Secret CISO 9/16: 7.49M Utility Records, vCenter RCE, WSO2 Token Forgery, Acronis LPE
A bad day for “it’s patched, we’re fine” thinking: a utility confirms a 7.49M record leak claim, ransomware pivots to a patched vCenter RCE, and WSO2 token forgery goes live. Also: Acronis plugin LPE already seeing exploitation.
Today’s theme is the attacker’s favorite word: “later.” Patch later, investigate later, rotate creds later. Then you wake up to a leak post, a KEV add, and a vendor saying “limited targeted exploitation” (which always means “not limited for long”).
Today's Top 5
- 7.49M utility customer records: CenterPoint Energy acknowledged an online post claiming a stolen customer dataset, and now the clock starts on what was actually in it. The filing is careful, the threat actor will not be.
- Ransomware piles onto vCenter: CISA says ransomware gangs have joined exploitation of a critical VMware vCenter flaw that was patched in July. The fun part is figuring out which “patched” systems were never really patched.
- WSO2 admin tokens forged: Active exploitation is targeting WSO2 API Manager via a JWT signature verification weakness that can yield full account takeover. If your API gateway is your front door, this is the spare key under the mat.
- Acronis plugin LPE exploited: Acronis identified a local privilege escalation bug in its cPanel backup plugin and says it is already being exploited. This is the kind of foothold attackers love after they land any low-priv shell.
- Springfield schools hit, data breached: The FBI told Springfield Public Schools that the incident included a data breach, with SSNs for staff possible but not confirmed. K-12 continues to be the softest target with the loudest blast radius.
Why today matters: We are watching the same playbook run in three lanes at once: public leak posts forcing disclosure, “patched” infrastructure becoming ransomware fuel, and identity systems failing open. If you run exposed management planes, API gateways, or vendor hosted healthcare workflows, you should be nervous this week.
Alright, let’s get specific.
Data Breaches

- CenterPoint Energy discloses customer data breach investigation: In a Form 8-K, CenterPoint said it became aware of an online post claiming a dataset containing certain customer information. The company is investigating scope and impact, and noted it does not currently expect a material financial impact. Source: CenterPoint Energy (8-K)
- LHC Group vendor vishing incident exposes patient data: LHC Group said a voice phishing incident led to unauthorized access to files in a vendor platform, with breach notifications indicating 28,000+ affected so far. Data types can include SSNs, IDs, and medical and insurance information. Source: HIPAA Journal
- Springfield Public Schools cyberattack confirmed as data breach: Local reporting says the FBI informed the district that data was breached during the incident that disrupted operations. The district warned that staff SSNs may be involved, though not confirmed. Source: Western Mass News
- Interlock ransomware claims City of Fort Smith, Arkansas: Leak site monitoring reports Interlock listed the city and claimed a large data leak tied to municipal systems. Treat the leak size and details as unverified until corroborated, but assume data theft risk is real. Source: Kalir (Pulse)
Security Research

- CISA warns ransomware gangs are exploiting VMware vCenter RCE: CISA says ransomware groups have joined exploitation of a vCenter Syslog Server directory traversal bug that can lead to unauthenticated code execution. Broadcom patched it in July, but attackers are clearly finding laggards. Source: BleepingComputer
- Active exploitation targets WSO2 API Manager JWT bypass: Researchers report in-the-wild exploitation of a JWT signature verification issue that enables forging admin tokens and full account takeover. If WSO2 is internet exposed, assume you are already being scanned. Source: The Hacker News
- Acronis cPanel backup plugin flaw now has a CVE and exploitation note: Acronis updated its advisory with CVE-2026-87886 and said it has detected exploitation in limited, targeted attacks. It is a local privilege escalation issue, so it pairs nicely with any initial access path. Source: BleepingComputer
- Pixel Update Bulletin ships September fixes: Google’s Pixel bulletin confirms patch levels (2026-09-05 and later) address issues in the Pixel and Android September bulletins. If you rely on Android compliance reporting, this is your authoritative reference for patch level mapping. Source: Android Open Source Project
- North Korea linked Linux espionage toolkit targets South Korean media and automotive: Reporting highlights a Linux toolkit used against load balancers and production infrastructure, with long dwell times and credential harvesting patterns. It is a reminder that your “boring” edge appliances are now prime espionage terrain. Source: Dark Reading
Top CVEs

- CVE-2026-59310: Critical directory traversal in VMware vCenter Syslog Server that can enable unauthenticated remote code execution. CISA warns ransomware gangs are now exploiting it, so treat exposed vCenter as an emergency patch and isolation item. Source
- CVE-2026-5430: WSO2 API Manager improper verification of JWT signature that enables forged admin tokens and account takeover. Active exploitation has been observed, which makes any internet exposed API gateway instance a high priority. Source
- CVE-2026-87886: Acronis Backup plugin for cPanel and related extensions have a local privilege escalation flaw that Acronis says is being exploited in limited targeted attacks. This is a post-compromise accelerant, not a standalone initial access bug. Source
- CVE-2026-85880: Windows ALPC elevation of privilege that Microsoft lists as exploited in the wild. Expect it to show up chained with phishing and browser exploitation to turn a foothold into SYSTEM fast. Source
- CVE-2026-81963: Windows Update Stack elevation of privilege that Microsoft lists as exploited in the wild. The uncomfortable detail is that the updater itself becomes the privilege escalation rung, which makes patch hygiene and endpoint controls inseparable. Source
Podcasts & Talks

- Risky Business #853, “We’re all gonna die, apparently” (Sep 16, 2026): This week’s episode is a good briefing for leadership because it tracks the gap between public alarm and real operational risk. Use it to calibrate comms without downplaying urgent patch work. Listen: Risky Business Media
Final Words
The pattern underneath today’s headlines is speed plus leverage. Leak posts force a disclosure cadence you do not control, and “patched” infrastructure becomes ransomware ammunition when asset inventory and change control are wishful thinking. The uncomfortable implication: your exposure is increasingly determined by how fast you can prove a negative, not by how good your policy deck looks.
This week, do three things:
- Patch and verify VMware vCenter for CVE-2026-59310, then block or restrict Syslog Server exposure and confirm version and patch state with an authenticated scan, not a spreadsheet.
- Hunt for WSO2 API Manager indicators of compromise and rotate signing keys and admin credentials after patching CVE-2026-5430, especially if the gateway is internet reachable.
- Inventory every host running the Acronis cPanel or Plesk backup plugin and update to fixed builds for CVE-2026-87886, then review for unexpected local user creation and privilege changes.
Your turn: If a leak post claiming millions of your customer records appeared tonight, do you have a pre-approved, one-page decision tree for “verify, disclose, notify, rotate, and monitor,” or are you writing it under pressure? Hit reply with your honest answer, or drop a comment on the web version. I read every reply.
Know someone who still treats vCenter like an internal-only snowflake that never needs emergency patching? Forward them this issue, it costs 30 seconds and the alternative costs a quarter. For forwarded and web readers, subscribe free at secretciso.org.
Stay vigilant, stay informed, and see you in the next edition of Secret CISO!