Weekly review

ThreatNoir Afternoon Brief — September 4

2026-09-04Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — September 4, 2026

The threat landscape continues to evolve rapidly with critical vulnerabilities emerging across multiple platforms and attack vectors. Today's review highlights urgent patching requirements for widely deployed software, large-scale exploitation campaigns targeting WordPress infrastructure, and sophisticated backdoor deployments by nation-state actors.

Google Warns of New Chrome Zero-Day Flaw Exploited in Attacks

Google has released an emergency update to address an actively exploited high-severity zero-day vulnerability in the Chrome browser's V8 engine, along with 11 additional security flaws. The zero-day, tracked as CVE-2026-11645, represents an immediate threat to the billions of Chrome users worldwide and requires immediate patching to prevent exploitation. Additional vulnerabilities addressed in this update include CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, and CVE-2026-85046. Source: Google warns of new Chrome zero-day flaw exploited in attacks

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are actively exploiting critical vulnerabilities in two popular WordPress plugins, with Wordfence reporting over 440,000 exploit attempts in recent days. The primary vulnerability, CVE-2026-14894 with a CVSS score of 9.8, affects the Super Forms plugin and allows unauthenticated attackers to upload arbitrary files due to missing file type validation. A second critical flaw, CVE-2026-32475, in Elementor Pro is also being actively exploited. Security researchers have identified multiple malicious IP addresses conducting these attacks, including 103.154.152.178, 103.164.182.122, 103.168.146.131, 103.168.147.235, 103.170.97.7, 129.227.46.143, 182.10.130.51, 189.4.122.140, 37.9.33.62, and 64.176.209.104, with the malware sample Mushr00w_upl.php being deployed during exploitation. Source: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

VMware Workstation and Fusion Updates Patch Critical Vulnerability

VMware has released security updates addressing critical vulnerabilities in Workstation and Fusion products that could allow attackers with administrative access to virtual machines to execute code on the host system. The vulnerabilities, identified as CVE-2026-59346 and CVE-2026-59347, represent a significant hypervisor escape risk and pose a threat to virtualized environments across enterprises. Organizations running these products should prioritize deployment of the latest patches to prevent potential host compromise. Source: VMware Workstation and Fusion Updates Patch Critical Vulnerability

Angry Birds: Toy Ghouls' New Toys

Kaspersky GERT experts have identified new backdoor variants deployed by the Toy Ghouls group, a nation-state affiliated threat actor. The group has developed sophisticated backdoors including GenieLocker, matrix-bird-agent, and mqtt-bird-agent that leverage unconventional command-and-control infrastructure. One variant uses the HiveMQ MQTT broker for command and control, while another employs the Matrix-based Element messenger platform, demonstrating the group's efforts to evade traditional detection mechanisms and maintain persistent access to compromised Russian organizations. Source: Angry Birds: Toy Ghouls' new toys

Organizations should prioritize immediate patching of Chrome browsers, WordPress plugins, and VMware products while implementing enhanced monitoring for indicators of compromise associated with the identified threat actors and malware families. The volume and sophistication of today's threats underscore the critical importance of maintaining current security postures across all systems and platforms.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Google warns of new Chrome zero-day flaw exploited in attacks
CVE6
  • Use-after-free vulnerability in Dawn, previously patched.
  • Actively exploited zero-day flaw in Chrome's V8 engine.
  • Out-of-bounds read/write in V8 engine, previously exploited.
  • Iterator invalidation in CSSFontFeatureValuesMap, previously patched.
  • Out-of-bounds write in Skia graphics library, previously exploited.
  • Inappropriate implementation in V8 engine, previously exploited.
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
CVE2
Malware1
  • Mushr00w_upl.php
    PHP web shell used in Super Forms exploitation
IP Address10
  • 37.9.33.62
    IP address associated with Super Forms exploit attempts
  • 103.168.147.235
    IP address associated with Super Forms exploit attempts
  • 103.168.146.131
    IP address associated with Super Forms exploit attempts
  • 103.154.152.178
    IP address associated with Super Forms exploit attempts
  • 103.170.97.7
    IP address associated with Super Forms exploit attempts
  • 182.10.130.51
    IP address associated with Super Forms exploit attempts
  • 189.4.122.140
    IP address associated with Super Forms exploit attempts
  • 129.227.46.143
    IP address associated with Super Forms exploit attempts
  • 64.176.209.104
    IP address associated with Super Forms exploit attempts
  • 103.164.182.122
    IP address associated with Super Forms exploit attempts
Angry Birds: Toy Ghouls’ new toys
Malware3
  • mqtt-bird-agent
    HiveMQ C2 backdoor name
  • matrix-bird-agent
    Element messenger C2 backdoor name
  • GenieLocker
    Custom ransomware used by Toy Ghouls