SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSaturday, September 05, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
| THREAT OF THE DAY Critical RCEs Actively Exploited | CRITICAL |
| 5 C2 IPs | 89 OTX IOCs | 33 ARTICLES |
| ■ ANALYST TLDR Multiple critical vulnerabilities are under active exploitation, including RCE flaws in HPE AOS-CX, Citrix NetScaler, Sangoma Switchvox, and WordPress plugins, alongside a Google Chrome zero-day. Organizations face significant risk from these exploited flaws, large-scale data breaches affecting identity verification services, and sophisticated phishing campaigns leveraging unicode evasion. Proactive patching and enhanced detection are paramount. |
| ■ CRITICAL STORIES HPE, Citrix, Sangoma, WordPress RCEs Exploited In The Wild Multiple critical RCE and authentication bypass vulnerabilities across HPE AOS-CX (CVE-2026-73749), Citrix NetScaler (CVE-2026-19490), Sangoma Switchvox (CVE-2026-9586), and WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro are being actively exploited. These flaws allow for remote code execution or authentication bypass, posing an immediate and severe threat to affected systems. |
Google Chrome Zero-Day Actively Exploited (CVE-2026-85046) Google has patched a high-severity zero-day vulnerability (CVE-2026-85046) in the Chrome V8 engine that is under active exploitation. This marks the 6th Chrome zero-day patched this year, highlighting the persistent threat of browser-based attacks. |
IDScan Sued Over Alleged Data Breach Affecting 153 Million Drivers Identity verification company IDScan is facing lawsuits following an alleged data breach that compromised over 153 million driver's licenses. This incident underscores the severe impact of breaches on identity-related services and the vast amount of sensitive data at risk. |
Phishing Campaign Uses Invisible Unicode to Evade Filters A high-volume phishing campaign is leveraging invisible Unicode tag characters to bypass Microsoft email filters. This sophisticated evasion technique allows malicious emails to reach inboxes, increasing the risk of credential theft and malware delivery. |
| ■ CVEs IDENTIFIED CVE-2026-73749 HPE AOS-CX — RCE Vulnerabilities |
CVE-2026-19490 Citrix NetScaler — Authentication Bypass (exploited in the wild) |
CVE-2026-6471 PostgreSQL — Logical Decoding Flaw, Replication-Role Code Execution |
CVE-2026-9586 Sangoma Switchvox — Unauthenticated SQL Injection, RCE (exploited in the wild) |
|
■ THREAT ACTORS Nightmare Eclipse | Security Researcher |
Released CrowdStrike Falcon zero-day exploit |
Amir Yaryab | Iranian Cyber Unit Leader |
Oversees IRGC's cyber unit and CyberAv3ngers |
IRGC's cyber unit | State-Sponsored |
Cyberattacks on critical infrastructure |
|
|
| ■ ATT&CK TTPs | T1566.001 | | Spearphishing Attachment | Phishing campaign using invisible Unicode to evade filters |
| T1036.002 | | Masquerading: Spoofing Name/Location | Invisible Unicode characters in phishing emails |
| T1190 | | Exploit Public-Facing Application | Exploitation of HPE AOS-CX, Citrix NetScaler, Sangoma Switchvox, WordPress Super Forms/Elementor Pro RCEs |
| T1078 | | Valid Accounts | Citrix NetScaler auth bypass, Dropbox account compromises, X password reset attacks, IDScan data breach |
| T1068 | | Exploitation for Privilege Escalation | CrowdStrike Falcon zero-day, PostgreSQL RCE, VMware Workstation/Fusion RCE |
| T1203 | | Exploitation for Client Execution | Google Chrome zero-day (V8 engine) |
|
■ PATCH PRIORITY HPE AOS-CX — RCE, actively exploited — SW |
Citrix NetScaler — Auth Bypass, actively exploited — BC |
Sangoma Switchvox — RCE, actively exploited — SW |
WordPress Super Forms — RCE, actively exploited — THN |
|
|
| ■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately patch HPE AOS-CX to address CVE-2026-73749, Citrix NetScaler for CVE-2026-19490, Sangoma Switchvox for CVE-2026-9586, and WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro due to active exploitation. |
| 2 | [P1] Update Google Chrome to the latest version to mitigate CVE-2026-85046 and other critical vulnerabilities, ensuring browser security against active zero-day exploits. |
| 3 | [P2] Apply updates for PostgreSQL (CVE-2026-6471) and VMware Workstation/Fusion to prevent privilege escalation and host compromise from virtual machines. |
| 4 | [P2] Review and strengthen email security configurations to detect and block sophisticated phishing campaigns, specifically those leveraging Unicode character evasion as reported by Microsoft. |
| 5 | [P3] Audit and secure all systems handling sensitive identity data, such as IDScan, to prevent large-scale data breaches, focusing on robust access controls, encryption, and continuous monitoring. |
|
| | C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
| FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
| IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |
|