STRATQUAD
CYBER THREAT INTELLIGENCE BRIEF
Daily Brief · 4 September 2026 · 24h windowRISKCRITICAL
StratQuad CTI Daily Brief, 4 September 2026

Compiled from 52 monitored sources · 664 articles reviewed

Today’s Briefing

CISA added CVE-2026-59822 and CVE-2026-48710 to the Known Exploited Vulnerabilities catalogue, the former an authentication bypass in BerriAI LiteLLM's MCP Streamable HTTP endpoint allowing unauthenticated session establishment with an arbitrary bearer token, the latter a request smuggling flaw in Kludex Starlette enabling path injection into the host component that can bypass authentication mechanisms reliant on reconstructed URL paths. Microsoft published research on a social engineering campaign in which attackers impersonate IT support to gain remote session access and pivot to enterprise-wide compromise. Chrome released 152.0.7977.75 addressing three critical-severity vulnerabilities including CVE-2026-84324, a use-after-free in Proxy exploitable via crafted network traffic for arbitrary code execution outside the sandbox, CVE-2026-84354, an authorisation flaw in FileSystem, and CVE-2026-84325, an input validation defect in DataTransfer that permits bypass of system access restrictions via a co-installed application.

Top Stories

  1. CC-4842 - Cisco Releases IOS XR Software Security Hardening Guidance
  2. CC-4841 - Broadcom Releases Security Advisory for Critical Vulnerabilities in VMware Workstation and VMware Fusion
  3. The story behind the intelligence
  4. Rockwell Automation ControlFLASH
  5. Pyramid Solutions NetStaX EtherNet/IP Stack

Full brief available to subscribers

The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.

All briefs