📡 IT SecOps News — September 16, 2026

Daily IT SecOps, vulnerability, patch, and security news briefing. Sources monitored: 17 feeds across Microsoft, CISA, security news, and IT communities


🚨 High Alerts & Active Exploits

Critical vulnerabilities, zero-days, active exploits in the wild, and emergency advisories requiring immediate IT SecOps attention.

Priority Title Source Advisory / Link
🔴 HIGH The true cost of a ransomware attack, with and without BCDR BleepingComputer Read News Article →
🔴 HIGH N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity… The Hacker News Read News Article →
🔴 HIGH Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation The Hacker News Read News Article →
🔥 ACTIVELY EXPLOITED Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks The Hacker News Read News Article →
🔥 ACTIVELY EXPLOITED Google fixes actively exploited Android zero-day on Pixel devices BleepingComputer Read News Article →
🔴 HIGH Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP W… The Hacker News Read News Article →
🔴 HIGH Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With For… The Hacker News Read News Article →
🔴 HIGH KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and… The Hacker News Read News Article →
🔴 HIGH Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and… The Hacker News Read News Article →
🔴 HIGH BambooToken Malware Uses MQTT to Control Windows and Linux Systems The Hacker News Read News Article →

The true cost of a ransomware attack, with and without BCDR

Source: BleepingComputer · Published: September 16, 2026 at 02:00 PM UTC · 🔗 Direct Link to Article / Advisory

The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. […]

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

Source: The Hacker News · Published: September 16, 2026 at 11:58 AM UTC · 🔗 Direct Link to Article / Advisory

N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensiti…

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Source: The Hacker News · Published: September 16, 2026 at 11:15 AM UTC · 🔗 Direct Link to Article / Advisory

🛡️ CVE: CVE-2026-58704 (CVE.org) · (NVD) Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. “In Cellular Modem, there is a possible permission bypass due to a logic error in the code,” according to a description of the…

🔥 [ACTIVELY EXPLOITED / ZERO-DAY] Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Source: The Hacker News · Published: September 16, 2026 at 11:08 AM UTC · 🔗 Direct Link to Article / Advisory

🛡️ CVE: CVE-2026-87886 (CVE.org) · (NVD) Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions - Acr…

🔥 [ACTIVELY EXPLOITED / ZERO-DAY] Google fixes actively exploited Android zero-day on Pixel devices

Source: BleepingComputer · Published: September 16, 2026 at 07:00 AM UTC · 🔗 Direct Link to Article / Advisory

Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. […]


⚠️ Bad Updates & Known Issues

Reports of problematic updates, broken KBs, OS regressions, and patches causing issues.

No problematic update reports detected today.


📅 Upcoming Changes & Deprecations (14-Day Horizon)

Upcoming security changes, feature retirements, and deadlines on the horizon.


✅ Official Updates & Security Advisories

Feature announcements, security blogs, and official releases.


🐛 IT SecOps Community Buzz

What IT SecOps teams and sysadmins are discussing today.


Generated automatically at September 16, 2026 at 03:18 PM UTC · View all IT SecOps news →