📡 IT SecOps News — September 18, 2026
Daily IT SecOps, vulnerability, patch, and security news briefing. Sources monitored: 17 feeds across Microsoft, CISA, security news, and IT communities
🚨 High Alerts & Active Exploits
Critical vulnerabilities, zero-days, active exploits in the wild, and emergency advisories requiring immediate IT SecOps attention.
| Priority | Title | Source | Advisory / Link |
|---|---|---|---|
| 🔴 HIGH | Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized … | The Hacker News | Read News Article → |
| 🔴 HIGH | WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Exte… | The Hacker News | Read News Article → |
| 🔴 HIGH | Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer | The Hacker News | Read News Article → |
| 🔴 HIGH | Get rid of ads with a lifetime AdGuard Family plan for only $11 | Neowin | Read News Article → |
| 🔴 HIGH | RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall | The Hacker News | Read News Article → |
| 🔴 HIGH | New RatHat Android malware uses AI to automate device control | BleepingComputer | Read News Article → |
| 🔴 HIGH | Brevo supply-chain attack injected ClickFix scripts on customer sites | BleepingComputer | Read News Article → |
| 🔴 HIGH | Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify… | The Hacker News | Read News Article → |
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Source: The Hacker News · Published: September 18, 2026 at 12:47 PM UTC · 🔗 Direct Link to Article / Advisory
🛡️ CVE: CVE-2026-85889 (CVE.org) · (NVD) Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. “Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacke…
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Source: The Hacker News · Published: September 18, 2026 at 10:40 AM UTC · 🔗 Direct Link to Article / Advisory
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People’s Republic of Korea’s (DPRK) Contag…
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
Source: The Hacker News · Published: September 18, 2026 at 09:18 AM UTC · 🔗 Direct Link to Article / Advisory
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. “The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code…
Get rid of ads with a lifetime AdGuard Family plan for only $11
Source: Neowin · Published: September 18, 2026 at 07:34 AM UTC · 🔗 Direct Link to Article / Advisory
Get rid of annoying ads and protect your device from malware with this AdGuard Family Plan lifetime deal, which is available for a limited time only. Read more…
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Source: The Hacker News · Published: September 18, 2026 at 06:17 AM UTC · 🔗 Direct Link to Article / Advisory
Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. “Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to dece…
⚠️ Bad Updates & Known Issues
Reports of problematic updates, broken KBs, OS regressions, and patches causing issues.
- 🟠 Microsoft fixes broken copy and paste for Excel 2016 users — BleepingComputer · Article Link → — 🔧 KB: KB5002914 (Microsoft Support)
Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. […]
📅 Upcoming Changes & Deprecations (14-Day Horizon)
Upcoming security changes, feature retirements, and deadlines on the horizon.
-
📆 Outlook: Multi Account Search — Microsoft 365 Roadmap · Read Announcement → Users will be able to see results from multiple mailboxes interweaved in a single ranked list and will be able to do standard mail actions. GA date: October CY2026
-
📆 Microsoft 365 admin center: Optional Public CDN Support in Brand Center Setup — Microsoft 365 Roadmap · Read Announcement → We are updating the Brand Center setup experience so that administrators can set up Brand Center without enabling Public CDN. Today, Public CDN is enabled as part of Brand Center setup, even when an organization only wants to use branding governance capabilities that do not re…
-
📆 Microsoft Teams: Schedule Channel Meetings from Outlook Calendar — Microsoft 365 Roadmap · Read Announcement → Users will be able to schedule Microsoft Teams channel meetings directly from Outlook Calendar. This streamlines meeting creation and helps keep discussions and meeting content connected in the appropriate channel. GA date: October CY2026
-
📆 Dynamics 365 Field Service: Manage rental service demand with work order requests — Microsoft 365 Roadmap · Read Announcement → Rental organizations need to coordinate commercial rental activity, equipment availability, asset condition, and service execution across multiple teams and applications. Service needs can arise while equipment is in stock, in transit, at a customer site, or being returned, bu…
-
📆 Dynamics 365 Field Service: Book Work Orders with Multiple Requirements — Microsoft 365 Roadmap · Read Announcement → Dispatchers can now select which resource requirement to schedule when booking a work order that has multiple requirements. The new Book experience is available from both the work order form and list view, and shows relevant details such as requirement duration, time windows, …
✅ Official Updates & Security Advisories
Feature announcements, security blogs, and official releases.
-
Configure Platform SSO for macOS devices - Microsoft Intune — Microsoft Intune What’s New · Read Article → Configure Platform SSO for macOS devices in Microsoft Intune Summarize this article for me In this article You can configure Platform SSO to enable single sign-on (SSO) for your macOS devices using passwordless authentication, Microsoft Entra ID user accounts, or smart cards. …
-
Microsoft Cloud PKI for Microsoft Intune - Microsoft Intune — Microsoft Intune What’s New · Read Article → Overview of Microsoft Cloud PKI for Microsoft Intune Summarize this article for me In this article Use Microsoft Cloud PKI to issue certificates for Intune-managed devices. Microsoft Cloud PKI is a cloud-based service that simplifies and automates certificate lifecycle managem…
-
From guidance to action: Security fundamentals that materially reduce risk — Microsoft Security Blog · Read Article → AI has made fundamental changes to the operating environment for cybersecurity. Explore exposure management guidance on recommended controls and take action and stay ahead of cyberthreats. The post From guidance to action: Security fundamentals that materially reduce risk appe…
-
Improving email security outcomes with real-world Microsoft Defender insights — Microsoft Security Blog · Read Article → The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve. The post Improving email security outcomes with real-world Microsoft Defender ins…
🐛 IT SecOps Community Buzz
What IT SecOps teams and sysadmins are discussing today.
- Microsoft Defender update fixes false antivirus alerts in Windows 10, 11, Server — Neowin · View Thread →
The flaw caused Defender to claim protection was disabled despite functioning normally, potentially generating widespread notification fatigue among administrators managing enterprise fleets. Read more…
Generated automatically at September 18, 2026 at 02:45 PM UTC · View all IT SecOps news →