Cisco has taken swift action to address a critical vulnerability in its Identity Services Engine (ISE), releasing a patch to mitigate a flaw that is being actively exploited. The vulnerability, as reported by The Register, stems from insufficient authentication control on an API endpoint. This flaw could be leveraged by an attacker to send a crafted request, potentially gaining unauthorized access by bypassing the web-based management interface of the affected device. To assist customers in identifying potential exploitation, Cisco has shared indicators of compromise. However, they caution that attackers with root access could erase traces of their activity. Thus, Cisco strongly recommends that administrators diligently review network and firewall logs outside the impacted device to spot suspicious activities, such as unexpected data uploads to or downloads from malicious external IP addresses.

In other cybersecurity news, Japanese software company Helpfeel has reported a breach impacting its image-sharing service, Gyazo. The breach, detailed by SecurityWeek, involved an attack on the image upload server on September 11th, granting unauthorized access to a database with 23.6 million user records. Exposed information includes names, email addresses, and other sensitive data. Furthermore, about 490 million metadata records related to images registered before January 2019 were disclosed without authorization, potentially allowing unauthorized access to image URLs.

Additionally, ESET has identified a new cyberespionage campaign by the China-linked group FamousSparrow. The group is deploying a backdoor named 'SparroWocky' across several Latin American countries, including Argentina and Ecuador, among others. This campaign appears to be a strategic response to the United States's increasing interest in the region, with implications for China's investments in Central and South America.