Escalation (a reported vulnerability (identifier could not be verified against NVD and has been withdrawn)) — Active Exploitation
Severity: HIGH Affected: Technology
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild [1]. The flaw affects backup and disaster recovery infrastructure widely deployed across hosting providers and shared hosting environments.
Sources:[1] BleepingComputer
Recommended Action
- Inventory all deployments of Acronis backup plugin on cPanel, WHM, and Plesk systems.
- Apply available patches from Acronis immediately; verify update status on all affected backup appliances.
- Review system logs on affected hosts for privilege escalation attempts or successful lateral movement by unprivileged users.
- Restrict local shell access to backup plugin directories and enforce principle of least privilege for backup service accounts.
3. KREMLIN Banking Malware — Chrome and Edge Session Token Theft
Severity: HIGH Affected: Finance
Cybersecurity researchers from Elastic Security Labs have documented a previously undocumented Brazilian banking malware operation delivering a toolkit called KREMLIN, tracked under the moniker REF9334 [1]. Active since at least May 2025, the malware now hijacks Chrome and Edge browsers to steal credentials and session tokens, expanding beyond traditional banking-focused malware tactics [1].
Sources:[1] The Hacker News
Recommended Action
- Block or restrict execution of unknown executables in user browser profile directories (%APPDATA%\Local, etc.) via endpoint protection policies.
- Deploy browser isolation or sandboxing for high-risk banking and financial services access where feasible.
- Monitor for suspicious browser process spawning, DLL injection, or access to browser credential/session stores.
- Alert on Chrome and Edge process access to stored credentials, certificates, or session cookies; enforce re-authentication for sensitive financial operations.
4. BambooToken Multi-Platform Malware — MQTT Command & Control
Severity: HIGH Affected: Technology
A previously unknown malware family called BambooToken is now using the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control both Windows and Linux systems [1][2]. The malware framework has been active since at least 2023, with researchers now documenting coordinated multi-platform campaigns ⚠[2].
Sources:[1] The Hacker News[2] BleepingComputer
Recommended Action
- Block or monitor outbound MQTT traffic (port 1883 and 8883) at egress points unless explicitly required for operational IoT/OT systems.
- Review endpoint detection and response (EDR) tools for MQTT protocol anomalies and suspicious broker connections outside legitimate infrastructure.
- Segment Windows and Linux systems by network role; restrict lateral movement between operating system types where possible.
- Hunt for persistence indicators: scheduled tasks, cron jobs, or service installations correlated with unexpected MQTT connections.
5. Iranian Telegram-Controlled Windows Malware — Dissident Surveillance
Severity: HIGH Affected: Government
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world [1]. The malware is controlled via the Telegram messaging app, enabling command-and-control infrastructure that evades traditional network monitoring [1].
Sources:[1] The Hacker News
Recommended Action
- Organizations with personnel or operations in high-risk regions should implement endpoint hardening and endpoint detection and response (EDR) tools with behavioral anomaly detection.
- Monitor for suspicious Telegram client behavior or unauthorized Telegram API connections from Windows systems.
- Educate high-risk users on phishing lures and malware distribution; provide secure alternatives for communications.
- Preserve and analyze system logs for signs of initial compromise (email attachments, drive-by downloads, watering-hole exploitation).
Today’s Action Checklist
- ☐ CRITICAL: Verify no Cisco Secure Email Gateway instances are unpatched for CVE-2026-76461; confirm remediation plan meets 2026-09-17 federal deadline.
- ☐ URGENT: Inventory and patch all Acronis backup plugin deployments (cPanel/WHM/Plesk) for a reported vulnerability (identifier could not be verified against NVD and has been withdrawn); prioritize active production systems.
- ☐ HIGH: Scan endpoints for KREMLIN banking malware indicators; review browser process logs for DLL injection or credential store access on Windows systems.
- ☐ HIGH: Block egress MQTT traffic on ports 1883 and 8883 unless required; hunt for BambooToken persistence on Windows and Linux systems.
- ☐ HIGH: Review remote access and VPN logs for Telegram-based C2 activity; enhance EDR detection for Telegram API connections and unusual process behavior.