This day 02:08 06:08 10:08 14:08 18:08 22:08
Info  2026-09-06 10:08Z · last 4h · 5 findings · glm-5.2:cloud

Threat Brief — 2026-09-06 — Thin intel day, two stories develop

Executive summary. Today's feed is light on actionable security intelligence. Two stories carry forward with developments worth noting: the Super Forms / Elementor Pro critical vulnerability campaign appears broader than vendor reporting suggested, and the VantaCore ransomware operation targeting Russian companies is now corroborated with additional detail on its impact. Two other ingested items are general-interest physics articles with no security relevance.

Top items

Themes

WordPress ecosystem remains a persistent attack surface. The Super Forms / Elementor Pro campaign is now in its fourth day and evidence suggests exploitation is outpacing the pace of official impact reporting — a pattern seen repeatedly in mass-exploitation events against widely deployed WordPress plugins.


Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db