Today’s lead:Active exploitation reaches root through Cisco email gatewaysGitLab patching does not close potential secret exposureFraudulent government requests bypassed Revolut’s disclosure controlsRubyGems confirms registry abuse but disputes AI attribution
Front page · Daily intelligence
Active exploitation reaches root through Cisco email gateways
Cisco says attackers are exploiting a crafted-email vulnerability that can execute commands as root on physical and virtual Secure Email Gateway appliances. There is no workaround, and patching cannot establish whether an appliance was already controlled.
By Security.io Intelligence Desk · Executive analysis
Assign email security, infrastructure and incident response as a single accountable workstream.
Why today: Cisco’s September 14, 2026 disclosure introduced confirmed active exploitation, a KEV listing and a no-workaround root-execution path inside an email-security control. That changed the decision from scheduled appliance maintenance to immediate patching plus compromise assessment. It ranked above…
“Inventory every physical, virtual and cloud-managed Cisco Secure Email Gateway.”
Decision owner: Email security service owner, supported by infrastructure operations and incident response
Decision horizon: Immediate: inventory, preserve evidence and begin upgrades within hours; complete compromise assessment before declaring closure.
Upgrade affected self-managed GitLab installations, preserve API and application logs, identify files and secrets that could have been read, and rotate affected trust material according to…
Today’s action: Identify every self-managed GitLab instance and its reachable interfaces.
Review every high-sensitivity government and law-enforcement request channel. Require out-of-band verification through independently maintained contacts, dual approval, immutable case records and field-level minimisation before data leaves…
Today’s action: Inventory government, law-enforcement and regulatory request channels.
Review Ruby dependencies introduced during the campaign, remove direct trust in newly published packages, validate RubyGems API tokens and constrain automated agents that can publish code…
Today’s action: Review Ruby dependencies introduced during the campaign period.
Hover or tap a point to see the story title, new references, cumulative evidence, source mix and why the story entered today’s edition. Keyboard: use ← or →.
This line shows cumulative cited references across the lead and four supporting briefs.