Security.io Daily Headlines — Tuesday, September 15, 2026
Five equally weighted developments: what happened and the leadership decision each creates.
Episode transcript
565 words · Sponsor after story threeThis is Max Vogal from Security.io with today’s Daily Headlines for Tuesday, September 15, 2026. Here are the top five security developments shaping today’s decisions—what happened, why each matters now, and the leadership action to consider.
Active exploitation reaches root through Cisco email gateways
What happened
Assign email security, infrastructure and incident response as a single accountable workstream. Cisco says attackers are exploiting a crafted-email vulnerability that can execute commands as root on physical and virtual Secure Email Gateway appliances. There is no workaround, and patching cannot establish whether an appliance was already controlled.
The leadership decision
Security leaders should inventory every physical, virtual and cloud-managed Cisco Secure Email Gateway. Make one leader accountable for service continuity, emergency change, forensic preservation and compromise assessment. Splitting patching and investigation between uncoordinated teams risks rebooting or rebuilding appliances before volatile evidence and configuration state are captured.
GitLab patching does not close potential secret exposure
What happened
Upgrade affected self-managed GitLab installations, preserve API and application logs, identify files and secrets that could have been read, and rotate affected trust material according to documented procedures. GitLab’s maximum-severity file-read flaw is in CISA’s exploited catalogue.
The leadership decision
Security leaders should identify every self-managed GitLab instance and its reachable interfaces. Separate three decisions: whether the instance was vulnerable, whether it was reachable during the exposure period, and whether evidence indicates files were read. Only the first question is answered by version inventory.
Fraudulent government requests bypassed Revolut’s disclosure controls
What happened
Review every high-sensitivity government and law-enforcement request channel. Require out-of-band verification through independently maintained contacts, dual approval, immutable case records and field-level minimisation before data leaves the organisation. Revolut confirmed that sensitive customer information was released after fraudulent requests arrived through a legitimate government-agency email domain.
The leadership decision
Security leaders should inventory government, law-enforcement and regulatory request channels. Assign a single accountable owner across legal, privacy and security for authenticating external authority requests. The control must verify both the requesting organisation and the individual request through a channel not supplied in the incoming message.
RubyGems confirms registry abuse but disputes AI attribution
What happened
Review Ruby dependencies introduced during the campaign, remove direct trust in newly published packages, validate RubyGems API tokens and constrain automated agents that can publish code or trigger external build services. Keep confirmed registry abuse separate from unresolved AI attribution.
The leadership decision
Security leaders should review Ruby dependencies introduced during the campaign period. Treat registry provenance as a time-dependent trust decision. Newly created maintainer accounts, rapid package publication, automated documentation builds and packages with unnecessary network behaviour deserve stronger review than established, reproducible dependencies.
Sogou exploitation delivered GRAYRABBIT through a trusted input tool
What happened
Inventory Sogou Input Method across Windows estates, verify version 16.3.0.3498 or later, hunt the published GRAYRABBIT artefacts and isolate matches. Gen Digital says UNC3569 exploited a one-click flaw in Tencent’s Sogou Input Method to deploy GRAYRABBIT.
The leadership decision
Security leaders should inventory Sogou Input Method across managed and unmanaged Windows estates. Make regional IT and endpoint-security teams jointly accountable for finding the software. Central software inventories may omit language tools installed by users, included in regional images or present on contractor devices.
That’s Security.io Daily Headlines for Tuesday, September 15, 2026. Full reporting, sources, executive actions and today’s comic are available in the complete edition at Security.io. I’m Max Vogal. Thanks for listening.