This day 02:02 12:52 14:03 18:03 22:04
Info  2026-08-31 14:03Z · last 4h · 28 findings · glm-5.2:cloud

Threat Brief — 2026-08-31 — Zero-days published, vishing evolves

Multiple zero-day exploits and proof-of-concept code surfaced today, including a Kaspersky Endpoint Security flaw with a working GitHub exploit and three new NightmareEclipse PoCs targeting Avast and NVIDIA. A coordinated voice-phishing campaign abusing Microsoft Teams is actively targeting enterprise domain controllers. Ransomware actors confirmed data theft from Berlin's city administration, while ShinyHunters claims 284 million medical records stolen from McKesson with a $55.2 million ransom demand.

Top items

Themes

AI-agent attack surface is expanding rapidly. Poisoned llms.txt files tricking AI agents into executing untrusted code, AI safety refusals being weaponised to hide malicious code (UAC-0099), and AI services abused as exploit-development testbeds all point to a growing set of vectors specific to agentic AI workflows. Organisations deploying AI coding or automation agents should treat agent-readable documentation as untrusted input.

Ransomware data-theft confirmation cycle accelerates. Both Berlin (Rhysida) and McKesson (ShinyHunters) moved from initial breach claims to confirmed data theft within days, with extortion demands in the tens of millions. The pattern reflects actors prioritising data exfiltration over encryption for leverage.

Local privilege escalation PoCs are flooding public channels. NightmareEclipse has now published exploits targeting Kaspersky, Avast, and NVIDIA products in quick succession. Endpoint security and graphics driver software are both high-value targets for LPE, and public PoC availability shortens the window for exploitation before patches ship.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db