Hello! This is Shemihaza, your Sentinel. This recap covers 14 to 19 September 2026.
Six online safety articles this week. Placed side by side, they share one thing: the entry point. A DM from a friend, an incoming phone call, a social ad, an email, a prompt to install an app. The scams are all different, but the first step is always an entry point someone else prepared for you.
The heaviest piece came last, on 19 September. You cannot tell those entry points apart by looking at them. Phishing mail has been reported with a real service domain in the From field.
So this week's thread is not "learn to spot the fake". It is: do not let the other party pick your next action.
That took three different shapes across the six articles: verify through a route that starts with you (the DM, the call, the email, the app install), do not move at their pace — read the screen yourself before a contract forms (the trial purchase), and keep a record of how you got in (the course solicitation).
Online safety this week: six entry points and what to do next
Sep 14 - The "please vote for my nephew" DM and how LINE accounts get taken over
Based on the 2026 Q2 (April to June) consultation figures from IPA's Information Security Support Desk and on LINEYahoo's official warning, updated 20 May 2026. Unauthorised-login consultations came to 423 cases.
A DM says a relative's child is entered in a contest, sends you to a fake login page, and asks you to forward the verification code. What the attacker is after is not your money. Once your account is taken, requests for money go out to your friends and family under your name. "I have nothing worth stealing" does not protect you here.
The replacement route: do not open the link — open the LINE app yourself. And never send a verification code to anyone.
Sep 15 - Callers claiming to be police: four things a real officer never does
Based on the National Police Agency's anti-fraud site SOS47 and its special-fraud statistics. Fake-police fraud accounted for 11,014 recognised cases and 100.50 billion yen in losses in Reiwa 7 alone — 70.6% of all special-fraud losses, with victims most commonly in their thirties.
The NPA states plainly that a real officer will not tell you over the phone that you are under investigation, will not contact you through a messaging app, will not send images of a police ID or an arrest warrant, and will not suddenly video-call your personal phone.
The replacement route: do not call back the number that called you. A number the other party chose cannot verify the other party. If you want to check, call #9110 — Japan's police advice line — or a station number you looked up yourself.
Sep 16 - Trial purchases that turn into subscriptions
Based on "Consumer consultations from people aged 65 and over, FY2025", published by Japan's National Consumer Affairs Center on 16 September 2026. Broken down by sales method, subscription-related consultations were 46,958 from people aged 65 and over and 47,387 from those under 65 — almost identical.
The figures appear in a document about older consumers, yet by count the under-65 group is slightly higher. But these are consultation counts, not a rate of who gets caught. Population sizes and willingness to seek advice differ by generation, so the data does not support that reading.
The entry point is an ad promising a first-time-only trial. Here the move is not to swap routes: read the final confirmation screen yourself before you press the order button. Whether it is a recurring contract is stated there.
Sep 17 - AI courses and side-hustle schools sold through web meetings
Based on "Beware of business-course trouble", published by the same centre on 16 September 2026. Consultations rose from 1,169 in FY2020 to 3,551 in FY2025, and FY2026 already had 1,121 in its first four months to 31 July, against 821 in the same period a year earlier.
The point of that article was not the count. It was that how you entered changes what you can do afterwards. For the same course, applying yourself from a social ad and being solicited during a web meeting can fall under different legal treatment. The centre's chart puts the FY2026 average contract value at 480,000 yen for mail-order sales against 790,000 yen for "telephone solicitation sales (including solicitation via web meetings)". The 790,000 is not a web-meeting-only average — the published category covers telephone solicitation sales as a whole, web meetings included.
Again this is not about swapping routes: do not sign during the meeting, and keep a record of how you applied. That record is what matters when you seek advice later.
Sep 18 - Payment apps topped up and drained by remote control
Based on the damage published by the National Police Agency in its Cyber Police Bureau bulletin on 18 September 2026: after a malicious app is installed, a cashless payment service is operated remotely, topped up and used to send money out.
Most of the scams covered here work by deceiving you into transferring money yourself. This one does not. The NPA describes the payment service being operated remotely, so the balance moves without your hands on it.
The agency lists three entry points, and every one of them begins with installing an app. The replacement route is simple: never install an app from anywhere but the official app store. The moment installation means following a link, stop.
Sep 19 - Phishing reports up 24.5% in August, and the sender field proves nothing
Based on the August report published by the Council of Anti-Phishing Japan on 18 September 2026. Reports reached 82,338, up 16,219 on the previous month, or about 24.5%. The top five impersonated brands alone accounted for roughly 70% of the total.
This article closes the week because it shows the entry point cannot be judged by appearance. Messages have been reported using a real service's domain name in the From field, so the displayed sender is not evidence of anything.
The replacement route: open the official app or your own bookmark instead of the link in the message. Check orders, points and payments through a route that starts with you, and you no longer have to guess whether the mail was genuine.
For engineers: this week's security alerts
Five items. Four of them are already in CISA's Known Exploited Vulnerabilities catalogue, meaning exploitation has been confirmed in the wild.
The thread this week: the published number and the state of your own environment do not line up. A CVSS value means different things depending on who assigned it, and "I updated" does not reliably mean "I am covered".
GitLab CVE-2026-85706 (CVSS v3.1 10.0 CRITICAL) - exploited
On self-managed GitLab, an unauthenticated attacker can read arbitrary files on the server. Fixed in 19.1.8 / 19.2.6 / 19.3.2. CISA added it to KEV on 11 September 2026 with a due date of 14 September.
The 10.0 was assigned by GitLab itself as the CNA, under CVSS v3.1. When we checked, NVD's NIST analysis was still "Undergoing Analysis". A score shown on an NVD page is not necessarily NIST's.
Cisco Secure Email Gateway CVE-2026-76461 (CVSS v3.1 9.8 CRITICAL) - exploited
A crafted email arriving is enough to execute commands as root without authentication. The recipient does not even have to open it. The weakness class is CWE-89 (SQL injection). Fixed in 16.5.0-780, and there is no workaround.
Cisco's own advisory states that in September 2026 its PSIRT became aware of active exploitation. CISA added it to KEV on 14 September, due 17 September. The 9.8 is Cisco's value as the CNA.
JetFormBuilder CVE-2026-12793 (CVSS v3.1 9.8 CRITICAL)
A WordPress form plugin (about 80,000 active installations per WordPress.org) where an unauthenticated attacker can create an administrator account. The 9.8 comes from Wordfence as the CNA; when we checked, NVD's status was "Received" with no independent NIST analysis.
The important part was that fixing one CVE was not enough. This CVE itself was patched in 3.6.2.1, but five further vulnerabilities were published in September, and closing all six requires 3.6.5.2 or later. This one is not in KEV.
Google Pixel CVE-2026-58704 (CVSS v3.1 8.8 HIGH) - exploited
A cellular-modem privilege bypass fixed in the Pixel Update Bulletin published 15 September 2026, which states that CVE-2026-58704 "may be under limited, targeted exploitation". CISA added it to KEV on 16 September, due 19 September. The fix is to get the device's security patch level to 2026-09-05 or later.
That 8.8 was assigned by CISA-ADP. Google (Google_Devices), the CNA, attached no CVSS to this record, and no independent NIST score is present — so CISA-ADP's is the only CVSS this CVE carries.
Linux kernel CVE-2025-39964 / CVE-2026-53266 - exploited, due 21 September
CISA added two Linux kernel flaws to KEV on 18 September 2026, both due 21 September: a race condition in AF_ALG sockets and an out-of-bounds write in the ebtables SNAT target. Both were fixed long ago. The news is not a new hole — it is that a hole that was already patched is confirmed to be under attack.
The scoring is split. For CVE-2025-39964, NIST completed its analysis on 19 September 2026 and NVD now shows 5.5 MEDIUM, while the kernel CNA still rates it 7.8 HIGH.
That number moved after our 18 September article. NIST analysis can land later, so always state whose score it is and when you read it.
And "I ran apt upgrade and rebooted" does not settle it. When we checked on 18 September, Ubuntu's security tracker listed CVE-2026-53266 against the main `linux` package as "Vulnerable, work in progress" for 24.04 LTS and 22.04 LTS, and "Vulnerable" for 20.04 LTS. If the fixed package has not shipped, updating changes nothing — and on top of that, a kernel keeps running the old image until you reboot.
This week's quiz - four questions
If you read this week's articles, you can spot all four. Try the first two with your family and the last two with your colleagues.
📦Every article from this week
- Phishing Reports Jumped 24.5% in August — the Sender Field Proves Nothing↗
- Money Leaving Your Payment App on Its Own: Japan's Police Name Three Entry Points↗
- Linux Kernel CVE-2025-39964 and CVE-2026-53266: Patch, Then Reboot — Both Now Confirmed Exploited↗
- Signed Up for an AI or Side-Hustle Course? How You Enrolled Decides What You Can Cancel↗
- Google Pixel CVE-2026-58704: Get to Patch Level 2026-09-05 — Modem Flaw Used in Targeted Attacks↗
- The "Trial" That Was a Subscription: 46,958 vs 47,387 Complaints, Almost Identical↗
- JetFormBuilder CVE-2026-12793: Update to 3.6.5.3 — Unauthenticated Admin Account Creation↗
- Callers Claiming to Be Police: Four Things Real Officers Never Do↗
- Cisco Secure Email Gateway CVE-2026-76461: Patch to 16.5.0-780 — A Single Email Grants Root↗
- Before You Reply: The "Please Vote" DM That Hijacks Your LINE Account↗
- GitLab CVE-2026-85706: Patch to 19.1.8/19.2.6/19.3.2 — Unauthenticated Arbitrary File Read, Already Exploited↗
Three lines to forward to your family
- ▸The "please vote" DM and the call from someone claiming to be police are both entry points the other side chose. Never send a verification code to anyone. Never call back the number they gave you — hang up and dial #9110, Japan's police advice line, yourself.
- ▸Never install an app from anywhere but the official app store. Apps installed from links in email or SMS have been used to operate payment apps remotely and send money out (published by Japan's National Police Agency on 18 September 2026).
- ▸Before you order anything marked "first time only" or "trial", read the final confirmation screen. It may be a recurring contract. If you have already signed, call 188, Japan's consumer hotline. There is nothing to be embarrassed about.
If something has gone wrong
If you are thinking "oh no", work through it in order. There is nothing to be embarrassed about.
If you sent a verification code, contact that service first. If the account is already taken, tell your friends and family through a different channel not to act on money requests coming from you. If a payment balance moved on its own, contact that payment provider first and remove any app you do not recognise.
The consultation lines below are for people in Japan. Consumer hotline: 188 (no area code) covers contracts and cancellations. Police advice line: #9110 is the nationwide number for non-emergency police consultation. You can use it while you are still unsure whether something is a scam, and equally after you have already lost money. If you are in immediate danger, call 110 instead. Neither number requires you to have been harmed first, and neither stops being available once you have.
- Emergency response guide by incident type↗
- National Police Agency: police advice line #9110 (prefectural contact list, Japan)↗
- National Consumer Affairs Center: local consumer centres (hotline 188, Japan)↗
- National Police Agency: reporting desks for cyber incidents (Japan)↗
- IPA: Information Security Support Desk, 2026 Q2 (April to June)↗
- National Police Agency: beware of fake-police fraud (SOS47)↗
- National Consumer Affairs Center: consultations from people aged 65 and over, FY2025 (16 September 2026)↗
- National Consumer Affairs Center: beware of business-course trouble (16 September 2026)↗
- National Police Agency: Cyber Police Bureau bulletin Vol.18 (18 September 2026)↗
- Council of Anti-Phishing Japan: August 2026 phishing report↗
- CISA: Known Exploited Vulnerabilities Catalog↗
