- Use-after-free vulnerability in Dawn, previously patched.
- Actively exploited zero-day flaw in Chrome's V8 engine.
- Out-of-bounds read/write in V8 engine, previously exploited.
- Iterator invalidation in CSSFontFeatureValuesMap, previously patched.
- Out-of-bounds write in Skia graphics library, previously exploited.
- Inappropriate implementation in V8 engine, previously exploited.
ThreatNoir Afternoon Brief — September 4
Afternoon Review in IT Security — September 4, 2026
The threat landscape continues to evolve rapidly with critical vulnerabilities emerging across multiple platforms and attack vectors. Today's review highlights urgent patching requirements for widely deployed software, large-scale exploitation campaigns targeting WordPress infrastructure, and sophisticated backdoor deployments by nation-state actors.
Google Warns of New Chrome Zero-Day Flaw Exploited in Attacks
Google has released an emergency update to address an actively exploited high-severity zero-day vulnerability in the Chrome browser's V8 engine, along with 11 additional security flaws. The zero-day, tracked as CVE-2026-11645, represents an immediate threat to the billions of Chrome users worldwide and requires immediate patching to prevent exploitation. Additional vulnerabilities addressed in this update include CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-85046. Source: Google warns of new Chrome zero-day flaw exploited in attacks
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are actively exploiting critical vulnerabilities in two popular WordPress plugins, with Wordfence reporting over 440,000 exploit attempts in recent days. The primary vulnerability, CVE-2026-14894 with a CVSS score of 9.8, affects the Super Forms plugin and allows unauthenticated attackers to upload arbitrary files due to missing file type validation. A second critical flaw, CVE-2026-32475, in Elementor Pro is also being actively exploited. Security researchers have identified multiple malicious IP addresses conducting these attacks, including 103.154.152.178, 103.164.182.122, 103.168.146.131, 103.168.147.235, 103.170.97.7, 129.227.46.143, 182.10.130.51, 189.4.122.140, 37.9.33.62, and 64.176.209.104, with the malware sample Mushr00w_upl.php being deployed during exploitation. Source: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
VMware Workstation and Fusion Updates Patch Critical Vulnerability
VMware has released security updates addressing critical vulnerabilities in Workstation and Fusion products that could allow attackers with administrative access to virtual machines to execute code on the host system. The vulnerabilities, identified as CVE-2026-59346 and CVE-2026-59347, represent a significant hypervisor escape risk and pose a threat to virtualized environments across enterprises. Organizations running these products should prioritize deployment of the latest patches to prevent potential host compromise. Source: VMware Workstation and Fusion Updates Patch Critical Vulnerability
Angry Birds: Toy Ghouls' New Toys
Kaspersky GERT experts have identified new backdoor variants deployed by the Toy Ghouls group, a nation-state affiliated threat actor. The group has developed sophisticated backdoors including GenieLocker, matrix-bird-agent, and mqtt-bird-agent that leverage unconventional command-and-control infrastructure. One variant uses the HiveMQ MQTT broker for command and control, while another employs the Matrix-based Element messenger platform, demonstrating the group's efforts to evade traditional detection mechanisms and maintain persistent access to compromised Russian organizations. Source: Angry Birds: Toy Ghouls' new toys
Organizations should prioritize immediate patching of Chrome browsers, WordPress plugins, and VMware products while implementing enhanced monitoring for indicators of compromise associated with the identified threat actors and malware families. The volume and sophistication of today's threats underscore the critical importance of maintaining current security postures across all systems and platforms.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Super Forms missing file type validation vulnerability
- Elementor Pro file upload vulnerability
- Mushr00w_upl.phpPHP web shell used in Super Forms exploitation
37.9.33.62IP address associated with Super Forms exploit attempts103.168.147.235IP address associated with Super Forms exploit attempts103.168.146.131IP address associated with Super Forms exploit attempts103.154.152.178IP address associated with Super Forms exploit attempts103.170.97.7IP address associated with Super Forms exploit attempts182.10.130.51IP address associated with Super Forms exploit attempts189.4.122.140IP address associated with Super Forms exploit attempts129.227.46.143IP address associated with Super Forms exploit attempts64.176.209.104IP address associated with Super Forms exploit attempts103.164.182.122IP address associated with Super Forms exploit attempts
- Stack-based buffer overflow vulnerability in VMware Workstation and Fusion.
- Integer overflow vulnerability in VMware Workstation and Fusion.
- mqtt-bird-agentHiveMQ C2 backdoor name
- matrix-bird-agentElement messenger C2 backdoor name
- GenieLockerCustom ransomware used by Toy Ghouls