Threat Brief — 2026-09-10 — Android dual-threat malware, Excel breakage
Executive summary: A new Android malware strain combining ransomware and spyware capabilities has surfaced, encrypting files while simultaneously exfiltrating data and harassing victims. Microsoft's September update troubles continue: Excel's latest security patch breaks copy-and-paste operations, compounding the already-reported RDS breakage. CISA has formally added a MikroTik RouterOS authentication bypass to its Known Exploited Vulnerabilities catalog, a development since the flaw was first reported as actively exploited last week.
Top items
- Mantax Otax Android malware combines ransomware, spyware, and harassment. A newly identified Android malware strain encrypts victim files, exfiltrates sensitive data, and floods victims with spam and harassment messages — an unusual combination of extortion techniques on mobile. The strain has not been linked to a previously named actor group. (src: BleepingComputer)
- CISA adds MikroTik RouterOS flaw to KEV catalog — formal confirmation of active exploitation. CVE-2026-67277KEV, a MikroTik RouterOS missing-authentication vulnerability, has been added to CISA's Known Exploited Vulnerabilities catalog. This formalises what was first reported on 2026-09-04 by SecurityLab.ru as active exploitation against SSH-exposed routers. A second CVE was also added in the same KEV update. (src: CISA)
- Microsoft Excel KB5002914 security update breaks copy-and-paste and formula dragging. This week's Office security update is causing copy-and-paste failures and broken formula dragging in Excel. Affected users report that rolling back the update restores functionality. This adds to a growing list of September Patch Tuesday side-effects, including the already-reported Remote Desktop Services failures on Windows Server 2019/2022/2025. (src: BleepingComputer)
Themes
September update quality issues are stacking up. Microsoft's September 2026 patch batch continues to produce operational breakage beyond the security fixes themselves: RDS connectivity failures on Windows Server (first reported 2026-09-10), Excel copy-and-paste disruption, and previously reported desktop-settings resets from KB5120998. Organisations applying these patches should test broadly and prepare rollback options.
