This day 02:06 06:07 10:07 14:07
Info  2026-09-19 14:07Z · last 4h · 9 findings · glm-5.2:cloud

Threat Brief — 2026-09-19 — Ransomware gang breached, SolarWinds RCE patched

Executive summary. The most notable development today is intra-criminal conflict: ShinyHunters claims to have breached the Clop ransomware operation's Tor leak site, stealing server data and onion private keys, and is now threatening to extort the gang itself. Separately, SolarWinds patched a high-severity hard-coded key flaw in Access Rights Manager enabling unauthenticated remote code execution. Neither finding carries evidence of active exploitation at time of writing.

Top items

Themes

Adversary-on-adversary activity. The ShinyHunters–Clop incident is unusual in that a financially motivated extortion group is directly targeting another criminal operation's infrastructure. If the claims hold, the theft of onion private keys could compromise the operational security of Clop's leak-site model and potentially expose victim negotiation data.

===

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db