SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefFriday, September 04, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Critical Cisco Nexus Root RCE Flaw Actively Threatens | CRITICAL |
|
5 C2 IPs | 4 OTX IOCs | 32 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by critical remote code execution vulnerabilities in Cisco Nexus 9000 switches and HPE ArubaOS-CX network operating systems. Additionally, active exploitation of WordPress plugins (Elementor Pro and a migration plugin) and the deployment of Pegasus zero-click spyware against Serbian activists emphasize the diverse nature of current threats. Organizations must also defend against novel phishing tactics, such as ASCII smuggling, and supply chain compromises targeting developer infrastructure like Coder. |
|
■ CRITICAL STORIES Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root This vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges on Silicon One-based Cisco Nexus 9000 switches, posing an immediate threat to enterprise network infrastructure. |
Critical Elementor Pro flaw exploited to take over WordPress sites Attackers are actively exploiting CVE-2026-32475 in the widely used Elementor Pro plugin to upload webshells and execute arbitrary commands, leading to complete site compromise. |
Coder's registry infrastructure compromised to push malicious modules Attackers compromised Coder's Cloudflare-managed infrastructure to inject unauthorized registry servers, delivering malicious Terraform modules designed to steal developer credentials. |
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone Citizen Lab confirmed a zero-click iMessage exploit was used to deploy NSO Group's Pegasus spyware against Serbian political opposition and activists, highlighting highly targeted state-sponsored surveillance. |
|
■ CVEs IDENTIFIED CVE-2026-32475 Elementor Pro (WordPress Plugin) — Remote Code Execution / Webshell Upload |
CVE-2026-19949 WordPress Migration Plugin — SQL Injection / Remote Code Execution |
[CVE-TBD-1] Cisco Nexus 9000 Series Switches (Silicon One-based) — Unauthenticated Remote Code Execution as Root |
[CVE-TBD-2] HPE ArubaOS-CX — Remote Code Execution |
|
■ THREAT ACTORS NSO Group | Commercial Spyware Vendor |
Deploying Pegasus spyware via zero-click iMessage exploits against Serbian activists |
Shai-Hulud Actor | Cybercriminal / Worm Operator |
Utilizing an updated infostealer worm targeting 469 credential locations across developer environments |
BraZetsu Operator | Cybercriminal |
Distributing Python-based Windows malware to compromise hosts for illicit marketplace inventory |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Active exploitation of CVE-2026-32475 in Elementor Pro and CVE-2026-19949 in WordPress migration plugin |
| T1195.001 | | Supply Chain Compromise: Compromise Software Dependencies and Development Tools | Compromise of Coder's Cloudflare infrastructure to distribute malicious Terraform modules |
| T1566.002 | | Phishing: Spearphishing Link | StreamRat banking Trojan distributed via malicious Meta and TikTok ads; ASCII smuggling used to bypass email filters |
| T1203 | | Exploitation for Client Execution | Pegasus zero-click spyware exploit targeting iMessage on iOS |
| T1539 | | Steal Web Session Information | Infostealers capturing authenticated sessions to bypass MFA |
| T1552 | | Unsecured Credentials | Shai-Hulud infostealer searching 469 locations for developer and cloud credentials |
|
■ PATCH PRIORITY Cisco — Nexus 9000 Switches — Unauthenticated remote code execution as root — [THN] |
HPE — ArubaOS-CX — Critical remote code execution vulnerability — [BC] |
Elementor — Elementor Pro WordPress Plugin (CVE-2026-32475) — Actively exploited RCE and webshell upload — [BC] |
WordPress — Migration Plugin (CVE-2026-19949) — High-severity SQL injection leading to remote code execution — [SW] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch the critical RCE vulnerability in Cisco Nexus 9000 Series switches immediately to prevent unauthenticated root-level code execution. |
| 2 | [P1] Update the Elementor Pro plugin for WordPress to the latest version to remediate CVE-2026-32475 and prevent active webshell exploitation. |
| 3 | [P1] Apply security updates for HPE ArubaOS-CX network operating systems to mitigate the critical remote code execution flaw. |
| 4 | [P1] Update the affected WordPress Migration Plugin to patch CVE-2026-19949 and block SQL injection and RCE vectors. |
| 5 | [P2] Audit all Terraform deployments and verify Coder registry configurations to ensure no unauthorized or malicious modules were pulled during the Cloudflare infrastructure compromise. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |