Daily Cyber Threat Intel Brief — 2026-09-04
Generated: 2026-09-04 08:00:45 UTC
Executive summary
Priority technology watch items
- A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]
- Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: NeoGen Corporation. Description excerpt: Over 5 million Salesforce records compromised containing some PII and 541GB+ of Sharepoint internal corporate data was…
- This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
- Updated an acknowledgement. This is an informational change only.
- Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
- Public RansomLook extortion-site listing claim. Group: space bears. Claimed victim/listing: Schwartz, Giannini, Lantsberger & Adamson (SGLA). Description excerpt: Schwartz, Giannini, Lantsberger & Adamson (SGLA) Accountancy Corporation is a full-service…
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-32475` | Critical Elementor Pro flaw exploited to take over WordPress sites | BleepingComputer Ransomware News |
| cve | `CVE-2026-84326` | Chromium: CVE-2026-84326 Uninitialized resource in V8 | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62815` | CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-70352` | CVE-2026-70352 Azure AI Language Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84358` | Chromium: CVE-2026-84358 Improper privilege management in Downloads | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84355` | Chromium: CVE-2026-84355 Incorrect authorization in Navigation | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84354` | Chromium: CVE-2026-84354 Incorrect authorization in FileSystem | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84353` | Chromium: CVE-2026-84353 Use after free in Shared Tab Groups | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84351` | Chromium: CVE-2026-84351 Buffer overflow in GPU | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84350` | Chromium: CVE-2026-84350 Use after free in TabStrip | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84349` | Chromium: CVE-2026-84349 Use after free in Browser | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84348` | Chromium: CVE-2026-84348 Information leak in MediaCapture | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84347` | Chromium: CVE-2026-84347 Use after free in WebRTC | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84335` | Chromium: CVE-2026-84335 Incorrect authorization in TabStrip | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84334` | Chromium: CVE-2026-84334 Incorrect authorization in Chromoting | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84332` | Chromium: CVE-2026-84332 Incorrect authorization in SiteSettings | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84331` | Chromium: CVE-2026-84331 Incorrect authorization in Actor | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84329` | Chromium: CVE-2026-84329 Confused deputy in CredentialProvider | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84328` | Chromium: CVE-2026-84328 Missing authorization in FileSystem | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84327` | Chromium: CVE-2026-84327 Incorrect authorization in Autofill | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84325` | Chromium: CVE-2026-84325 Improper input validation in DataTransfer | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84324` | Chromium: CVE-2026-84324 Use after free in Proxy | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84323` | Chromium: CVE-2026-84323 Missing authorization in FileSystem | Microsoft Security Response Center RSS |
| cve | `CVE-2026-58641` | CVE-2026-58641 .NET Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62906` | CVE-2026-62906 Microsoft Discovery Studio Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-70178` | CVE-2026-70178 Microsoft Fabric Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-80098` | CVE-2026-80098 Copilot Studio Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-83711` | CVE-2026-83711 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| ipv4 | `176.65.139.206` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |