21st September – Threat Intelligence Report
Reported exploitedJapan Digital Agency Government Solution ServiceWaterPlumBrevoOur summary
Check Point's weekly report says Cisco is aware of active exploitation of CVE-2026-76460 in Cisco Identity Services Engine, which can give unauthenticated remote attackers access to the management interface; Cisco also fixed CVE-2026-76461 in Secure Email Gateway. Check Point patched CVE-2026-91843 in Security Management and Log Servers, Oracle addressed more than 800 flaws including in Oracle E-Business Suite, and ISC updated BIND 9 for 14 issues, including CVE-2026-77692; the roundup also covers breaches affecting Japan Digital Agency Government Solution Service, Brevo, and Gyazo, plus the WaterPlum campaign.
Below is the opening; the full story is at Check Point Research.
From Check Point Research
For the latest discoveries in cyber research for the week of 21st Setpember, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
- Japan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, including names and contact details belonging to government officials and contractors, while financial information was not affected.
- Two oil tankers bound for Texas were hit by cyberattacks that disrupted onboard systems during voyages to the United States. US Coast Guard and FBI personnel boarded the vessels, while officials confirmed malicious cyber activity on the VL Prosperity but have not publicly attributed the attacks to a specific actor.
- Brevo, a French customer communication and marketing platform, has confirmed a supply chain attack after attackers used a compromised Cloudflare API key to inject malicious ClickFix scripts into websites that use Brevo components. The attack affected about 100,000 websites.
- Japanese software company Helpfeel, operator of image-sharing service Gyazo, has reported a data breach after attackers exploited a vulnerability in an image upload server. Above 23 million user records and 490 million image metadata records were exposed, including email addresses, password hashes, session IDs, integration tokens, and location metadata.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.