Security Digest

[Cybersecurity Digest] Cisco's login skip got a perfect 10

Sent · Cybersecurity & Privacy Digest

Cisco just shipped a fix for a vulnerability that let anyone, no password, no token, no login at all, walk straight past its network gatekeeper and grab root. It was already being used in the wild before the patch existed. That is the week we are in.


The Big 3

Cisco's Network Gatekeeper Had a Perfect 10 Hole in It

Cisco Identity Services Engine decides who gets onto a network. On 16 September, Cisco disclosed CVE-2026-76460, a maximum severity (CVSS 10.0) authentication bypass in an ISE API endpoint. No credentials needed, and successful exploitation hands an attacker root. Cisco confirmed active exploitation before the patch landed, and CISA gave federal agencies until 19 September to fix it, with no workaround available.

Why it matters: a lot of zero trust architecture leans on ISE to decide who is trustworthy, so a hole that skips authentication entirely undermines the whole premise it is built to protect.

Read more: Cisco's ISE hardening advisory

The Tool Your IT Provider Uses to Fix Your PC Just Got a 10.0

N-able rushed out hotfixes for three N-central flaws this week: two authentication bypasses (CVE-2026-86206, CVE-2026-86207) and a pre-authentication remote code execution bug, CVE-2026-86218, also scoring a perfect 10.0. N-central is remote monitoring and management software that IT providers use to run hundreds of client networks from one console, and an older N-central bug is already on CISA's exploited list from earlier this year.

Why it matters: one compromised login here does not just hand over one business, it can hand over every client that business's IT provider manages.

Read more: N-central exploitation history at The Hacker News

One Reused Police Password Opened Florida's Entire Driver Database

ShinyHunters says it broke into Florida's DAVID driver database using a password-reset weakness and credentials belonging to a Plant City Police Department employee, stored on a personal device. FLHSMV says it contained the breach on 4 September, days after it began, but the group claims around 200,000 driver records were taken and added the agency to its extortion leak site on 7 September.

Why it matters: no zero-day, no supply chain attack, just one login saved somewhere it should not have been. That is still the most common way sensitive government systems get breached.

Read more: BleepingComputer's coverage of the DAVID breach


Quick Hits

Three ransomware crews, one Cisco flaw: Cisco confirmed three separate threat clusters, including state-linked actors, have been exploiting patched Secure Firewall Management Center bugs to deploy Qilin ransomware.

BIND's DNS software gets a 14-flaw patch: the Internet Systems Consortium released BIND 9.20.29 and 9.21.26 fixing fourteen security flaws disclosed on 16 September, worth checking if you run your own DNS infrastructure.

Delaware widens its privacy law: Governor Matt Meyer signed House Bill 380 on 2 September, expanding the Delaware Personal Data Privacy Act ahead of it taking effect 1 January 2027 (00:00 US Eastern).

A new China-linked backdoor is doing the rounds: researchers spotted FamousSparrow using a previously undocumented backdoor called SparroWocky against government targets in Latin America.


Tool of the Week

YubiKey 5C NFC is a physical security key that replaces passwords and SMS codes with a tap, so there is nothing sitting on a personal device for someone else to misuse. Good for anyone who read the Florida DMV story above and wants their own logins to depend on something better than a password that can be reset by anyone who guesses the right answers.

Who it is for: anyone with a Google, Microsoft, or work account that supports hardware security keys, especially if you handle sensitive systems for your job.


Protect Yourself

If you are a Florida driver, do not wait for FLHSMV to confirm whether your specific record was included in the DAVID breach. Put a free credit freeze on with all three major bureaus (Equifax, Experian, TransUnion) this week, and treat any unexpected call or email referencing your driving or vehicle history as a probable scam rather than a coincidence.


Forwarded this? Get your own cybersecurity briefing at futuretechnologyhq.com/newsletter

Stay safe out there. Nath, Future Technology

Some links in this newsletter may be affiliate links. We only recommend products we genuinely think are worth your time.

← Back to the archive

Get the briefing

The biggest tech story, explained in 3 minutes. Delivered free every weekday.

Trusted by thousands of readers