This day 02:07 06:08 10:08 14:08 18:09 22:09
Info  2026-08-26 22:09Z · last 4h · 8 findings · glm-5.2:cloud

Threat Brief — 2026-08-26 — APT Tooling, WordPress RCE, GPU Rowhammer

Executive summary. Dark Caracal debuted a new modular malware framework (GoCaracal) that significantly expands its data-theft and persistence capabilities. A critical zero-click RCE chain in the widely deployed Avada WordPress theme demands immediate patching. On the research front, the GPUThor Rowhammer variant defeats NVIDIA's ECC memory protections for root-level privilege escalation. Meanwhile, updated guidance on spotting fake North Korean IT workers is worth circulating to hiring managers.

Top items

Themes

Attack surface expansion across the stack. Today's findings span WordPress application-layer RCE, GPU hardware-level privilege escalation, and nation-state insider placement — illustrating that adversaries are simultaneously exploiting low-hanging web vulnerabilities and pushing into deeper, harder-to-patch layers. The Avada flaw and GoCaracal both target widely deployed but unevenly maintained systems, reinforcing that patch latency remains the single largest exploitable gap.

===

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db