Threat Brief — 2026-09-04 — Mass exploitation scales up
Executive summary: Attack volume against WordPress plugin vulnerabilities has surged to 440,000+ documented exploit attempts, with a second plugin (Super Forms) now confirmed in the same campaign alongside the previously reported Elementor Pro flaw. OpenAI officially launched GPT‑6 Astra, which scored 100% on the ExploitBench benchmark — a signal that autonomous exploit generation capability continues to mature, even as the vendor attempts to gate proof-of-concept requests.
Top items
- WordPress plugin exploitation now at 440,000+ attempts — Super Forms CVE‑2026‑14894 added to the campaign. Wordfence reports that threat actors are now exploiting two critical WordPress plugin flaws in tandem: the previously covered Elementor Pro vulnerability (CVE‑2026‑32475) and a newly surfaced Super Forms flaw (CVE‑2026‑14894, CVSS 9.8, missing file validation enabling arbitrary file upload/RCE). The scale of exploitation — over 440,000 attempts — represents a significant escalation from the initial disclosure. This story was first reported 2026‑09‑03 by BleepingComputer covering Elementor Pro exploitation; the new development is the confirmed attack volume and the addition of Super Forms as a second target. (src: The Hacker News, SecurityLab)
- GPT‑6 Astra officially unveiled; scores 100% on ExploitBench. OpenAI formally launched GPT‑6 Astra, claiming it is their most aligned model. The model achieved a perfect score on the ExploitBench benchmark, which tests autonomous vulnerability discovery and exploit writing. OpenAI states it is blocking PoC exploit generation requests, but the benchmark result demonstrates that frontier AI models can now reliably produce working exploits when permitted. This story was first reported 2026‑09‑02 by SecurityLab regarding Astra's zero-day discovery capabilities; the new development is the official product launch and the published 100% ExploitBench result. (src: The Hacker News)
Themes
AI as both weapon and shield. Two threads are converging: GPT‑6 Astra's perfect ExploitBench score demonstrates offensive AI maturity, while the previously reported GuardBreaker technique (UAC‑0099 embedding nuclear-weapon prompts in malware to trip AI safety filters) shows adversaries actively adapting malware to evade AI-assisted analysis. The arms race between AI-powered defence and AI-aware offence is intensifying on both sides.
===
