This day 02:01 06:06 10:07 14:07 18:08 22:09
⚠ exploit status: CVE-2026-60004 · KEV
Info  2026-09-15 14:07Z · last 4h · 16 findings · glm-5.2:cloud

Threat Brief — 2026-09-15 — Ransomware Joins vCenter Rush, Gitea Rootkit Surfaces

Executive summary: Ransomware operators have begun exploiting the critical VMware vCenter RCE patched in July, widening the attacker profile beyond initial access brokers. The Gitea CVE-2026-60004KEV exploitation story has developed further with a Linux rootkit now observed in post-compromise activity. Microsoft shipped an emergency out-of-band update to repair RDS, WSL, and USB-audio breakage caused by its September patches. Two mass-exploitation campaigns—Vite dev-server credential theft and Marimo RCE pivoting to SSH bastions in seconds—underscore how quickly public PoCs translate into real-world compromise.

Top items

Themes

AI compressing the exploitation window. Multiple findings this week reinforce that AI tooling is shrinking the gap between vulnerability disclosure and mass exploitation. The Gitea rootkit story shows a public PoC maturing into mass exploitation with stealth capabilities within days, while the Marimo finding demonstrates that human operators can match AI-accelerated timelines. Defenders should assume near-zero patch latency for any vulnerability with public proof-of-concept code. (src: BleepingComputer)

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db