Week in review: Cisco patches exploited email gateway 0-day, Revolut breach
2026-09-20T08:51:41Z•d8d98959bb9a6a7d515eee54d9828ab3a5aef33f0203e8d7a54e4fe7e73496b4
AI-coding-agentsAI-securityAndroidCiscoIoT-securityMCPRevolutWordPresscredential-exposuredata-breachemail-securityexploitation-in-the-wildidentity-fraudsocial-engineeringsupply-chain-securityvulnerabilityzero-click-RCEzero-day
What happened
Help Net Security’s weekly roundup covers a Cisco email gateway zero-day reportedly exploited in the wild, a Revolut data breach involving impersonation of a government agency, and emerging risks affecting AI coding agents, MCP configurations, abandoned IoT applications, fraudulent hires, and WordPress operations. The most severe item is a reported zero-click remote code execution vulnerability affecting major AI coding agents through marketplace plugins, with two products reportedly still unpatched. Publicly exposed hardcoded MCP credentials and vulnerable abandoned IoT dependencies also pose
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- d8d98959bb9a6a7d515eee54d9828ab3a5aef33f0203e8d7a54e4fe7e73496b4
- Enrichment time
- 2026-09-20T08:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.