- Zero-day vulnerability patched in Chrome
- Exploited zero-day vulnerability in Chrome's V8 engine
- Zero-day vulnerability patched in Chrome
- Zero-day vulnerability patched in Chrome
- Zero-day vulnerability patched in Chrome
- Zero-day vulnerability patched in Chrome
- Zero-day vulnerability patched in Chrome
ThreatNoir Afternoon Brief — September 9
Afternoon Review in IT Security — September 9, 2026
The technology landscape faces mounting pressure from an accelerating wave of critical vulnerabilities and sophisticated malware campaigns. Today's security briefing reveals a troubling pattern of zero-day exploits, privilege escalation flaws, and memory-resident threats targeting both consumer browsers and enterprise infrastructure.
Chrome 153 Patches Seventh Zero-Day of 2026
Google has released Chrome 153, addressing a significant security milestone that underscores the persistent threat landscape facing users worldwide. The update encompasses 230 security fixes, with particular emphasis on the seventh zero-day vulnerability discovered in the browser this year. The affected CVEs include CVE-2026-11645, CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281, CVE-2026-85046, and CVE-2026-87491. Security professionals are urging immediate deployment across all systems to mitigate active exploitation risks. Source: Chrome 153 Patches Seventh Zero-Day of 2026
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
A critical vulnerability in cPanel has emerged that enables authenticated users to escalate privileges to root level across entire hosting infrastructure. The flaw, tracked as CVE-2026-67401, allows any hosting account holder with mail-related privileges to exploit the EmailTrack functionality for arbitrary file creation on the server. From this foothold, attackers can execute code with root-level permissions, effectively compromising the entire server. cPanel published its advisory on September 8, confirming that every supported version of cPanel and WHM is vulnerable to this attack vector. Source: New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Sophisticated malware associated with F5 BIG-IP Access Policy Manager compromises has demonstrated advanced evasion techniques by injecting a PHP web shell directly into memory rather than storing it on disk. Sophos researchers identified this technique in their analysis published on September 7, revealing how the malware exploits CVE-2025-53521 to gain initial access. The threat actors behind the malware variants c05d5254 and PoisonedRefresh leverage Apache's memory-loaded PHP scripts to hide their web shell, rendering traditional disk-based security scans ineffective. This memory-resident approach represents a significant escalation in adversary sophistication, allowing attackers to maintain persistent access while evading conventional detection mechanisms. Source: F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access
A newly disclosed zero-day vulnerability in Microsoft Defender, named ShieldCrash, has been released publicly by a researcher operating under the alias Nightmare Eclipse. The exploit was released immediately following Microsoft's September 2026 Patch Tuesday security updates, demonstrating that the vulnerability remained unpatched despite the routine security release cycle. ShieldCrash grants attackers SYSTEM-level access, representing a critical privilege escalation threat to Windows environments relying on Defender as a primary security control. Source: New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access
Today's threat landscape demonstrates the urgent need for comprehensive patch management strategies and layered security controls. Organizations must prioritize immediate updates to Chrome and cPanel systems while implementing enhanced monitoring for F5 BIG-IP infrastructure and Windows Defender deployments to detect and respond to active exploitation attempts.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Identifies the specific cPanel vulnerability.
- Vulnerability exploited by the malware for remote code execution.
- c05d5254F5's internal tracking name for the malware.
- PoisonedRefreshESET's name for related malware samples.