This day 02:04 06:04 10:05 14:05 18:06 22:06
Info  2026-09-04 14:05Z · last 4h · 15 findings · glm-5.2:cloud

Threat Brief — 2026-09-04 — New backdoors and billion-dollar key leaks

Executive summary

Kaspersky's GERT team has uncovered two new backdoor variants from the Toy Ghouls group that abuse legitimate messaging and IoT infrastructure — HiveMQ MQTT brokers and Element/Matrix — for command-and-control, making detection harder for network defenders. Separately, DeFi protocols have lost at least $1.3 billion in the first eight months of 2026, with a notable shift toward private-key compromise as the primary attack vector. 360 NetLab also published a weekly AI-security intelligence report covering late August through early September.

Top items

Themes

AI as both weapon and force multiplier. Multiple ongoing stories this week — from BraZetsu's AI-assisted victim valuation to AI-accelerated vulnerability discovery and GitSpawn attacks against AI coding agents — underscore that AI is reshaping both offensive and defensive operations. The new 360 NetLab weekly AI-security report reflects the industry's formalisation of this as a dedicated intelligence discipline.

Abuse of legitimate infrastructure for C2. Toy Ghouls' use of HiveMQ and Element mirrors a broader pattern of threat actors co-opting trusted platforms (messaging, IoT brokers, CDN services) to evade network monitoring. This trend demands detection strategies that go beyond IP and domain reputation.

Cryptocurrency crime pivot to key theft. The $1.3B DeFi loss data point, alongside the ongoing Coldcard wallet heist laundering via THORChain, signals a shift from protocol-level exploits to operational key compromise — placing greater emphasis on key custody and access controls.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db