Threat Brief — 2026-09-06: Old systems cut off, new attacks surface
Executive summary: Microsoft has begun forcibly disconnecting legacy Exchange servers after exhausting its warning timeline — a significant operational event for any organisation still running unsupported versions. Rockwell has disclosed an ICS attack that CISA was unaware of, and the Pentagon has disabled ad trackers on military smartphones over credible surveillance and targeting risks. Separately, a single Google Cloud engineer bypassed three layers of redundancy during planned maintenance, turning resilient infrastructure into a single point of failure.
Top items
- Rockwell discloses ICS attack unknown to CISA — Rockwell identified an attack on its industrial control systems that CISA had no record of, and reportedly confused the vulnerability's disclosure status, causing confusion in security teams. This matters because it suggests a gap between vendor-discovered and regulator-tracked ICS threats. First reported 2026-09-06 by RSS:securitylab-ru. (src: SecurityLab)
- Pentagon disables ad trackers on military smartphones over missile-surveillance threat — The scale of the ad-tracker exposure surfaced during a classified operation, with location data from commercial ad SDKs creating potential targeting pathways for adversaries. This highlights how consumer-grade telemetry on government devices can translate into kinetic risk. First reported 2026-09-06 by RSS:securitylab-ru. (src: SecurityLab)
- Microsoft begins forcibly disconnecting old Exchange servers — After repeated warnings, Microsoft has started cutting off unsupported Exchange servers, which could disrupt mail flow for organisations that have not migrated. Anyone still running out-of-support Exchange should treat this as an imminent operational risk, not a future deadline. (src: SecurityLab)
- Google Cloud engineer bypasses three security layers during maintenance — A planned maintenance operation defeated Google Cloud's redundant infrastructure design, collapsing it into a single point of failure. The incident illustrates that human action during routine change windows can invalidate architectural resilience assumptions. (src: SecurityLab)
- Telegram QR-code login method faces potential block — A lawsuit may force Telegram to disable QR-code-based authentication, a login method used by many desktop users. The legal challenge creates uncertainty around an authentication path that could be removed without much warning. (src: SecurityLab)
Themes
Operational consequences of deferred modernisation. Microsoft's forced Exchange disconnection and the Rockwell disclosure both underscore that legacy industrial and enterprise systems remain prime targets — and the gap between what vendors know and what regulators track can be wide enough to hide active attacks.
Consumer telemetry as a kinetic threat vector. The Pentagon's ad-tracker action reinforces a pattern seen across recent weeks: commercial data-collection infrastructure on mobile devices creates adversary targeting opportunities that traditional security controls do not address.
