📡 IT SecOps News — September 17, 2026

Daily IT SecOps, vulnerability, patch, and security news briefing. Sources monitored: 17 feeds across Microsoft, CISA, security news, and IT communities


🚨 High Alerts & Active Exploits

Critical vulnerabilities, zero-days, active exploits in the wild, and emergency advisories requiring immediate IT SecOps attention.

Priority Title Source Advisory / Link
🔴 HIGH Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious D… The Hacker News Read News Article →
🔴 HIGH Chinese hackers use SparroWocky malware in govt espionage attacks BleepingComputer Read News Article →
🔥 ACTIVELY EXPLOITED Cisco warns of max severity ISE zero-day exploited in attacks BleepingComputer Read News Article →
🔥 ACTIVELY EXPLOITED Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Act… The Hacker News Read News Article →
🔴 HIGH Iranian hackers use CHOSEN BRICK Windows malware to spy on targets BleepingComputer Read News Article →
🔴 HIGH Malware bypasses browser checks to force install Chrome, Edge extensions BleepingComputer Read News Article →
🔴 HIGH Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Com… The Hacker News Read News Article →
🔴 HIGH Three Threat Groups Target Russian Enterprises With Backdoors, Ransomwar… The Hacker News Read News Article →

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Source: The Hacker News · Published: September 17, 2026 at 12:30 PM UTC · 🔗 Direct Link to Article / Advisory

🛡️ CVE: CVE-2026-81642 (CVE.org) · (NVD) Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tra…

Chinese hackers use SparroWocky malware in govt espionage attacks

Source: BleepingComputer · Published: September 17, 2026 at 09:00 AM UTC · 🔗 Direct Link to Article / Advisory

The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. […]

🔥 [ACTIVELY EXPLOITED / ZERO-DAY] Cisco warns of max severity ISE zero-day exploited in attacks

Source: BleepingComputer · Published: September 17, 2026 at 07:20 AM UTC · 🔗 Direct Link to Article / Advisory

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. […]

🔥 [ACTIVELY EXPLOITED / ZERO-DAY] Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Source: The Hacker News · Published: September 17, 2026 at 06:39 AM UTC · 🔗 Direct Link to Article / Advisory

🛡️ CVE: CVE-2026-76460 (CVE.org) · (NVD) Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. “This vulnerability is due to insufficient authentication control o…

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

Source: BleepingComputer · Published: September 16, 2026 at 08:24 PM UTC · 🔗 Direct Link to Article / Advisory

Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. […]


⚠️ Bad Updates & Known Issues

Reports of problematic updates, broken KBs, OS regressions, and patches causing issues.

No problematic update reports detected today.


📅 Upcoming Changes & Deprecations (14-Day Horizon)

Upcoming security changes, feature retirements, and deadlines on the horizon.


✅ Official Updates & Security Advisories

Feature announcements, security blogs, and official releases.

No new official announcements detected today.


🐛 IT SecOps Community Buzz

What IT SecOps teams and sysadmins are discussing today.


Generated automatically at September 17, 2026 at 03:25 PM UTC · View all IT SecOps news →