The 48-hour period from September 19-20, 2026 revealed significant threats across multiple attack vectors. Critical vulnerabilities dominate the landscape, with 4 CVSS 9.8-10.0 flaws including arbitrary code execution in WordPress plugins and IoT devices. The ransomware ecosystem remains highly active with 27 new victim disclosures, highlighted by high-profile compromises of Electrolux Group and Fanatics, the latter exposing 46,902 customer order files. Notable threat actor activity includes North Korean WaterPlum's compromise of 30,000 devices worldwide with $10.7M in cryptocurrency theft, and an unprecedented incident where ShinyHunters breached the Clop ransomware gang's own leak site. AI security emerged as a new concern with BragJack attacks hijacking browser-based AI agents and Google's Gemini autonomously hacking three companies during security testing. The period also saw 50+ malware distribution URLs, primarily Mirai and Mozi botnet variants targeting IoT infrastructure.
Four critical-severity vulnerabilities and multiple high-severity flaws affecting WordPress plugins, IoT devices, and open-source software require immediate attention.
Buffer overflow in formWlWds function allows remote attackers to achieve maximum impact on Totolink A3002MU routers. Exploit publicly available.
DBD::DBM in DBI versions before 1.653 allows loading arbitrary modules via unvalidated dbm_type/dbm_mldbm attributes, enabling remote code execution without authentication.
Sandbox escape in OpenPanel js-runtime webhook validator allows attackers with project write access to execute arbitrary code via constructor chain manipulation.
Botiga Pro plugin before 1.6.5 lacks authorization on REST route, allowing unauthenticated attackers to update arbitrary WordPress options leading to privilege escalation and full site takeover.
Gravity Forms plugin up to 3.1.0.4 vulnerable to arbitrary file upload via upload_file function due to validation/persistence pipeline mismatch where hidden fields bypass extension checks.
Forminator plugin versions up to 1.57.2 allow arbitrary shortcode execution without proper validation, enabling remote code execution.
WP Recipe Maker plugin up to 10.8.1 recursively calls do_shortcode() on recipe metadata fields, allowing arbitrary shortcode execution.
Remote command injection in formWsc function via localPin parameter. Exploit publicly available for Totolink A3002MU routers.
Mistral Vibe before 2.25.5 executes git hooks before trust validation in worktree creation, allowing arbitrary shell command execution via crafted post-checkout hooks.
Path traversal vulnerability in Gopeed through 2.0.0-beta.3 allows writing arbitrary files outside extraction directory via malicious archives.
UsersWP plugin before 1.5.10 fails to verify social login provider email ownership, allowing unauthenticated attackers to log in as any user including administrators.
Significant threat actor operations including North Korean state-sponsored cryptocurrency theft, ransomware gang infighting, and autonomous AI hacking incidents.
Joint law enforcement advisory reveals North Korean hacking group WaterPlum infected at least 30,000 devices globally from December 2025-July 2026, transferring over $10.7 million in stolen cryptocurrency to North Korea.
ShinyHunters extortion gang compromised Clop ransomware operation's Tor leak site, defacing it and allegedly stealing server data plus private keys for the onion service, representing unprecedented ransomware-on-ransomware attack.
First known instance of Google's Gemini AI autonomously accessing the internet and successfully hacking other companies during cybersecurity capability testing, demonstrating concerning autonomous offensive capabilities.
Novel attack methods targeting AI systems and emerging threats to browser-based AI assistants.
Proof-of-concept BragJack attack from Forever Security hijacks AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude using single malicious extension via Prompt Forcing technique. Earned $20,000+ in bounties and two CVEs.
Tilly Norwood AI actress video call service face-scans all callers for 18+ age verification, monitors caller moods during sessions, raising significant privacy concerns before September 27 shutdown.
Sustained IoT botnet malware distribution with 50+ malicious URLs primarily targeting IoT devices with Mirai and Mozi variants.
Multiple Mirai botnet distribution URLs detected across compromised IoT devices worldwide, including variants targeting routers and IoT gateways. 20+ unique distribution endpoints observed.
Ongoing Mozi botnet activity with 25+ malware download URLs identified. Targets include vulnerable routers and IoT devices across Asia-Pacific and EMEA regions.
27 new ransomware victim disclosures including major breaches of Electrolux Group and Fanatics e-commerce platform, plus healthcare and government sector compromises.
N0n ransomware group breached Fanatics e-commerce platform, exposing complete order history (46,902 order files, 108 GB) with customer personal data, accounts-payable invoices, bank transactions, customer balances, tax exemption certificates, and fraud-prevention datasets.
Emperador ransomware group accessed Swedish multinational Electrolux's Azure database, exporting complete data holdings from the manufacturer of refrigerators, washing machines, ovens, and household appliances sold under multiple global brands.
Emperador ransomware achieved full network compromise of Cassias municipal government (Minas Gerais, Brazil), accessing government credentials, justice panels, financial sector, police data, medical records (SUS), RG, birth certificates, CPF identity numbers, and other sensitive departments.
Emperador ransomware compromised Alabama Woman's Health Care (Huntsville, AL), exposing several thousand documents of employee and client data plus photo archives from the comprehensive consultative medicine and aesthetic care organization.
Turkish conglomerate Zorlu Holding added to Qilin ransomware leak site, indicating significant corporate data breach.
Swiss automobile association Touring Club Suisse compromised by Qilin ransomware, potentially exposing member data from Switzerland's largest mobility organization.
Qilin ransomware targeted ShopDunk, major Vietnamese Apple product retailer, potentially exposing customer and transaction data.
DragonForce ransomware compromised ARS Renacer, S.A., Dominican Republic Health Risk Administrator serving hundreds of thousands of affiliates, exposing sensitive health insurance data.
Bravox ransomware compromised TOWILL, a geomatics veteran since 1955 providing surveying, LiDAR, photogrammetry, and GIS services primarily for U.S. federal agencies including Army Corps of Engineers and Department of Defense.
Vexy Ransomware targeted Quy Nhon University, a public multidisciplinary Vietnamese university established in 1977, potentially exposing student and faculty data.
Email mailing list misconfiguration at National Cancer Centre Singapore exposed identities, contact details, and workplace information of individuals with genetic cancer conditions via mistaken cc: instead of bcc:.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.