📡 IT SecOps News — September 15, 2026
Daily IT SecOps, vulnerability, patch, and security news briefing. Sources monitored: 17 feeds across Microsoft, CISA, security news, and IT communities
🚨 High Alerts & Active Exploits
Critical vulnerabilities, zero-days, active exploits in the wild, and emergency advisories requiring immediate IT SecOps attention.
| Priority | Title | Source | Advisory / Link |
|---|---|---|---|
| 🔴 HIGH | BambooToken malware controls Windows and Linux systems via MQTT | BleepingComputer | Read News Article → |
| 🔥 ACTIVELY EXPLOITED | What Zero-Day Response Should Be in the Post-Mythos Era | BleepingComputer | Read News Article → |
| 🔴 HIGH | CISA: Critical VMware RCE flaw now exploited by ransomware gangs | BleepingComputer | Read News Article → |
| 🔥 ACTIVELY EXPLOITED | Cisco patches Secure Email Gateway zero-day exploited in attacks | BleepingComputer | Read News Article → |
| 🔥 ACTIVELY EXPLOITED | Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Comm… | The Hacker News | Read News Article → |
| 🔥 ACTIVELY EXPLOITED | China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRI… | The Hacker News | Read News Article → |
| 🔴 HIGH | Hackers hijack HBO Max Reddit account to push malware in ClickFix ads | BleepingComputer | Read News Article → |
| 🔴 HIGH | Microsoft releases emergency out-of-band Windows update to fix Patch Tue… | Neowin | Read News Article → |
BambooToken malware controls Windows and Linux systems via MQTT
Source: BleepingComputer · Published: September 15, 2026 at 03:00 PM UTC · 🔗 Direct Link to Article / Advisory
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. […]
🔥 [ACTIVELY EXPLOITED / ZERO-DAY] What Zero-Day Response Should Be in the Post-Mythos Era
Source: BleepingComputer · Published: September 15, 2026 at 01:45 PM UTC · 🔗 Direct Link to Article / Advisory
AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. […]
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
Source: BleepingComputer · Published: September 15, 2026 at 12:16 PM UTC · 🔗 Direct Link to Article / Advisory
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. […]
🔥 [ACTIVELY EXPLOITED / ZERO-DAY] Cisco patches Secure Email Gateway zero-day exploited in attacks
Source: BleepingComputer · Published: September 15, 2026 at 07:31 AM UTC · 🔗 Direct Link to Article / Advisory
Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. […]
🔥 [ACTIVELY EXPLOITED / ZERO-DAY] Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Source: The Hacker News · Published: September 15, 2026 at 06:11 AM UTC · 🔗 Direct Link to Article / Advisory
🛡️ CVE: CVE-2026-76461 (CVE.org) · (NVD) Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that…
⚠️ Bad Updates & Known Issues
Reports of problematic updates, broken KBs, OS regressions, and patches causing issues.
No problematic update reports detected today.
📅 Upcoming Changes & Deprecations (14-Day Horizon)
Upcoming security changes, feature retirements, and deadlines on the horizon.
-
📆 Microsoft Teams: Report suspicious guest invitations — Microsoft 365 Roadmap · Read Announcement → Microsoft Teams will enable users to report suspicious guest invitations directly from Teams. When users receive an unexpected or potentially malicious guest invitation, they can report it to their IT admin for review, helping identify and mitigate phishing and other abuse thr…
-
📆 Outlook: New Cloud Policy controls — Microsoft 365 Roadmap · Read Announcement → We’re introducing Cloud Policy service support for Outlook on the web and new Outlook for Windows. Admins can set default values for supported Outlook settings and choose whether users can change them, providing consistent cloud-based control across their organization GA date:…
✅ Official Updates & Security Advisories
Feature announcements, security blogs, and official releases.
No new official announcements detected today.
🐛 IT SecOps Community Buzz
What IT SecOps teams and sysadmins are discussing today.
- Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers — The Hacker News · View Thread →
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development server…
- Microsoft confirms KB5002914 Excel update breaks copy and paste — BleepingComputer · View Thread → — 🔧 KB: KB5002914 (Microsoft Support)
Microsoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update. […]
- CrowdStrike CEO pushes back against AI slowdown calls — Neowin · View Thread →
The cybersecurity executive highlights ongoing risks from Hugging Face and RubyGems attacks, advocating for runtime guardrails over regulation. Read more…
- LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server — The Hacker News · View Thread →
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, …
- ENISA warns frontier AI compresses exploit windows — Neowin · View Thread →
Advanced AI is automating reconnaissance and chaining low severity bugs, overwhelming human patch management and forcing a shift to automated triage. Read more…
- KB5129195 fails to fix secure domain logins broken by Windows 11 KB5124008 — Neowin · View Thread → — 🔧 KB: KB5129195 (Microsoft Support) · 🔧 KB: KB5124008 (Microsoft Support)
Admins have confirmed KB5129195 emergency update doesn’t fix secure domain logins that were broken after Windows 11’s KB5124008 update. Read more…
- Microsoft confirms September 2026 KB5002914 update “silently” break Excel copy-paste — Neowin · View Thread → — 🔧 KB: KB5002914 (Microsoft Support)
Microsoft has acknowledged that its latest Excel update, KB5002914, is indeed breaking copy-paste functionality. Read more…
- ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits — The Hacker News · View Thread →
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The…
Generated automatically at September 15, 2026 at 03:26 PM UTC · View all IT SecOps news →