Info
2026-09-03 18:03Z · last 4h · 29 findings
· glm-5.2:cloud
Threat Brief — 2026-09-03 — ICS Advisories, Active WordPress Exploitation, Court Data Breach
Executive summary: Today's intake is dominated by a batch of CISA ICS advisories covering RCE and privilege-escalation flaws in industrial control products from Rockwell Automation, OPC Foundation, IXON, and others. A critical Elementor Pro WordPress plugin vulnerability (CVE-2026-32475) is being actively exploited for site takeover via webshell deployment. Thomson Reuters disclosed a March 2026 breach of its C-Track court case management platform affecting courts in 11 U.S. states, with potential exposure of SSNs and sealed case data. The BraZetsu Python malware framework and the RepoGhost GitHub repository hijacking campaign round out the notable new threats.
Top items
- Elementor Pro WordPress plugin actively exploited (CVE-2026-32475). A recently patched critical vulnerability in the Elementor Pro plugin is being exploited in the wild to deliver webshell payloads and execute arbitrary commands on compromised WordPress servers. A public exploit is available and active exploitation is confirmed. (src: BleepingComputer)
- Critical Cisco Nexus 9000 unauthenticated root RCE. Cisco has released patches for a critical flaw in 10 Silicon One-based Nexus 9000 switches allowing unauthenticated, remote attackers to execute code as root. An IOS XR hardening release bundling additional fixes was also published. (src: The Hacker News)
- Thomson Reuters C-Track court software breach exposes SSNs and sealed data. An unauthorized party obtained files from the C-Track court case management platform in March 2026, affecting courts in 11 U.S. states and the U.S. Virgin Islands. Exposed data may include Social Security Numbers and sealed case records. (src: The Hacker News)
- IXON VPN Client RCE with elevated privileges. A vulnerability in the IXON VPN Client could allow an attacker to achieve remote code execution on the client machine with elevated privileges. CISA has published an ICS advisory with affected version details. (src: CISA)
- OPC Foundation OPC UA LocalDiscoveryServer high-privilege takeover. A flaw in the OPC UA LDS could allow an attacker to seize control of a high-privilege terminal during installation and run arbitrary commands. Affects specific versions of the LocalDiscoveryServer component. (src: CISA)
- Rockwell Automation ControlFLASH arbitrary command execution. Successful exploitation could allow an attacker to run arbitrary commands or code at the logged-in user's permission level on a target machine running affected versions of ControlFLASH. (src: CISA)
- Inductive Automation Ignition authenticated project-creation bypass (CVE-2026-77393). A vulnerability in Ignition versions ≤ 8.1.53 could allow any authenticated user to create projects, potentially enabling privilege escalation within the SCADA platform. (src: CISA)
- BraZetsu Python malware framework monetizes compromised Windows hosts. A sophisticated Python-based Windows malware framework fuels an underground marketplace that commercializes access to compromised hosts, going beyond standard infostealer functionality by treating infected machines as sellable inventory. (src: The Hacker News)
- RepoGhost hijacks 52 GitHub repositories with malicious code. Fake AI, crypto, and exploit tools were convincing enough that developers voluntarily executed the infected packages, allowing the campaign to compromise dozens of repositories. (src: SecurityLab.ru)
- Dropbox accounts compromised via Lenovo email verification flaw. Over 5,000 Dropbox users were notified of account compromise after attackers exploited a bug in Lenovo's email verification process and a legacy Lenovo ID–Dropbox integration. First reported 2026-09-02 by BleepingComputer. (src: Xakep)
- Additional ICS advisories — Rockwell, Tycon, Schneider. Rockwell Automation ArmorStart LT has webserver availability and XSS vulnerabilities; the 1756-ENBT module can be crashed via a DoS flaw requiring manual restart; Tycon Systems TPDIN-Monitor-WEB3 is vulnerable to MitM attacks, factory resets, and credential theft; and Schneider Electric issued Update A for Easergy, EcoStruxure, PowerLogic, and Saitel products. (src: CISA — ArmorStart) · (src: CISA — 1756-ENBT) · (src: CISA — Tycon) · (src: CISA — Schneider)
- MSRC updates CVE-2026-58641 .NET Elevation of Privilege affected software. Microsoft added SkiaSharp 4.151.2 to the affected software table for this .NET EoP vulnerability, expanding the scope of potentially impacted components. (src: MSRC)
- Chinese group hijacks government websites for SEO reputation laundering. Visitors saw familiar government domains, but content was covertly controlled by a Chinese threat actor leveraging the sites' trusted reputation to boost malicious SEO infrastructure. (src: SecurityLab.ru)
- CISA and G7 release post-quantum cryptography call to action. A joint publication highlights the urgent need for organizations and governments to begin transitioning to post-quantum cryptographic standards. (src: CISA)
Themes
- ICS patching wave: Six ICS advisories from CISA in a single day span RCE, privilege escalation, DoS, and MitM across Rockwell, IXON, OPC Foundation, Tycon, Schneider, and Inductive Automation — a broad reminder that OT/ICS patch cycles lag IT and require dedicated attention.
- Supply-chain and platform trust abuse: RepoGhost (fake GitHub tooling), BraZetsu (commodified host access), and the Chinese SEO hijack of government sites all exploit trust in established platforms — developers, users, and visitors assume legitimacy where none exists.
- AI service disruptions: Both ChatGPT and Anthropic's Claude experienced major outages today, a relevant operational dependency for organisations integrating AI services into production workflows. (src: BleepingComputer — ChatGPT) · (src: BleepingComputer — Claude)
