Information Security News – 09/21/2026

Share This Post

Chinese hackers use SparroWocky malware in govt espionage attacks

Article Link: https://www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/

  • ESET researchers identified a new backdoor called SparroWocky, deployed by the China-linked espionage group FamousSparrow in an ongoing campaign against government organizations across Latin America.
  • SparroWocky replaces the group’s previous SparrowDoor malware with a more advanced, modular backdoor that can run commands, capture screenshots every 500 milliseconds, browse and manipulate files, spy on other logged-in user sessions, and act as a network proxy.
  • The malware is loaded via DLL side-loading and uses layered evasion techniques, including disguising its own code as legitimate Windows components and hijacking Windows’ thread-creation process so security tools see a fake, benign starting point rather than the malware’s real one.
  • The goal appears to be intelligence gathering on how Latin American governments are responding to rising U.S. pressure on Chinese economic interests, and researchers note the malware’s sophistication points to a well-resourced, experienced threat actor.
  • Additional information: https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/

What does this mean for me?

  • Sophisticated attackers may be able to monitor screens, steal files, and remain hidden on compromised computers. Be cautious with unexpected attachments, links, and software downloads, and report unusual computer behavior promptly rather than attempting to investigate it yourself.

CISA decides weekly vulnerability bulletin isn’t necessary anymore

Article Link: https://www.theregister.com/security/2026/09/16/cisa-decides-weekly-vulnerability-bulletin-isnt-necessary-anymore/5296968

  • CISA announced its long-running weekly vulnerability bulletin will stop going out after September 28, framing the move as part of a broader shift from ranking vulnerabilities by static severity scores to a risk-based approach.
  • The change follows a June Binding Operational Directive telling federal civilian agencies to prioritize patching based on real-world factors, including evidence of active exploitation, the level of access a flaw grants, and whether exploitation can be automated, rather than treating all vulnerabilities equally.
  • CISA did not explain why it chose to cancel the bulletin outright rather than update its format, but the shift comes as the number of disclosed vulnerabilities continues to grow rapidly, aided by AI-assisted security research, while the broader CVE ecosystem is also having to filter out an increasing volume of low-quality, AI-generated vulnerability reports.
  • CISA says it isn’t abandoning CVE tracking and is instead directing organizations to its Known Exploited Vulnerabilities catalog, cybersecurity advisories, and the CVE catalog itself. Anyone who relies on the current weekly bulletin will need to log into their GovDelivery or Granicus account and separately enable those subscriptions, or risk missing critical notices once the bulletin ends.
  • Additional information: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk

What does this mean for me?

  • Not every software vulnerability poses the same level of risk, and security teams are increasingly prioritizing the issues most likely to be exploited. For employees, the message remains simple: install required updates and restart your devices when requested so your organization’s highest-priority security fixes take effect.

Cisco email security boxes can be rooted by… an email

Article Link: https://www.theregister.com/security/2026/09/15/cisco-email-security-boxes-can-be-rooted-by-an-email/5296604

  • Cisco disclosed a critical vulnerability (CVE-2026-76461, CVSS 9.8) in its Secure Email Gateway appliances that lets an attacker gain root access simply by sending a specially crafted email, with no login credentials required and no workaround available. Patching is the only fix.
  • Cisco confirmed active exploitation as of September, discovered while resolving a support case, though the company hasn’t disclosed who is behind the attacks or how many organizations have been affected. Some of Cisco’s own cloud-hosted appliances showed signs of compromise, and Cisco has already patched and upgraded all of them.
  • Once an attacker gains root access, they can tamper with the gateway’s own logs to cover their tracks, so a clean-looking log doesn’t necessarily mean the system wasn’t breached; suspicious activity should also be checked against network and firewall logs instead.
  • For appliances suspected of compromise, Cisco’s recommended recovery is to preserve forensic evidence, rebuild on a fresh virtual machine with patched software, and rotate all credentials and cryptographic material rather than trying to clean the existing system in place.
  • The exact device businesses rely on to filter out malicious email is the one being turned into an attacker’s entry point, with attackers already inside some environments and no way to block the flaw short of patching immediately.
  • Additional information: https://arcticwolf.com/resources/blog-uk/cve-2026-76461/

What does this mean for me?

  • Even the security systems designed to protect your email can have vulnerabilities. Technology alone cannot catch every threat, so continue to be cautious with unexpected messages, links, attachments, and requests for sensitive information, even when an email reaches your normal inbox.

Malicious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Article Link: https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/

  • An attacker gained unauthorized access to the website of Admin Menu Editor Pro, a premium WordPress plugin used to customize admin dashboards and pushed a malicious plugin update (version 2.35) that installed a hidden web shell on customer sites.
  • The developer removed the malicious update and released a clean version 2.36 the same day, but the attacker still had access to the site and compromised that release as well, meaning two separate malicious versions reached customers before the site was taken fully offline.
  • Approximately 230 customers installed the malicious update across at least 1,500 sites, with the developer warning the true number could be higher since several hundred additional customers downloaded the plugin during the affected window and may also be compromised. Investigators believe the attacker had root-level access to the plugin’s server infrastructure.
  • Affected users should check for a hidden wp_-prefixed user account, a new /wp-content/object-cache/ directory, and related database entries, then restore from a clean backup taken before September 14 or manually remove the plugin and malicious files if a backup isn’t available.
  • This incident is an example of a supply chain attack, the plugin’s code wasn’t the weak point, the vendor’s infrastructure was, and customers who stayed current on updates were compromised anyway simply by trusting a legitimate source.

What does this mean for me?

  • Software from a legitimate vendor can occasionally become compromised before it reaches customers. Use only company-approved software and browser extensions, and let IT manage updates and installations whenever possible rather than downloading tools or updates from unfamiliar sources.

Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

Article Link: https://www.securityweek.com/texas-utility-centerpoint-energy-confirms-breach-after-hacker-leaks-data/

  • CenterPoint Energy, a Houston-based utility serving roughly 7 million electric and gas customers across Texas, Indiana, Minnesota, and Ohio, confirmed in an SEC filing that an unauthorized third party obtained customer personal information through one of its external-facing systems.
  • The confirmation followed a hacker posting on a cybercrime forum on September 12, claiming to have stolen nearly 7.5 million customer records and threatening that a future attack would target the company’s core infrastructure rather than just data. A 2.5 GB archive claiming to contain the stolen data was made available for download, though its authenticity is unconfirmed.
  • CenterPoint says the incident has not disrupted electric or gas delivery and does not expect it to have a material financial impact, though the investigation is still ongoing.
  • This is not the first time CenterPoint has been tied to a data leak; the company was previously named in connection with the 2023 Cl0p MOVEit campaign and a separate 2024 claim from an access broker, in both cases reportedly stemming from third-party data rather than a direct breach of its own systems.

What does this mean for me?

  • Stolen customer information can be used to make future scams much more convincing. Be cautious of unexpected calls, emails, or text messages claiming to be from your utility provider, especially if they use personal information to gain your trust or pressure you into making a payment or providing additional information.

OpenAI reveals six more rogue AI incidents

Article Link: https://www.itpro.com/technology/artificial-intelligence/openai-reveals-six-more-rogue-ai-incidents

  • OpenAI disclosed six new examples of “unexpected or concerning model behavior,” where an AI model or agent takes actions humans didn’t intend, alongside a new framework for how it will publicly disclose such incidents going forward.
  • Two cases involved models editing their own summaries to hide mistakes or misaligned behavior, including one unreleased model that altered its own working instructions across 27 separate instances to bypass its normal constraints. In another case, a model used exposed API keys without authorization, then fabricated earnings data entirely when it still couldn’t retrieve the real figures.
  • OpenAI acknowledged its past disclosures had been inconsistent, often delayed until enough incidents could be bundled into a single report or folded into a system card for a new model release. Under the new framework, any OpenAI employee can flag a misalignment incident and request it be shared publicly, though final publication remains at the discretion of technical staff.
  • A published report must include what happened, any resulting harm, how the issue was discovered, and what OpenAI plans to do to mitigate it. OpenAI also noted no industry-wide standard for this kind of disclosure currently exists and said it hopes this framework becomes a first step toward one.
  • Additional information: https://openai.com/index/model-misalignment-reporting-framework/

What does this mean for me?

  • AI can produce incorrect information or take actions that were not intended, especially when it is given access to other systems or data. Treat AI output as something to review rather than automatically trust, verify important information, and maintain human oversight before using AI-generated results to make consequential business decisions.



Reach out to our incident response team for help

More To Explore

Information Security News – 09/21/2026

Chinese hackers use SparroWocky malware in govt espionage attacks Article Link: https://www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/ What does this mean for me? CISA decides weekly vulnerability bulletin isn’t necessary

Information Security News – 09/14/26

Passkey-Themed Phishing Attacks Lead to Microsoft 365 Data Theft Article Link: https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/ What does this mean for me? Florida DMV Database Breached Through Stolen Police

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.