Threat Brief — 2026-09-14 — Trusted platforms weaponised
CISA has added a actively exploited Cisco Secure Email Gateway SQL injection flaw to its KEV catalogue, while Japan's Digital Agency disclosed a VPN-related breach affecting roughly 246,000 government employee records. Microsoft shipped emergency out-of-band Windows updates to resolve RDS breakage from September's patch cycle. Separately, attackers compromised HBO Max's official Reddit account to push ClickFix-style infostealer payloads — the latest evolution in a campaign that has increasingly abused legitimate services for distribution.
Top items
- Cisco Secure Email Gateway SQL injection (CVE-2026-76461KEV) added to CISA KEV. CISA added this vulnerability to its Known Exploited Vulnerabilities catalogue based on evidence of active exploitation in the wild. SQL injection in an email gateway can allow attackers to bypass authentication or extract sensitive message data from a perimeter security device. This has not yet been featured in a prior brief; it was first reported today by CISA. (src: CISA)
- Japan Digital Agency discloses VPN breach exposing ~246,000 personnel records. A flaw in a VPN appliance allowed access to approximately 246,000 rows of government employee personal data. The breach illustrates how single-appliance vulnerabilities at perimeter layers can expose large volumes of internal records. This has not yet been featured in a prior brief; it was first reported today by BleepingComputer. (src: BleepingComputer)
- Microsoft releases emergency out-of-band Windows updates for RDS failures. Microsoft has issued out-of-band patches to fix Remote Desktop Services breakage caused by September's security updates, alongside Hyper-V and USB audio issues on some versions. This is a genuine development in an ongoing story first reported 2026-09-10 by BleepingComputer; the emergency fix represents Microsoft's first official remediation for the RDS regression. (src: BleepingComputer)
- HBO Max Reddit account hijacked to push ClickFix infostealer ads. Attackers compromised HBO Max's official Reddit account and used it to serve malicious ClickFix advertisements targeting both Windows and macOS users with information-stealing malware. This is a new development in an ongoing ClickFix campaign first reported 2026-09-05 by BleepingComputer; the compromise of a high-profile brand's social media account marks an escalation in the campaign's abuse of trusted platforms. (src: BleepingComputer)
- Homebrew 7.0.0 ships with built-in vulnerability scanner and BrewUI. The macOS/Linux package manager's latest major release adds an integrated vulnerability scanner, stronger security controls, and a native graphical interface. Supply-chain tooling improvements like built-in vulnerability scanning reduce the risk of compromised or outdated dependencies in development environments. (src: BleepingComputer)
Themes
Trusted-platform abuse continues to scale. The HBO Max Reddit compromise follows a pattern seen earlier this month with a malicious Twitch browser extension available in official Chrome and Firefox stores. Attackers are increasingly leveraging legitimate, high-trust distribution channels — verified social media accounts and platform extension stores — to deliver malware, reducing the effectiveness of reputation-based defences that rely on source credibility.
===
