This day 02:00 06:00 10:00 14:01 18:01 22:01
Info  2026-08-16 14:01Z · last 4h · 5 findings · glm-5.2:cloud

Threat Brief — 2026-08-16 — Kernel Backdoors & Robot Eyes

Executive summary. Mustang Panda has been caught deploying a backdoor directly inside the Windows kernel, evading antivirus entirely and compromising government agencies across at least four countries. Separately, the actively-exploited macOS Screen Sharing authentication bypass now has fresh reporting detailing a trivially simple two-packet exploit chain yielding root access — if you haven't patched, do it now. On the consumer-privacy front, a budget cleaning robot is recording home interiors and occupant behaviour with no opt-out, raising data-collection questions for any environment where these devices are deployed.


Top items


Themes

Kernel-level stealth is the new bar. Both the Mustang Panda backdoor and the macOS Screen Sharing exploit demonstrate attackers operating at or near the kernel to evade traditional endpoint controls. The Mustang Panda case is particularly concerning because the implant is designed specifically to be invisible to AV — a signal that commodity EDR/AV may be insufficient against determined nation-state actors, and kernel-level telemetry or behavioural detection is increasingly necessary.

Consumer devices as intelligence-collection platforms. The cleaning-robot story fits a broader pattern of cheap connected devices capturing rich environmental data (interior layout, occupant behaviour, daily routines) with no meaningful consent or opt-out mechanism. These devices are potential sources of actionable intelligence if present in or near sensitive spaces.

===

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db