Cisco is warning that CVE-2026-76461 — a critical SQL injection in Secure Email Gateway / AsyncOS (physical and virtual) — is being actively exploited. Unauthenticated attackers can reach root command execution through a crafted email. CVSS 9.8; CISA added it to KEV with a federal due date of Sep 17. Cisco is contacting Secure Email Cloud customers with IoCs. There was no public PoC at disclosure. If you run SEG appliances, treat this as hunt-and-patch now (Cisco cites builds such as 16.5.0-780 — verify against the advisory for your train).

Same day, eSentire TRU published GhostCode: a device-code phishing kit where the victim completes a real Microsoft sign-in plus MFA using the attacker’s device code. Operators then registered three Entra devices and obtained a Primary Refresh Token in about 78 seconds, with token abuse starting ~5 seconds after auth. MFA does not stop the token; Intune-joined devices can persist after token revoke until they are removed.

Livermore takeaway: email appliances are high-value pivots for SMB/MSP stacks — patch and hunt per Cisco. On identity, block unused device-code flows with Conditional Access, and alert on deviceCode → unusual clients (e.g. python-requests) plus burst device registrations. This is distinct from the earlier passkey-vishing pattern — same family of “user did something real,” different control gap.