This briefing covers the 24-hour period from September 13-14, 2026, revealing a critical threat landscape dominated by WordPress plugin vulnerabilities, active ransomware campaigns, and persistent IoT botnet activity. Most alarming is CVE-2026-81648 affecting the CryptoPayment Gateway WordPress plugin with a CVSS score of 10.0, allowing unauthenticated attackers to delete arbitrary files, overwrite configurations, and achieve remote code execution. Multiple high-severity WordPress vulnerabilities (CVE-2026-88793, CVE-2026-85129, CVE-2026-74933) enable unauthenticated XSS injection, posing significant risks to organizations using these plugins.
Ransomware activity remains intense with 11 newly disclosed victims across multiple threat groups including Qilin, Krybit, Barracuda, and ShinyHunters. Notable targets include Kimberly-Clark (issued final warning before data leak) and i2i-systems (described as having "one of the most poorly secured" infrastructures encountered). The Chess.com data breach exposed 4.6 million email addresses obtained through scraping. IoT malware distribution continues unabated with 50+ Mirai and Mozi botnet command-and-control URLs identified, targeting vulnerable IoT devices globally.
Organizational security events include an AT&T retail worker sentenced to 16 months for SIM-swap attacks enabling account takeovers, and Colombia reporting that 60% of cyberattacks target healthcare institutions. The NSA announced a major reorganization creating five mission centers including dedicated cyber and AI units. Delaware enacted updates to its data privacy and breach notification laws, while HHS released an updated Security Risk Assessment tool for healthcare entities.
Multiple critical vulnerabilities identified in WordPress plugins and various software packages, with several enabling unauthenticated remote code execution and arbitrary file operations.
Critical vulnerability in CryptoPayment Gateway WordPress plugin versions 1.2.1-1.2.2 allows unauthenticated users to delete arbitrary files, overwrite payment gateway configuration, and achieve remote code execution via unprotected AJAX endpoints. Immediate patching required.
YouTube Embed WordPress plugin versions 10.0-10.3 vulnerable to stored XSS via unprotected AJAX action relying only on nonce validation. Attackers can inject arbitrary scripts executing on every page load.
Hoo Companion WordPress plugin 1.0.2 lacks authorization checks in import feature, allowing unauthenticated attackers to inject arbitrary web scripts into active theme settings.
GenieWords WordPress plugin versions 1.5.27-1.5.34 allows unauthenticated users to overwrite configuration and inject XSS via unprotected REST API and AJAX actions.
ESPnet before version 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, enabling arbitrary code execution from attacker-supplied checkpoint files.
Spug through version 3.4.0 vulnerable to RCE via ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters.
China-aligned threat actors exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method for Windows, to deploy GrayRabbit backdoor. Targets Windows systems with popular Chinese input method software.
MKVToolNix through version 101.0 contains heap buffer overflow in avilib library's ODML superindex parser. Crafted AVI files with oversized entry counts cause integer wraparound and undersized heap allocation.
SIPp through version 3.7.7 vulnerable to buffer overflow in get_header() function when processing SIP messages with headers exceeding 20,490 bytes. Remote attackers can crash client process.
Nodemailer versions 9.1.0-10.0.4 contain quadratic time complexity vulnerability in addressparser when parsing email addresses with RFC 5322 comments. Can consume excessive CPU and block Node.js event loop.
Eleven organizations added to ransomware leak sites with active extortion, plus a major scraping incident exposing 4.6 million Chess.com user records.
In August 2026, 4.6 million unique email addresses from Chess.com were posted online, obtained via scraping. Data includes usernames, names, countries, and account information. Analysis confirms scraping methodology rather than direct breach.
ShinyHunters ransomware group issued final warning to Kimberly-Clark with deadline of September 16, 2026, threatening data leak and 'several annoying digital problems.' Major consumer goods manufacturer with global operations.
Barracuda ransomware group compromised i2i-systems, describing it as 'one of the most poorly secured companies' encountered. Attackers moved freely across network for a week, citing lack of proper security configurations and IT department negligence.
INCOR Group, Indian real estate and construction company, listed on Doommageddon leak site with deadline of September 20, 2026. Status marked as 'upcoming' data release.
Leading Colombian commercial truck and heavy machinery distributor compromised by Emperador ransomware. Company operates nationwide network providing vehicle sales, parts distribution, and maintenance services.
Gilco Scaffolding added to Qilin ransomware leak site, targeting construction/industrial services sector.
Kashkha, multinational modest fashion brand founded in Dubai with three decades of operations, compromised by Krybit ransomware group.
French healthcare organization CARIDRO VAL DE LOIRE listed on Qilin ransomware leak site.
Widespread IoT botnet activity with 50+ malware distribution URLs identified, primarily Mirai and Mozi variants targeting vulnerable devices globally.
Multiple Mirai botnet command-and-control servers identified distributing malware payloads. URLs targeting IoT devices at 115.202.109.101, 94.244.36.34, 36.69.88.182, and 45.165.186.80 delivering bin.sh and binary payloads.
Extensive Mozi botnet activity with 30+ unique distribution URLs targeting MIPS and ARM-based IoT devices. Primary source IPs located in China and Colombia. Payloads include 32-bit ELF binaries for MIPS and ARM architectures.
China-aligned espionage group leveraging CVE-2026-51990 vulnerability in Tencent Sogou Input Method to deploy GrayRabbit backdoor on Windows systems. Targets organizations using popular Chinese language input software.
Insider threat prosecution and active ransomware groups conducting extortion campaigns against multiple sectors including healthcare, manufacturing, and technology.
Kenneth Carter, 44-year-old former AT&T retail worker in Portland, Oregon, sentenced to 16 months federal prison for using system access to hijack customers' phone numbers enabling cybercriminals to conduct account takeovers and financial fraud.
ShinyHunters ransomware group issued final warning to Fortune 500 company Kimberly-Clark with September 16 deadline, threatening data leak and unspecified 'digital problems.' Represents high-profile target in consumer goods sector.
Qilin ransomware group actively extorting victims in healthcare (CARIDRO VAL DE LOIRE) and construction (Gilco Scaffolding) sectors, demonstrating continued focus on critical infrastructure targets.
Significant organizational changes at NSA and regulatory updates in Delaware affecting data privacy and breach notification requirements.
Delaware Governor signed HB 380 and HB 381 on September 2, 2026. HB 380 amends Delaware Personal Data Privacy Act (effective January 1, 2025), while HB 381 amends computer security breach notification requirements. Organizations must review compliance obligations.
Six in 10 cyberattacks in Colombia target healthcare institutions according to Biofile report based on IBM X-Force Index analysis. Highlights growing exposure of hospitals and clinics to digital threats in Latin America.
National Security Agency conducting thorough reorganization creating five mission centers, including dedicated cyber and AI units. Represents largest structural change at world's largest electronic intelligence agency.
Department of Health and Human Services Office for Civil Rights and ONC released version 3.7 of Security Risk Assessment Tool for healthcare entities to assess HIPAA Security Rule compliance.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.