This day 02:03 06:03 10:04 14:04 18:05 22:05
Info  2026-09-25 22:05Z · last 4h · 30 findings · glm-5.2:cloud

Threat Brief — 2026-09-25 — Rivals hack ransomware gangs

Executive summary: The most actionable new item is a CSRF flaw in the Elementor WordPress plugin that lets unauthenticated attackers create administrator accounts. On the threat-actor front, ShinyHunters' breach of the Clop ransomware leak site has been confirmed by Clop itself, with the attack vector now identified as an unpatched Grav CMS unauthenticated path traversal — Clop has since relocated to a new Tor address. Two Microsoft Office CVEs were belatedly published as informational notices for patches already shipped in July and August. Geopolitically, Poland formalised a civilian-military cyber reserve (CyberLEGION), and OpenAI is providing advanced models and support to Ukrainian defenders.

Top items

Themes

Threat-actor-on-threat-actor activity. The ShinyHunters/Clop development is the latest example of cybercriminals targeting each other's infrastructure. Clop's own leak site was compromised through the same class of unpatched CMS vulnerability that ransomware gangs routinely exploit in their victims, a symmetry worth noting for defenders who track attacker infrastructure.

AI in active conflict and red-teaming. Both the OpenAI/Daybreak and Google AI-hacker deployments (the latter already reported) signal that AI-driven offensive tooling is moving from research into real-world use against live infrastructure, with nation-state-level provisioning to active conflict zones.

National cyber-reserve formalisation. Poland's CyberLEGION joins a growing pattern of states building structured civilian cyber-defence programmes, blurring the line between military and civilian hacker communities.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db