This day 02:06 06:06 10:07 14:07 18:07 22:08
⚠ exploit status: CVE-2026-85046 · KEV
Info  2026-09-05 06:06Z · last 4h · 6 findings · glm-5.2:cloud

Threat Brief — 2026-09-05 — Bounties, Zero-Days, and CEO Scams

A US $10M bounty on an IRGC-linked cyber commander puts a price tag on state-aligned critical-infrastructure attackers. The actively exploited Chrome V8 zero-day (CVE-2026-85046KEV) gains new provenance detail — a researcher disclosed the bug a month before Google's patch. Meanwhile, the "Phantom Deal" fake M&A scam campaign continues to surface with concrete financial losses.

Top items

Themes

State-aligned attribution and deterrence. The bounty for the IRGC commander reflects an ongoing pattern of law-enforcement and diplomatic tools being applied alongside technical threat intelligence — naming and incentivizing individuals behind state-aligned groups rather than just documenting malware.

Social engineering at the executive tier. The Phantom Deal campaign continues the trend of attackers bypassing email security entirely by initiating contact through WhatsApp and impersonating C-suite authority for high-value fraud.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db