Skip to content
TacitSoft Cyber Daily for 2026-09-16
TacitSoft Cyber Daily

Active exploits, agentic browser risk, and cyber decoys

Defenders face urgent Issabel and KEV remediation, new browser-agent attack paths, and practical detection guidance from CISA.

Source-linked signals
12
Edition date
Sep 16, 2026
Coverage window
Complete UTC day

Ranked operator signal

Signals in this edition

Each item links to its publisher and includes one independently written TacitSoft sentence based on structured facts.

Rank 01
CISA Cybersecurity Advisories Vulnerability Intel

CISA Adds Two Known Exploited Vulnerabilities to Catalog

TacitSoft analysis

Cisco ISE and Acronis Backup operators should prioritize CVE-2026-76460 and CVE-2026-87886 following their addition to CISA's KEV catalog.

Identifiers
CVE-2026-76460, CVE-2026-87886
Read source
Rank 02
CISA Cybersecurity Advisories Vulnerability Intel

CISA Adds One Known Exploited Vulnerability to Catalog

TacitSoft analysis

Mobile security teams should prioritize CVE-2026-58704 on affected Google Pixel devices following its addition to CISA's KEV catalog.

Identifiers
CVE-2026-58704
Read source
Rank 03
BleepingComputer Breaking Security

Spain's data agency gets first report of AI-powered data breach

TacitSoft analysis

Incident responders should preserve tool-call and identity telemetry when AI agents are suspected in a breach, while treating attribution as unverified until proven.

Read source
Rank 04
The Hacker News Security News

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

TacitSoft analysis

Issabel operators should urgently remediate CVE-2026-89026 and investigate exposed PBX systems for compromise.

Identifiers
CVE-2026-89026
Read source
Rank 05
Openwall oss-security Open Source Disclosure

CVE-2026-89775: Guest-to-Host Escape in KVM/arm64

TacitSoft analysis

KVM/arm64 operators using nested virtualization should prioritize assessment and remediation of CVE-2026-89775.

Identifiers
CVE-2026-89775
Read source
Rank 06
BleepingComputer Breaking Security

Malware bypasses browser checks to force install Chrome, Edge extensions

TacitSoft analysis

Identity teams should investigate forced Chrome and Edge extension installs and rotate exposed credentials or session tokens.

Read source
Rank 07
CISA Cybersecurity Advisories Vulnerability Intel

Using Cyber Decoys to Strengthen Detection and Response

TacitSoft analysis

Defensive teams should evaluate cyber decoys as a complement to zero trust for detecting credential misuse and living-off-the-land movement.

Read source
Rank 08
Openwall oss-security Open Source Disclosure

CVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability

TacitSoft analysis

Apache MyFaces operators should assess CVE-2026-68536 for server-side request forgery and local file inclusion exposure.

Identifiers
CVE-2026-68536
Read source
Rank 09
Openwall oss-security Open Source Disclosure

CVE-2026-91752: GNU libextractor < 1.15 Stack Overflow via OLE2

TacitSoft analysis

Operators processing untrusted documents should identify GNU libextractor versions before 1.15 and prioritize CVE-2026-91752 remediation.

Identifiers
CVE-2026-91752
Read source
Rank 10
Dark Reading Enterprise Security

BragJack Attack Can Turn a Browser's Agentic AI Against It

TacitSoft analysis

Organizations deploying agentic browsers should constrain assistant permissions and monitor AI-triggered access, actions, and data movement.

Read source
Rank 11
Dark Reading Enterprise Security

AI Security Spending Jumps as Fear Outpaces Proof of Value

TacitSoft analysis

Security leaders should bind AI security spending to measurable outcomes, risk reduction, and explicit operating controls.

Read source
Rank 12
Cloudflare Blog Vendor Security Primary

When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts

TacitSoft analysis

Online retailers should add browser-side runtime detection for malicious JavaScript that conventional scanners may miss.

Read source

Get the briefing on your schedule

Choose daily, weekly, monthly, or any combination.

Choose your briefing cadence