Cybersecurity Radar — 2026-09-20
The Brevo supply-chain attack has compromised approximately 100,000 websites, injecting malware via a compromised API key. Simultaneously, Microsoft released patches for 18 vulnerabilities in its AI and cloud products, while CISA announced it will retire its weekly vulnerability bulletin in favor of a risk-based approach.
Cybersecurity Radar — 2026-09-20
🔴 Critical Alerts

Brevo Supply-Chain Attack Injects Malware into 100,000 Websites Hackers utilized a compromised API key to deploy a Cloudflare worker that injected malicious scripts into roughly 100,000 websites using Brevo services. This widespread supply-chain attack represents a significant threat to web integrity and user security across numerous domains. Immediate review of Brevo API keys and website code is recommended for all affected entities.
Cisco ISE Zero-Day Exploited in Active Attacks Cisco has warned of a critical authentication bypass vulnerability in its Identity Services Engine (ISE), tracked as CVE-2026-76460 with a CVSS score of 10.0. This zero-day flaw is currently under active exploitation, potentially allowing attackers to execute root commands on affected systems. Organizations using Cisco ISE must apply available patches immediately to mitigate this severe risk.
Threat Landscape

Critical Check Point Management Server Flaw A critical vulnerability in Check Point Management Server allows unauthenticated attackers to run code as root. Check Point confirmed that R82.20, standalone deployments, Log Servers, and Multi-Domain servers are vulnerable. The vulnerable path runs only through the Trusted Client interface, but the impact remains high for exposed management servers.
Unpatched Magento and Adobe Commerce Zero-Day E-commerce storefronts are being compromised to inject backdoors by exploiting an unpatched Magento and Adobe Commerce zero-day dubbed "StyleSmuggler." This activity highlights the ongoing targeting of online retail platforms through known but unpatched vulnerabilities in popular commerce platforms.
Vulnerabilities & Patches
Microsoft Patches 18 Vulnerabilities in AI and Cloud Products Microsoft has fixed 18 vulnerabilities across Azure and AI-branded products. Privilege escalation flaws accounted for the majority of these fixes. Organizations utilizing Microsoft's cloud and AI infrastructure should prioritize these updates to secure their environments against potential privilege escalation attacks.
Linux Kernel Flaws Added to CISA KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog. These flaws, including CVE-2026-45321, require immediate patching for federal agencies and are highly recommended for all Linux users due to active exploitation.
Microsoft Excel Copy/Paste Issue Resolved Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. This fix addresses functional disruptions introduced by recent security patches, ensuring stability for Office users.
Breaches & Incidents
Thomson Reuters C-Track Platform Breach Thomson Reuters disclosed a breach of its C-Track court case-management platform. While specific details on the scale of data exposed were not fully detailed in the immediate summary, the compromise of a legal case-management system raises significant concerns regarding the confidentiality of legal proceedings and sensitive client data.
Industry & Policy
CISA Retires Weekly Vulnerability Bulletin CISA is discontinuing its weekly vulnerability bulletin on September 28. The agency is pivoting to instruct agencies to prioritize flaws based on real risk rather than volume. This change aims to help security teams focus on the most critical threats rather than managing a large volume of lower-priority alerts.
What to Watch
- Supply Chain Integrity: The Brevo incident underscores the growing risk of third-party service compromises. Monitor API usage and vendor security postures closely.
- Active Exploitation of Cisco ISE: With a CVSS 10.0 rating, watch for increased ransomware or data exfiltration attempts targeting unpatched Cisco ISE instances.
- CISA's Risk-Based Prioritization: Observe how federal agencies and private sector partners adapt to the new risk-based prioritization model following the retirement of the weekly bulletin.
Reader Action Items
- Audit Brevo Integrations: If you use Brevo, immediately rotate API keys and scan your website files for unauthorized Cloudflare workers or malicious script injections.
- Patch Cisco ISE Immediately: Apply Cisco's latest security updates for Identity Services Engine to address CVE-2026-76460. Assume compromise if unpatched.
- Review Microsoft Cloud/AI Updates: Deploy the latest patches for Azure and AI products to mitigate privilege escalation risks identified in the recent Microsoft security update.
This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.