📡 IT SecOps News — September 15, 2026

Daily IT SecOps, vulnerability, patch, and security news briefing. Sources monitored: 17 feeds across Microsoft, CISA, security news, and IT communities


🚨 High Alerts & Active Exploits

Critical vulnerabilities, zero-days, active exploits in the wild, and emergency advisories requiring immediate IT SecOps attention.

Priority Title Source Advisory / Link
🔴 HIGH BambooToken malware controls Windows and Linux systems via MQTT BleepingComputer Read News Article →
🔥 ACTIVELY EXPLOITED What Zero-Day Response Should Be in the Post-Mythos Era BleepingComputer Read News Article →
🔴 HIGH CISA: Critical VMware RCE flaw now exploited by ransomware gangs BleepingComputer Read News Article →
🔥 ACTIVELY EXPLOITED Cisco patches Secure Email Gateway zero-day exploited in attacks BleepingComputer Read News Article →
🔥 ACTIVELY EXPLOITED Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Comm… The Hacker News Read News Article →
🔥 ACTIVELY EXPLOITED China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRI… The Hacker News Read News Article →
🔴 HIGH Hackers hijack HBO Max Reddit account to push malware in ClickFix ads BleepingComputer Read News Article →
🔴 HIGH Microsoft releases emergency out-of-band Windows update to fix Patch Tue… Neowin Read News Article →

BambooToken malware controls Windows and Linux systems via MQTT

Source: BleepingComputer · Published: September 15, 2026 at 03:00 PM UTC · 🔗 Direct Link to Article / Advisory

A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. […]

🔥 [ACTIVELY EXPLOITED / ZERO-DAY] What Zero-Day Response Should Be in the Post-Mythos Era

Source: BleepingComputer · Published: September 15, 2026 at 01:45 PM UTC · 🔗 Direct Link to Article / Advisory

AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. […]

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

Source: BleepingComputer · Published: September 15, 2026 at 12:16 PM UTC · 🔗 Direct Link to Article / Advisory

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. […]

🔥 [ACTIVELY EXPLOITED / ZERO-DAY] Cisco patches Secure Email Gateway zero-day exploited in attacks

Source: BleepingComputer · Published: September 15, 2026 at 07:31 AM UTC · 🔗 Direct Link to Article / Advisory

Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. […]

🔥 [ACTIVELY EXPLOITED / ZERO-DAY] Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Source: The Hacker News · Published: September 15, 2026 at 06:11 AM UTC · 🔗 Direct Link to Article / Advisory

🛡️ CVE: CVE-2026-76461 (CVE.org) · (NVD) Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that…


⚠️ Bad Updates & Known Issues

Reports of problematic updates, broken KBs, OS regressions, and patches causing issues.

No problematic update reports detected today.


📅 Upcoming Changes & Deprecations (14-Day Horizon)

Upcoming security changes, feature retirements, and deadlines on the horizon.

  • 📆 Microsoft Teams: Report suspicious guest invitationsMicrosoft 365 Roadmap · Read Announcement → Microsoft Teams will enable users to report suspicious guest invitations directly from Teams. When users receive an unexpected or potentially malicious guest invitation, they can report it to their IT admin for review, helping identify and mitigate phishing and other abuse thr…

  • 📆 Outlook: New Cloud Policy controlsMicrosoft 365 Roadmap · Read Announcement → We’re introducing Cloud Policy service support for Outlook on the web and new Outlook for Windows. Admins can set default values for supported Outlook settings and choose whether users can change them, providing consistent cloud-based control across their organization GA date:…


✅ Official Updates & Security Advisories

Feature announcements, security blogs, and official releases.

No new official announcements detected today.


🐛 IT SecOps Community Buzz

What IT SecOps teams and sysadmins are discussing today.


Generated automatically at September 15, 2026 at 03:26 PM UTC · View all IT SecOps news →