The Daily Zero-Day

Date: SEPTEMBER 19, 2026 Editor-in-Chief: Jose Laurentino III Global Threat Intelligence Edition

Executive Summary

Today's intelligence landscape highlights a massive wave of security patching, led by Microsoft addressing nearly 1,000 security flaws and critical zero-day threats emerging in enterprise infrastructure like Cisco ISE and Orkes Conductor. Meanwhile, artificial intelligence features heavily across the threat landscape—from state-backed groups and advanced malware navigating Android devices to corporate data leakage risks and novel phishing vectors.

Top Intelligence Briefings

Cisco Zero-Day Highlighted by Authentication Bypass

A critical authentication bypass flaw (CVE-2026-76460) impacting Cisco's Identity Services Engine (ISE) has received a maximum 10 out of 10 CVSS score, underscoring severe API endpoint authentication risks.

Actionable Takeaway: Immediately apply vendor patches and review exposure of all Cisco ISE API endpoints to internal and external networks.

Critical Pre-Auth RCE in Orkes Conductor Exploited

Fortinet reports that a critical pre-authentication Remote Code Execution (RCE) vulnerability impacting Orkes Conductor is actively being exploited in the wild by threat actors.

Actionable Takeaway: Audit Orkes Conductor deployments immediately and ensure updates are deployed to prevent unauthorized pre-auth system access.

New Android Malware 'RatHat' Uses AI for Theft

Researchers have uncovered a sophisticated new Android malware strain dubbed RatHat that leverages AI capabilities to autonomously navigate infected mobile devices while harvesting bank logins, 2FA codes, and screen-lock PINs.

Actionable Takeaway: Restrict side-loaded applications and enforce strict Mobile Device Management (MDM) policies to detect unauthorized UI automation anomalies.

FamousSparrow APT Deploys 'SparroWocky' Backdoor

ESET researchers have documented SparroWocky, a powerful new flagship backdoor utilized by the FamousSparrow APT group in targeted cyberespionage operations.

Actionable Takeaway: Monitor network telemetry for anomalous command patterns and review ESET's IOC indicators to defend against FamousSparrow infrastructure.
Previous editions:
Fort Lauderdale, FL, September 28, 2026
Visitors since September 18th, 2026: 34,865