F5 Bot Defense uses real-time risk scoring to detect fraud and abuse
2026-09-15T14:51:42Z•f6c8952c6ed36f6199d5a0a0ff7dcbfe97c1f391ff09b20ab51a5fef35f6a23a
CVE-2026-76461AI securityAPI securityCisco Secure Email GatewayClickFixMITRE ATT&CKSQL injectionaccount takeoveractive exploitationbot defensecredential theftdetection engineeringemail securityfraudidentity securityinfostealermalvertisingthreat intelligencezero-day
What happened
Help Net Security’s September 15, 2026 feed covers AI and API security products, identity and infostealer risks, detection engineering, abuse of AI services, and multiple active threats. The most significant incident is active exploitation of CVE-2026-76461, a SQL injection zero-day affecting Cisco Secure Email Gateway appliances. Attackers also hijacked HBO Max’s Reddit account to distribute ClickFix malvertising leading to information-stealing malware. Other items describe defensive capabilities for bot fraud, API credential governance, enterprise AI protection, and MITRE-aligned detection;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- f6c8952c6ed36f6199d5a0a0ff7dcbfe97c1f391ff09b20ab51a5fef35f6a23a
- Enrichment time
- 2026-09-15T14:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.