Threat Brief — 2026-09-17 — Cisco ISE zero-day under active attack
Cisco has disclosed a maximum-severity Identity Services Engine zero-day that is being exploited in the wild, making it the most urgent item today. Microsoft has published a workaround for September patch-related domain login breakage that is disrupting enterprise authentication. Meanwhile, the Revolut extortion timeline escalates with a $3M cryptocurrency ultimatum, and Tez Tour has reportedly confirmed its breach after DataSuckers' claims.
Top items
- Cisco ISE maximum-severity zero-day actively exploited. Cisco has released security updates for a critical Identity Services Engine vulnerability that attackers are exploiting in the wild. The flaw was added to CISA's KEV catalog today. ISE is widely deployed for network access control, so this presents a high-impact attack surface where exploitation can pivot to broader network compromise. (src: BleepingComputer) — Developing: first reported 2026-09-17 by CISA KEV; BleepingComputer now adds vendor advisory and exploitation detail.
- TP-Link cameras accessible without password, exposing live video feeds. Security reporting indicates that certain TP-Link IP cameras can be compromised without authentication, allowing attackers to view live video streams. This is particularly relevant for any camera deployed in sensitive or private locations. No CVE identifier was provided in the source. (src: SecurityLab)
- Microsoft issues workaround for Windows 11 domain login breakage from September patches. A known issue introduced by the September 2026 security updates (KB5124008) prevents users from logging in with valid domain credentials due to broken domain trust. Microsoft has now published a temporary workaround. (src: BleepingComputer) — Developing: first reported 2026-09-16 by BleepingComputer; Microsoft has now provided a workaround.
- Revolut extortion escalates: hackers demand $3M in Monero. The group "iamnotavillain" has issued an ultimatum to Revolut, demanding 6,000 Monero (~$3M) and threatening to sell customer dossiers including documents, IBANs, and transaction histories. This marks an escalation from the original breach disclosure. (src: SecurityLab) — Developing: first reported 2026-09-13 by SecurityLab; the extortion demand and threat to sell data are new.
- Tez Tour reportedly confirms cyberattack after DataSuckers claimed 395M records. Tez Tour representatives have confirmed the incident following the DataSuckers group's claims of server compromise, data theft, and website defacement on 15 September. (src: Xakep) — Developing: first reported 2026-09-16 by SecurityLab; vendor confirmation is the new development.
- Ukrainian programmer sentenced to 13 years in LockerGoga case. A court has sentenced a Ukrainian programmer to 13 years in prison in connection with the LockerGoga ransomware case, citing source code found on the defendant's computer as more compelling than claims of benign development work. (src: SecurityLab)
- Academic research: latent world model backdoor attack for downstream control. Researchers have demonstrated a backdoor attack against pretrained world models used as dynamics backbones for control tasks. The attack embeds triggers in the latent state space that cause harmful downstream behaviour when the model is reused for control. This is relevant to organisations adopting pretrained AI/ML components in autonomous or control systems. (src: Seebug)
Themes
Two patterns are visible today. First, critical infrastructure weaknesses in identity and access management continue to surface — Cisco ISE and the Windows domain trust breakage both affect the authentication layer that everything else depends on. Second, extortion tactics are evolving beyond simple data theft: the Revolut ultimatum and DataSuckers' combined defacement-plus-extortion approach suggest threat actors are increasingly combining public pressure with ransom demands.
