Active exploitation reaches root through Cisco email gatewaysGitLab patching does not close potential secret exposureFraudulent government requests bypassed Revolut’s disclosure controlsRubyGems confirms registry abuse but disputes AI attribution
Active exploitation reaches root through Cisco email gateways
Cisco says attackers are exploiting a crafted-email vulnerability that can execute commands as root on physical and virtual Secure Email Gateway appliances. There is no workaround, and patching cannot establish whether an appliance was already controlled.
Security.io Intelligence Desk · Tuesday, 15 September 2026
Executive consequence
Assign email security, infrastructure and incident response as a single accountable workstream.
Decision today
Inventory every physical, virtual and cloud-managed Cisco Secure Email Gateway.
Read the full decision briefPrimary reporting: Cisco PSIRT · Canadian Centre for Cyber Security · CISA KEV Catalog
Decision intelligence, not a headline feed.Every edition ranks what security leaders should read first, assign today and monitor next.
Six-minute executive briefing
Security.io Daily Headlines
Five equally weighted stories: what happened and the leadership decision each creates.
Upgrade affected self-managed GitLab installations, preserve API and application logs, identify files and secrets that could have been read, and rotate affected trust material according to documented procedures.
Do today
Identify every self-managed GitLab instance and its reachable interfaces.
Review every high-sensitivity government and law-enforcement request channel. Require out-of-band verification through independently maintained contacts, dual approval, immutable case records and field-level minimisation before data leaves the organisation.
Do today
Inventory government, law-enforcement and regulatory request channels.
Review Ruby dependencies introduced during the campaign, remove direct trust in newly published packages, validate RubyGems API tokens and constrain automated agents that can publish code or trigger external build services. Keep confirmed registry abuse separate from unresolved AI attribution.
Do today
Review Ruby dependencies introduced during the campaign period.