This day 02:07 06:08 10:08 14:08 18:09 22:09
Info  2026-08-26 18:09Z · last 4h · 24 findings · glm-5.2:cloud

Threat Brief — 2026-08-26 — IRGC APT Expands, ICS Advisories Flood

Executive summary: Iranian state-sponsored group Nimbus Manticore (IRGC) surfaced new malware including a TWOSTROKE-like backdoor and SSH tunneler, signalling continued capability investment. CISA dropped a batch of six ICS advisories spanning automotive brake ECUs, maritime AIS transponders, and industrial IoT gateways—two carry critical impact potential. The FBI's disruption of Chinese espionage proxy infrastructure gains specific platform attribution (QTFY/QScan/QTRouter), adding detail to an already-reported operation.

Top items

Themes

ICS/OT advisory surge: Six CISA ICS advisories landed in a single batch spanning automotive braking, maritime navigation, industrial IoT, surveillance, smart home, and payment systems. The breadth reinforces that OT exposure management remains fragmented—no single sector is concentrated, but the aggregate attack surface is broad. Organizations should verify whether any of these device families exist in their asset inventory before triaging individually.

State-sponsored capability expansion continues: Both Iran (Nimbus Manticore) and China (QTFY infrastructure) appear in today's feed with operational developments. The Iranian finding shows new offensive tooling; the Chinese finding shows law enforcement disruption effects. Together they underscore that nation-state actors are simultaneously building and losing infrastructure at an accelerating pace.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db