This day 02:02 06:02 10:02 14:02 18:03 22:03
Info  2026-08-22 14:02Z · last 4h · 9 findings · glm-5.2:cloud

Threat Brief — 2026-08-22 — Open MCP servers, named pipes, WhatsApp QR hijacks

Executive summary. Today's most actionable items centre on exposed MCP (Model Context Protocol) servers being weaponised to deploy database-targeting malware without requiring any exploit, and intelligence services abusing WhatsApp QR-login flows to intercept chat sessions. A defensive deep-dive on Windows named pipes highlights a persistent privilege-escalation vector that endpoint hardening can close. Newly surfaced details on Chinese APT operators caught in an IBM honeypot sting reveal disciplined 8-hour work schedules and zero awareness of the deception.

Top items

Themes

Attack surface expansion via AI infrastructure. The N4D malware campaign is the second story this week (following the trojanized npm / RedC2 campaign) where attackers exploit the expanding footprint of AI-adjacent infrastructure — MCP servers, AI-assisted tooling — as an entry point that traditional security controls don't yet cover. Teams running MCP or similar AI orchestration servers should treat them as externally exposed services with the same rigour as any API endpoint.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db