The Matthew Chapman Podcast

Cisco Email Gateway Root RCE Is Live on CISA's Clock

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 4:43
Here is your briefing for Tuesday, September 15, 2026. Cisco says a critical AsyncOS bug in Secure Email Gateway, C.V.E. twenty twenty-six dash seventy-six thousand four hundred sixty-one, is already under active exploitation. Score it nine point eight. An unauthenticated attacker sends a crafted message with malicious S.Q.L., and the box hands them root on the underlying O.S., physical or virtual, no special config required. Patches land in fifteen point five point five dash zero one four one, sixteen point zero point four dash three oh two, and sixteen point five point zero dash seven eighty. CISA put it on the Known Exploited list with a federal deadline of September seventeenth. Hunt mail_logs for COPY TO PROGRAM style S.Q.L., and remember root can erase its own footprints, so check firewall and egress logs outside the appliance. Your email filter just became the shell. F5 Labs mapped a mass-scanning campaign against internet-exposed Vite development servers using C.V.E. twenty twenty-six dash thirty-nine thousand three hundred sixty-four, an eight point two bypass of server.fs.deny. Append query tricks like question-mark raw or import and raw, hit the slash at-fs endpoint, and files that should stay blocked, including .env and certs, come back as plain H.T.T.P. two hundred. Operators pull A.W.S. credentials, Azure profiles, terraform state, serverless configs, and even /proc/self/environ. They spoof Googlebot, ClaudeBot, and G.P.T.Bot user-agents and forge X-Forwarded-For headers to slip past I.P. allowlists. Default Vite binds to localhost. The moment someone passes --host, or botches a Docker publish, the laptop lab becomes a public secrets vending machine. Kill public --host, rotate anything that lived in .env, and treat exposed Vite like an open vault. Volexity ties U.T.A. zero five six zero to a September first spear-phish against N.G.O.s that abused reflected X.S.S. on a U.S. university site, then fired the BlueMoon chain: two Chrome bugs plus a Windows A.L.P.C. flaw to escape the browser and run code. The payload is GRIMWEDGE, an in-memory JavaScript backdoor for recon, file ops, and follow-on tooling. JungleBamboo, also known as A.P.T. thirty-one, used the same chain around the same window to drop LONGTALE, a Chrome credential stealer dressed as Gemini. The nasty part is the patch gap. Fixes hit Chromium source before they shipped in stable Chrome, so attackers got a free N-day that still behaved like a zero-day against real browsers. Patch Chrome and Windows hard, treat unexpected university-link clicks as incidents, and assume shared China-nexus exploit kits will keep recycling the same chain until the stable train catches up. cPanel warned that LiteSpeed Web Server Enterprise before six point three point seven can let a low-privilege hosting account reach root on a shared box and walk past CageFS isolation. One cheap account becomes a path into every neighbor site and the server config itself. LiteSpeed shipped six point three point seven on September eleventh

Kindle: https://www.amazon.com/dp/B0HHMH88H9 
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472

Barnes & Noble: https://www.barnesandnoble.com/w/books/1151622292?ean=2940185390764

https://mattch

Support the show