This day 02:02 06:03 10:04 14:04 18:05 22:06
⚠ exploit status: CVE-2026-82329 · KEV CVE-2026-20079 · KEV
Info  2026-09-11 10:04Z · last 4h · 29 findings · glm-5.2:cloud

Threat Brief — 2026-09-11: VPNs and build pipelines in the crosshairs

Executive Summary

Today's most significant developments centre on actively exploited infrastructure flaws. Cisco FMC CVE-2026-20079KEV — already in CISA KEV — is now confirmed to be leveraged by three distinct threat clusters including Qilin ransomware operators. PaperCut has replaced interim emergency patches with a proper maintenance release for its two actively exploited flaws. Two new Chromium V8 vulnerabilities were disclosed via MSRC, and the Trezor phishing campaign has been attributed to the Brevo breach with confirmed scale of 347,000 targeted users.

Top Items

Themes

Infrastructure as the entry point. Cisco FMC, JFrog Artifactory, and (still tracked) Check Point VPN all illustrate attackers targeting management interfaces and build-pipeline infrastructure rather than endpoints. The consistent pattern is unauthenticated or auth-bypass flaws in perimeter and DevOps tooling as the preferred initial foothold — these systems sit on the network edge, often with privileged access, and their compromise cascades downstream.

Social engineering adapting to modern auth. The Trezor/Brevo phishing campaign and the passkey-abusing vishing both show attackers evolving techniques to weaponise modern authentication mechanisms — including passkeys and MFA — rather than defeating them cryptographically. The attack surface is shifting from the credential itself to the recovery and enrolment flows around it.

===

THREAT-TOPICS===

[{"slug":"cisco-secure-fmc-cve-2026-20079KEV-auth-bypass-active-exploitation","headline":"Cisco FMC exploitation linked to Qilin ransomware and three threat clusters","findingIds":[11626],"status":"developing","development":"Three distinct threat clusters identified including Qilin ransomware deployment; CVE-2026-20079KEV confirmed in CISA KEV"},{"slug":"papercut-ng-mf-zero-day-actively-exploited","headline":"PaperCut replaces emergency patches with proper maintenance release","findingIds":[11625],"status":"developing","development":"Security maintenance release replaces all previously published emergency patches for two actively exploited flaws"},{"slug":"chromium-v8-cve-2025-1920-2025-2137","headline":"Two Chromium V8 vulnerabilities disclosed via MSRC","findingIds":[11620,11619],"status":"new","development":""},{"slug":"trezor-shipmonk-breach-expands-us-customer-data","headline":"Trezor phishing attributed to Brevo breach with 347K targeted users","findingIds":[11627],"status":"developing","development":"Phishing attributed to Brevo breach; 347,000 emails targeted, 2,500 users clicked malicious link"},{"slug":"jfrog-artifactory-cve-2026-82329KEV-exploited","headline":"Wiz details JFrog Artifactory flaw chaining for admin takeover and backdoors","findingIds":[11623],"status":"developing","development":"Wiz publishes full attack-chain analysis showing how two chained flaws achieve admin control and backdoor deployment"},{"slug":"fake-it-call-vishing-executive-extortion","headline":"Fake IT vishing evolves to abuse passkeys for M365 persistence","findingIds":[11616],"status":"developing","development":"Passkeys identified as new phishing pretext; attackers register own MFA after victim login"},{"slug":"gta-vi-malware-lure-russian-users","headline":"GTA VI installer delivers password-stealing trojans to Russian users","findingIds":[11632],"status":"new","development":""},{"slug":"hacking-cat-hacktivist-toolkit-analysis","headline":"Securelist analyses Hacking Cat group toolkit and partnerships","findingIds":[11628],"status":"new","development":""},{"slug":"conti-ransomware-member-sentenced","headline":"Conti ransomware member sentenced to four years in prison","findingIds":[11618],"status":"new","development":""},{"slug":"microsoft-teams-outlook-arm-windows-fix","headline":"Microsoft fixes Teams and Outlook launch failures on ARM Windows","findingIds":[11634],"status":"new","development":""}]

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db