Daily Cyber Threat Intel Brief — 2026-09-12
Generated: 2026-09-12 08:00:54 UTC
Executive summary
Priority technology watch items
- This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have…
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
- Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]
- Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: compunnel.com. Description excerpt: The company provides a combination of talent acquisition, IT consulting, digital engineering, artificial intelligence, cybersecurity,…
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Medical Department Store. Description excerpt: Medical Department Store in united state
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2025-54988` | Metasploit Wrap Up: This One Goes to Sixteen! | Rapid7 Blog |
| cve | `CVE-2025-66516` | Metasploit Wrap Up: This One Goes to Sixteen! | Rapid7 Blog |
| cve | `CVE-2026-69461` | CVE-2026-69461 Windows NTFS Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69732` | CVE-2026-69732 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulner | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69860` | CVE-2026-69860 Windows Imaging Component Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-71336` | CVE-2026-71336 Windows Work Folder Service Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-81355` | CVE-2026-81355 Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-73016` | CVE-2026-73016 DirectWrite Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-80080` | CVE-2026-80080 Microsoft Office Word Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-85892` | CVE-2026-85892 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-85051` | Chromium CVE-2026-85051: Type confusion in Compositing | Microsoft Security Response Center RSS |
| cve | `CVE-2026-85049` | Chromium CVE-2026-85049: Use after free in Skia | Microsoft Security Response Center RSS |
| cve | `CVE-2026-85048` | Chromium CVE-2026-85048: Use after free in Compositing | Microsoft Security Response Center RSS |
| cve | `CVE-2026-85045` | Chromium CVE-2026-85045: Race condition in V8 | Microsoft Security Response Center RSS |
| cve | `CVE-2026-85043` | Chromium CVE-2026-85043: Incomplete cleanup in Network | Microsoft Security Response Center RSS |
| cve | `CVE-2026-85042` | Chromium CVE-2026-85042: Use after free in DevTools | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84333` | Chromium: CVE-2026-84333 Use after free in Dawn | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84330` | Chromium: CVE-2026-84330 UI misrepresentation in FullScreen | Microsoft Security Response Center RSS |
| cve | `CVE-2026-84352` | Chromium: CVE-2026-84352 Use after free in WebGL | Microsoft Security Response Center RSS |
| cve | `CVE-2026-77490` | CVE-2026-77490 Microsoft Edge (Chromium-based) Spoofing Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69468` | CVE-2026-69468 Windows Volume Manager Extension Driver Elevation of Privilege Vulnerabilit | Microsoft Security Response Center RSS |
| cve | `CVE-2026-70334` | CVE-2026-70334 Visual Studio Code Security Feature Bypass Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-77499` | CVE-2026-77499 Windows DHCP Server Denial of Service Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-81379` | CVE-2026-81379 Visual Studio Code Security Feature Bypass Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-68894` | CVE-2026-68894 Windows Error Reporting Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69314` | CVE-2026-69314 Windows Device Association Broker Service Elevation of Privilege Vulnerabil | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69405` | CVE-2026-69405 Windows DHCP Server Denial of Service Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-81963` | CVE-2026-81963 Windows Update Stack Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2025-2137` | Chromium: CVE-2025-2137 Out of bounds read in V8 | Microsoft Security Response Center RSS |
| cve | `CVE-2025-1920` | Chromium: CVE-2025-1920 Type Confusion in V8 | Microsoft Security Response Center RSS |