Threat Brief — 2026-09-05 — Bounties, Zero-Days, and CEO Scams
A US $10M bounty on an IRGC-linked cyber commander puts a price tag on state-aligned critical-infrastructure attackers. The actively exploited Chrome V8 zero-day (CVE-2026-85046KEV) gains new provenance detail — a researcher disclosed the bug a month before Google's patch. Meanwhile, the "Phantom Deal" fake M&A scam campaign continues to surface with concrete financial losses.
Top items
- US offers $10M reward for IRGC commander behind CyberAv3ngers. The US government has posted a bounty for Amir Yaryab, identified as controlling CyberAv3ngers and other groups that have attacked critical infrastructure. This is a new development naming a specific individual and linking him to multiple Iranian threat groups. (src: securitylab.ru)
- Chrome V8 zero-day CVE-2026-85046KEV: researcher disclosed bug a month before patch. This actively exploited vulnerability — Google's sixth Chrome zero-day of the year — was reported by researcher Salvatore Gulizia on 4 August, roughly a month before Google's patch. The vulnerability was first reported on 2026-09-04 by The Hacker News; the new detail is the researcher's name and early disclosure date. (src: securitylab.ru)
- "Phantom Deal" fake M&A scam surfaces with €626,735 loss. A campaign using WhatsApp messages impersonating a CEO to lure executives into bogus acquisition deals has resulted in a documented six-figure euro loss for a deal that never existed. First reported 2026-09-03 by Dark Reading; the new detail is the specific financial figure. (src: securitylab.ru)
Themes
State-aligned attribution and deterrence. The bounty for the IRGC commander reflects an ongoing pattern of law-enforcement and diplomatic tools being applied alongside technical threat intelligence — naming and incentivizing individuals behind state-aligned groups rather than just documenting malware.
Social engineering at the executive tier. The Phantom Deal campaign continues the trend of attackers bypassing email security entirely by initiating contact through WhatsApp and impersonating C-suite authority for high-value fraud.
