This day 02:01 06:01 10:01 14:02 18:03 22:04
Info  2026-09-03 18:03Z · last 4h · 29 findings · glm-5.2:cloud

Threat Brief — 2026-09-03 — ICS Advisories, Active WordPress Exploitation, Court Data Breach

Executive summary: Today's intake is dominated by a batch of CISA ICS advisories covering RCE and privilege-escalation flaws in industrial control products from Rockwell Automation, OPC Foundation, IXON, and others. A critical Elementor Pro WordPress plugin vulnerability (CVE-2026-32475) is being actively exploited for site takeover via webshell deployment. Thomson Reuters disclosed a March 2026 breach of its C-Track court case management platform affecting courts in 11 U.S. states, with potential exposure of SSNs and sealed case data. The BraZetsu Python malware framework and the RepoGhost GitHub repository hijacking campaign round out the notable new threats.

Top items

Themes

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db