Cisco warns of max severity ISE zero-day exploited in attacks

2026-09-17T07:23:24Z•8873cf5b2ee2597336183836fb2a1cbb49712172f42b302520f5db2263e8a029
AcronisAndroidCHOSEN BRICKCisco ISEConnectWise ScreenConnectIran-linked threat actorsKREMLIN malwarePleskWordPress supply-chain compromiseactive exploitationcPanelcredential theftdata breachenterprise securitymalicious browser extensionsransomwaresession-token theftzero-day

What happened

A BleepingComputer security-news feed highlights multiple active or emerging threats, including a maximum-severity Cisco Identity Services Engine zero-day exploited in the wild, active exploitation of a critical ConnectWise ScreenConnect flaw, actively exploited Android and Acronis backup-plugin vulnerabilities, state-linked CHOSEN BRICK malware campaigns, KREMLIN malicious browser-extension deployment, and a compromised WordPress plugin affecting approximately 1,500 sites. The feed also covers data breaches, enterprise update issues, and ransomware impact.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
8873cf5b2ee2597336183836fb2a1cbb49712172f42b302520f5db2263e8a029
Enrichment time
2026-09-17T07:23:24Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.