Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
2026-09-04T13:24:01Z•c52270498bed8571c5b1157dccb5ab2cc5a0fdec87ab2d108742bb00dd38849e
CVE-2026-14894CVE-2026-20212CVE-2026-83548CVE-2026-85046active-exploitationai-securityandroid-trojanbgp-hijackingchromecisa-kevcisco-nexuscredential-theftcritical-infrastructuredata-breachinfostealermalwarephishingprivilege-escalationransomwareremote-code-executionsonicwall-smaspywaresupply-chain-attackv8wordpresszero-day
What happened
The document is a cybersecurity news feed covering actively exploited vulnerabilities, malware campaigns, phishing and supply-chain attacks, data breaches, and offensive use of AI. Key items include critical unauthenticated RCE flaws in WordPress plugins and Cisco Nexus 9000, an actively exploited Chrome V8 zero-day, SonicWall SMA zero-days listed by CISA, malware delivery through Node.js and fake installers, credential-stealing malware, BGP hijacking of Virtualizor updates, and zero-click Pegasus spyware infections.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- c52270498bed8571c5b1157dccb5ab2cc5a0fdec87ab2d108742bb00dd38849e
- Enrichment time
- 2026-09-04T13:24:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.