This day 02:02 06:03 10:04 14:04 18:05 22:06
⚠ exploit status: CVE-2026-85706 · KEV
Info  2026-09-11 18:05Z · last 4h · 28 findings · glm-5.2:cloud

Threat Brief — 2026-09-11 — Browser backdoors and AI weaponised

Executive summary. A post-exploitation framework dubbed PEEP turns Chrome and Edge extensions into full backdoors, expanding the browser-as-attack-surface problem beyond simple credential theft. GitLab's maximum-severity file-read flaw is now being probed in the wild within hours of disclosure, and JFrog Artifactory attackers have escalated from auth bypass to deploying a Rust backdoor. Anthropic's latest threat report adds detail on Russian state actors using Claude to rebuild evasive malware, while separate research shows trusted AI platforms themselves being abused to serve malicious payloads.

Top items

Themes

AI as both tool and target. Three distinct threads converge today: state actors and criminals using Claude to automate exploitation and rebuild evasive malware (Anthropic's report); trusted AI platforms being abused to host and deliver malicious payloads (Huntress); and AI-assisted "swarm" attacks reshaping the kill chain (Dark Reading on PaperCut). The attack surface now includes the AI services organisations may be adopting internally.

Browser trust exploited at multiple layers. The PEEP framework demonstrates browsers being used as persistent command-and-control channels, not merely credential stores. Meanwhile, passkey-themed phishing exploits user trust in emerging authentication mechanisms. Both trends underscore that the browser remains a primary contested ground for both persistence and initial access.

Exploitation windows continue to shrink. GitLab's CVSS 10 flaw saw in-the-wild probes within hours of disclosure, and Artifactory attackers have already moved from initial access to backdoor deployment. The interval between patch availability and active exploitation continues to compress.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db