Threat Brief — 2026-09-25 — Rivals hack ransomware gangs
Executive summary: The most actionable new item is a CSRF flaw in the Elementor WordPress plugin that lets unauthenticated attackers create administrator accounts. On the threat-actor front, ShinyHunters' breach of the Clop ransomware leak site has been confirmed by Clop itself, with the attack vector now identified as an unpatched Grav CMS unauthenticated path traversal — Clop has since relocated to a new Tor address. Two Microsoft Office CVEs were belatedly published as informational notices for patches already shipped in July and August. Geopolitically, Poland formalised a civilian-military cyber reserve (CyberLEGION), and OpenAI is providing advanced models and support to Ukrainian defenders.
Top items
- Elementor WordPress plugin CSRF enables admin account creation. A cross-site request forgery vulnerability in the Elementor plugin for WordPress allows an unauthenticated attacker to forge requests that create administrator-level accounts. WordPress sites running Elementor should treat this as a priority patch; admin account creation gives full site compromise. (src: BleepingComputer)
- ShinyHunters breached Clop leak site via unpatched Grav CMS path traversal; Clop relocates to new Tor address. First reported 2026-09-19 by BleepingComputer. The new development: Clop has confirmed its previous server was compromised and defaced, and the attack vector has been identified as an unauthenticated path traversal in Grav CMS. Clop has moved its leak site to a new Tor address. The Grav CMS flaw underscores that threat actors' own infrastructure is often exposed to the same unpatched-vulnerability risk as their victims. (src: BleepingComputer)
- U.S. Army soldier sentenced to 70 months for AT&T and Verizon breaches. The soldier pleaded guilty to hacking telecommunications companies and stealing call and text metadata for more than 100 million AT&T customers in 2024. The sentencing closes a case involving large-scale metadata theft from major U.S. carriers. (src: KrebsOnSecurity)
- Microsoft belatedly discloses Outlook RCE CVE-2026-100208 and Office information-disclosure CVE-2026-100206. Both CVEs were addressed by updates already released in August and July 2026 respectively, but were inadvertently omitted from the original security update notes. These are informational changes only; patches are already available in the corresponding monthly updates. (src: MSRC — CVE-2026-100208, MSRC — CVE-2026-100206)
- Poland unifies military and civilian hackers into CyberLEGION. The programme now has over 3,500 participants, with Poland's Ministry of Justice joining as a new partner. This represents a continued European trend of formalising civilian cyber-defence capabilities alongside military structures. (src: SecurityLab.ru)
- OpenAI to provide Ukraine with access to Daybreak AI models. Ukrainian defenders will receive advanced models, training, and technical support, marking a notable escalation in the direct provisioning of AI capabilities to an active conflict zone. (src: SecurityLab.ru)
Themes
Threat-actor-on-threat-actor activity. The ShinyHunters/Clop development is the latest example of cybercriminals targeting each other's infrastructure. Clop's own leak site was compromised through the same class of unpatched CMS vulnerability that ransomware gangs routinely exploit in their victims, a symmetry worth noting for defenders who track attacker infrastructure.
AI in active conflict and red-teaming. Both the OpenAI/Daybreak and Google AI-hacker deployments (the latter already reported) signal that AI-driven offensive tooling is moving from research into real-world use against live infrastructure, with nation-state-level provisioning to active conflict zones.
National cyber-reserve formalisation. Poland's CyberLEGION joins a growing pattern of states building structured civilian cyber-defence programmes, blurring the line between military and civilian hacker communities.
