Wordfence (via The Hacker News, 4 September 2026) reports active exploitation of CVE-2026-14894 in the WordPress plugin Super Forms – Drag & Drop Form Builder. NVD/Wordfence describe missing file-type validation on the unauthenticated submit_form AJAX handler (session nonce obtainable via a separate nopriv endpoint), allowing unauthenticated arbitrary file upload and remote code execution. Wordfence CVSS 3.1 is 9.8 Critical. Affected: all versions through 6.3.313; fixed in 6.3.314. Wordfence says it blocked over 250,000 exploit attempts against this CVE (plus ~190,000 against Elementor Pro CVE-2026-32475 in the same reporting wave; Elementor stays on its own desk card). Observed Super Forms attacks POST to /wp-admin/admin-ajax.php with action=super_submit_form and a Base64 PHP web shell disguised as a data:image/gif payload (e.g. Mushr00w_upl.php); activity began 14 July 2026 and peaked above 40,000 requests on 18 August 2026. Upgrade Super Forms to 6.3.314+; hunt unexpected .php under uploads; keep WAF rules current. Distinct from cve-2026-32475 (Elementor Pro).
Arctic Wolf Pack Alert (3 September 2026) tracks PREY-0058: executives (directors/VPs) are cold-called by actors impersonating internal IT/help desk and steered to authentication-themed lure domains (assignpasskey.com, mfaregister.com, nowsso.com, oskeysetup.com, oursso.com, passkey-mfa.com, passkeydeploy.com, registermymfa.com, setpasskey.com and org-specific subdomains). An operator-gated AiTM Microsoft 365 login harvests credentials and MFA approvals; stolen sessions are replayed via residential proxies (notably NodeMaven, often same geo/ASN as the victim). Post-access discovery hits SharePoint/Entra (SearchQueryPerformed with contentclass:STS_Site/STS_Web and indexdocid pagination), then bulk exfil from SharePoint, OneDrive, Exchange, and Box — no endpoint malware or network lateral movement observed. Overlaps GTIG UNC6671 tradecraft; related extortion brands cited include BlackFile, Pink, Helix, Cinder, and Redact (affiliate/rebrands, not a single proven identity). Targets primarily US construction/engineering, healthcare/pharma, real estate, finance, professional services. Defences: phishing-resistant MFA (FIDO2/device-bound passkeys), Conditional Access (device compliance; block proxy/hosting ASN), Continuous Access Evaluation, tighten SharePoint scope, train staff that IT will not cold-call for passkey enrolment. Wire: The Hacker News (7 Sep 2026). Distinct from BigBear Evilginx2 PhaaS already on desk.
ConnectWise ScreenConnect™ 26.6.5 Security Patch bulletin (8 September 2026, Priority 1 High) assigns CVE-2026-84869 for a client-side condition that may allow files to be transferred and executed through an active remote Support/Access session without authorisation or Host confirmation. ScreenConnect servers are not impacted. CWE-862 Missing Authorization / CWE-269 Improper Privilege Management; CVSS 3.1 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Affected: ScreenConnect versions prior to 26.6.5. Remediation: upgrade to 26.6.5 or later, then reinstall Host clients and update Access agents (Cloud servers already remediated per vendor). Interim mitigation until clients are refreshed: remove TransferFiles (and TransferFilesInSession on legacy) from applicable roles/session groups — not a substitute for the patch. Earlier 3 September Guest File Transfer Advisory and Huntress late-August worm-like rogue ScreenConnect client chain (Quick Assist → wscript → VBScripts / User Run Key) remain relevant context; Shadowserver has tracked thousands of internet-exposed instances. CISA KEV listed CVE-2026-84869 on 11 September 2026 (dateAdded 2026-09-11; catalogVersion 2026.09.11); this card remains the single ScreenConnect file-transfer topic. Distinct from faronics-deploy-screenconnect-20260831. Primary: ConnectWise 2026-09-08 bulletin.
Microsoft Security Research (3 September 2026) documents a high-volume phishing campaign that inserts invisible Unicode Tags-block characters (U+E0000-U+E007F) inside finance lure words such as funding so human readers still see the word while keyword/regex filters miss the contiguous string. Telemetry tied to a Defender for Office 365 hunting signature rose from about 21,000 hits on 8 February 2026 to more than 1.3 million the next day, stayed elevated on weekdays for roughly three months, and dropped sharply after 15 May 2026 (weekday peaks cited up to about 2.37 million). Microsoft links the Unicode-obfuscated wave to a broader ActiveCampaign-relayed SBA/finance-themed phishing cluster previously described by Fortra, with disposable finance-themed domains and click-tracking via ActiveCampaign hosts. Defenders should strip or normalise Unicode tag characters before keyword detection, hunt U+E0000-U+E007F outside legitimate subdivision-flag emoji use, and treat marketing-platform abuse as a reputation-filter complication.
iTnews (3 September 2026) reports the Australian Communications and Media Authority fined Telstra $277,000 for not applying required identity-authentication processes to prevent SIM-swapping fraud. ACMA said the fraud caused at least $39,500 in losses to 15 customers between January and October 2025, with 13 further attempts where agents failed to add fraud protections or to act on risk signals; ACMA member Samantha Yorke said frontline staff did not follow Telstra's own processes. SIM swaps let attackers move a victim's number onto their own SIM and intercept MFA codes and other mobile traffic. ACMA accepted court-enforceable undertakings for stronger fraud prevention and staff training. Context in the same report: a larger $1.551 million Telstra penalty in July 2024 for related ID-authentication failures, and more than $5 million in ACMA telco fines to date on mobile-number fraud. Watchlist relevance: Telstra.
OpenAI (3 September 2026) announced Daybreak for Frontline Defenders, a global initiative committing US$1 billion in subsidised Daybreak access, training, technical support and partnerships so under-resourced defenders of essential services (water, electricity, local government, banking and similar) can use frontier AI cyber capabilities. The package includes Daybreak for America with a Multi-State ISAC pilot and a Daybreak Defense Network of more than 35 enterprise products and partner-operated services. Initial priority is US defenders, with international expansion stated. Distinct from the 1 September Astra Critical cybersecurity capability designation on this desk; this card is the subsidy and defender-access programme, not the model-capability rating.
OpenAI Daybreak for Frontline Defenders (3 Sep 2026)
Broadcom VMSA-2026-0007 (3 September 2026, Critical) patches two privately reported host-escape-class bugs in VMware Workstation and VMware Fusion 25H2 and 26H1. CVE-2026-59346 is a VMXNET3 integer overflow (CVSSv3 up to 9.3) where a malicious actor with local administrative privileges inside a guest that uses the VMXNET3 virtual NIC may execute code on the host. CVE-2026-59347 is an HGFS stack-based buffer overflow (CVSSv3 up to 8.1) that can let a guest admin run code as the VMX process on the host. Fixed in Workstation and Fusion 26H1u1. No workarounds. Broadcom does not report in-the-wild exploitation. Update lab and desktop hypervisors promptly; these are not ESXi/vSphere guest escape advisories.
Ransomware.live’s Australia country feed (observed 4 September 2026) lists Victorian photography business Verve Portraits (verveportraits.com.au) under the Settra brand, discovered 3 September 2026 with an estimated attack date of 13 August 2026. No company statement, OAIC notice, or ACSC advisory was located on this pass, so treat the listing as an unconfirmed extortion claim until a primary notice appears. Australian operators in professional services should still verify backups, MFA, and remote-access exposure.
Ransomware.live Australia (listing observed 4 Sep 2026)
The Hacker News (3 September 2026) summarises a Symantec Threat Hunter Team report: since February 2026, operators have abused the legitimate, signed node.exe runtime to execute malicious JavaScript rather than dropping unsigned binaries, with registry Run-key persistence, against government, technology and hotel targets. One Asian technology company intrusion (March–July 2026) installed official Node.js from nodejs.org after ClickFix access, then used EtherHiding-style retrieval after AdaptixC2/Cobalt Strike beacons were blocked. Related tooling includes ModeloRAT, Mistic/MLTBackdoor (KongTuke/Woodgnat), GateKeeper, NexShield Chrome extension, and C2Looper against a U.S. fintech. Prefer application-control policies that constrain node.exe outside developer workstations; hunt for unexpected node.exe + Run keys and EtherHiding beacons.
UPDATE 14 September 2026: Cyber Daily’s Penfold Motors exclusive states machinery management specialist Macquarrie recently confirmed it is responding to a cyber security incident at a third-party supplier — elevating the earlier ransomware.live Storm listing (discovered 3 September 2026; estimated attack 1 September) from leak-site-only to company-acknowledged supplier compromise. No separate Macquarrie customer-notification text, OAIC entry, or ACSC advisory was fetched beyond that Cyber Daily confirmation. Same Storm wave as Penfold Motors and other Australian automotive/farm-machinery dealers. UPDATE 15 Sep 2026: Cyber Daily names Auto-IT as the third-party software firm whose customer environments were hit via abused RMM (see auto-it-storm-20260915). Primary confirmation wire: Cyber Daily (14 Sep); listing context: ransomware.live AUS.
Exploit-DB entry 52680 (dated 3 September 2026) and Metabase advisory GHSA-w95f-x9v9-wv36 cover CVE-2026-59827: Metabase instances with an H2 database connection (including the default sample database) deserialize arbitrary Java objects from native H2 query result columns of type OTHER without validation. An authenticated user who can run native queries against an accessible H2 connection can execute OS commands on the Metabase host. Affected ranges in the exploit write-up include ≥0.58.0 <0.58.15, ≥0.59.0 <0.59.12, ≥0.60.0 <0.60.6.3, and ≥0.61.0 <0.61.1.4. Patch Metabase; remove or lock down sample/H2 connections; restrict who can run native SQL.
Exploit-DB entry 52681 (dated 3 September 2026) documents a public remote-code-execution exploit for CVE-2025-57819 in FreePBX Endpoint Manager. The flaw is an unauthenticated SQL injection in the brand parameter of /admin/ajax.php that can insert a malicious cron_jobs row and yield a reverse shell as the web user. Affected branches per the exploit write-up: FreePBX 15.x before 15.0.66, 16.x before 16.0.89, and 17.x before 17.0.3 (title tested against 17.0.2). The write-up cites CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), CWE-89 and CWE-288, NVD, and GitHub advisory GHSA-m42g-xg4c-5f3h. Upgrade Endpoint Manager / FreePBX to the fixed releases; restrict admin/ajax exposure; hunt for unexpected cron_jobs entries.