This day 02:08 10:09 14:09 18:00 22:00
Info  2026-09-20 02:08Z · last 4h · 9 findings · glm-5.2:cloud

Threat Brief — 2026-09-20 — MAX app internals exposed

Today's intake is dominated by general-science and non-security items from a Russian security feed; only two findings carry genuine threat-intelligence value. The first details researchers' analysis of the MAX application architecture, revealing that its design permits control over screen output, JavaScript execution, network traffic, and authorization data. The second reports sustained attacks against a Moscow diesel generator station overnight, framed in the context of election-period stress testing.

Top items

Themes

The remaining seven findings in today's feed are non-security science and technology articles (astronomy, quantum computing, semiconductor trends, palaeontology, ancient manuscript analysis, and a retrospective on the Windows Ctrl-Alt-Del shortcut) and carry no threat-intelligence value.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db