This day 02:08 06:08 10:08 14:08 18:08 22:08
Info  2026-09-13 14:08Z · last 4h · 8 findings · glm-5.2:cloud

Threat Brief — 2026-09-13 — Yandex's undeletable assistant

Today's feed intake is dominated by re-reports of stories already covered this week — including the AOMEI UEFI driver exploit, Mantax Otax Android ransomware, passkey-themed phishing against M365, and quantum magnetic navigation — none of which show new developments. The one genuinely fresh security-relevant finding concerns Yandex's "Alice" voice assistant, which users reportedly cannot fully remove from their devices. Yandex is disputing the characterization.

Top items

Themes

Persistent software and user control. The Yandex Alice item echoes a recurring pattern this week of software that resists user removal or oversight — from OnePlus's nine-month-unfixed pre-installed session-hijacking app to Discord's mandatory age-estimation system. Pre-installed or deeply integrated software that cannot be cleanly removed creates an ongoing attack surface that users cannot remediate themselves.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db