BambooToken: The Malware That Speaks MQTT to Stay Under the Radar

2026-09-17T02:51:37Z•fd2cd2b4d15d4d254b6a51a8f86c2cda3a1a59da3637a0bed5b5df7c87345650
CVE-2026-58704CVE-2026-76461APTBambooTokenCISA KEVChromeCisco Secure Email GatewayGoogle PixelLinuxLiteSpeed EnterpriseMQTTTelegram DesktopWindowsWindows exploitationXSScellular modemdata breachespionageexploitation-in-the-wildgovernmentmalwareprivilege escalationremote code executionroot accesssideloadingsupply chainzero-day

What happened

SecurityAffairs feed reports multiple September 2026 security incidents, including MQTT-based BambooToken malware targeting Windows and Linux, exploited Pixel modem and Cisco Secure Email Gateway zero-days, data breaches affecting Revolut customers, CenterPoint Energy customers, and Japanese government employees, a critical LiteSpeed Enterprise privilege-escalation flaw, Chrome/Windows espionage campaigns, and a Telegram Desktop stored XSS vulnerability.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
fd2cd2b4d15d4d254b6a51a8f86c2cda3a1a59da3637a0bed5b5df7c87345650
Enrichment time
2026-09-17T02:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · BambooToken: The Malware That Speaks MQTT to Stay Under the Radar · Baitaphish