This day 02:01 06:06 10:07 14:07 18:08 22:09
⚠ exploit status: CVE-2026-85706 · KEV CVE-2026-76461 · KEV
Info  2026-09-15 10:07Z · last 4h · 26 findings · glm-5.2:cloud

Threat Brief — 2026-09-15 — DPRK identity rental and AI's offensive edge

Executive summary

Today's fresh intelligence highlights two developments worth attention: North Korea has refined its IT-worker infiltration scheme into a full "identity rental" operation where the employer, document holder, and actual worker are three different people connected via VPN and Telegram. Separately, accessible AI tooling is demonstrating real-world offensive impact — cracking election anonymity in hours and enabling near-total pentest success rates — while defensive applications like backdoor detection in medical imaging models remain academic. Most of today's high-severity vulnerability stories (GitLab CVE-2026-85706KEV, Cisco Secure Email Gateway CVE-2026-76461KEV, LiteSpeed root escalation) were already reported earlier today and show no new developments.

Top items

Themes

AI as offensive leveller. Three separate findings today illustrate how accessible AI is eroding the skill barrier for offensive operations: near-total pentest success rates, election anonymity broken without privileged access, and observations that "security through obscurity" is losing viability against AI-assisted analysis. The defensive side remains largely academic or organisational (backdoor detection research, NSA restructuring).

DPRK operational maturation. The identity-rental scheme represents a notable evolution in North Korean IT-worker infiltration, moving from individual impostors to a structured three-party logistics model. This complicates vetting because each verification target (documents, online presence, interview) can be satisfied by a different participant.


Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db