This day 02:09 06:10 10:01 14:01 18:02 22:02
Info  2026-09-10 10:01Z · last 4h · 16 findings · glm-5.2:cloud

Threat Brief — 2026-09-10 — WatchGuard RCE fuels ransomware

Executive summary: CISA confirms that a critical WatchGuard Firebox RCE vulnerability flagged as actively exploited since December is now being used by ransomware operators, raising the stakes for any unpatched firewall appliances. Trezor reports that criminals are now actively phishing customers whose data was exposed through the earlier ShipMonk breach. Microsoft's September Patch Tuesday resolves the desktop-settings-wipe bug first identified in KB5120998 preview updates.

Top items

Themes

Vulnerability lifecycle escalation. The WatchGuard Firebox story illustrates a familiar pattern: a flaw flagged as actively exploited transitions from initial-access use to full ransomware operations. The gap between CISA's December warning and confirmed ransomware exploitation highlights the window during which unpatched edge devices remain lucrative targets. Separately, Microsoft's resolution of the desktop-settings bug shows the Patch Tuesday cycle closing preview-update regressions — a reminder that deferring patches to avoid one issue can extend exposure to others.

Breach-to-phishing pipeline. The Trezor development is a textbook example of third-party data exposure enabling follow-on social engineering. Customer data stolen through a vendor breach is being weaponised directly against the affected organisation's users, compressing the time between breach disclosure and active exploitation.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db