Daily Cyber Threat Intel Brief — 2026-09-16
Generated: 2026-09-16 08:00:43 UTC
Executive summary
Priority technology watch items
- Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]
- Overview On September 14, 2026, Cisco published a security advisory for CVE-2026-76461 , a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and…
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]
- Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Community Property Management. Description excerpt: full data 200 GB+ We have been in business since 1978 as a management firm specializing in the management of common…
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Owen Leigh Optometry. Description excerpt: Full DATA 400 GB+ The brain uses the eyes to gather information about our surroundings. The brain cannot process all our…
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-76461` | CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild | Rapid7 Blog |
| cve | `CVE-2026-78517` | CVE-2026-78517 Microsoft Office Word Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-73006` | CVE-2026-73006 DirectWrite Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-68812` | CVE-2026-68812 Microsoft Excel Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69486` | CVE-2026-69486 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-68824` | CVE-2026-68824 Connected User Experiences and Telemetry Elevation of Privilege Vulnerabili | Microsoft Security Response Center RSS |
| cve | `CVE-2026-68841` | CVE-2026-68841 Windows NTFS Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-68847` | CVE-2026-68847 Connected User Experiences and Telemetry Elevation of Privilege Vulnerabili | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69406` | CVE-2026-69406 Windows Kernel Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69608` | CVE-2026-69608 Microsoft Windows Search Component Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69605` | CVE-2026-69605 Microsoft Install Service Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-80075` | CVE-2026-80075 Windows Work Folders Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69286` | CVE-2026-69286 Windows USB Audio Class Driver Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69321` | CVE-2026-69321 Windows Power Dependency Coordinator Tampering Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69416` | CVE-2026-69416 Windows DHCP Server Denial of Service Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69619` | CVE-2026-69619 Windows exFAT File System Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69714` | CVE-2026-69714 Windows Device Association Service Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-61923` | CVE-2026-61923 Windows Display Enhancement Service Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62753` | CVE-2026-62753 Windows HTTP.sys Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62772` | CVE-2026-62772 Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Pri | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62717` | CVE-2026-62717 Windows Message Queuing Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-80097` | CVE-2026-80097 Microsoft Authenticator Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69559` | CVE-2026-69559 Microsoft Teams for Android Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65812` | CVE-2026-65812 Microsoft Teams for Android Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-85893` | CVE-2026-85893 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| ipv4 | `86.122.231.80` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| ipv4 | `5.182.210.61` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| ipv4 | `5.182.210.174` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| ipv4 | `213.232.114.14` | URLhaus: malware_download URL observed (online) | URLhaus Recent URLs |