# Daily Threat Intelligence Debrief

> The Threadlinqs daily debrief is a curated summary of every cyber threat added or updated in the last 24 hours, with detection coverage and MITRE ATT&CK mapping.

- **Edition:** 2026-10-04
- **Built:** 2026-10-05T10:00:30.075Z
- **Canonical:** https://intel.threadlinqs.com/debrief
- **New threats:** 12
- **New detections:** 207 (Splunk SPL / Microsoft KQL / Sigma)
- **Platform totals:** 2623 threats, 24046 detections

## Summary

Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC. Coordinated model-distillation campaign against OpenAI: 15,000+ accounts attempt to extract protected model reasoning, linked to Moonshot AI-associated individuals. Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root on Host) via Sandbox Bug Bounty; $50,000 Bounty Awarded.

## Threats in this debrief

- [TL-2026-2891](https://intel.threadlinqs.com/threat/TL-2026-2891) — MEDIUM — Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC
- [TL-2026-2915](https://intel.threadlinqs.com/threat/TL-2026-2915) — MEDIUM — Coordinated model-distillation campaign against OpenAI: 15,000+ accounts attempt to extract protected model reasoning, linked to Moonshot AI-associated individuals
- [TL-2026-2878](https://intel.threadlinqs.com/threat/TL-2026-2878) — HIGH — Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root on Host) via Sandbox Bug Bounty; $50,000 Bounty Awarded
- [TL-2026-2884](https://intel.threadlinqs.com/threat/TL-2026-2884) — HIGH — China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)
- [TL-2026-2889](https://intel.threadlinqs.com/threat/TL-2026-2889) — HIGH — TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files (CVE-2026-60137, CVE-2026-63030)
- [TL-2026-2896](https://intel.threadlinqs.com/threat/TL-2026-2896) — HIGH — CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Catalog
- [TL-2026-2898](https://intel.threadlinqs.com/threat/TL-2026-2898) — HIGH — Kairos Data-Extortion Group Claims Slate Valley Unified School District (Vermont); 762 GB Claimed, Board Declines Ransom, Leak Imminent
- [TL-2026-2901](https://intel.threadlinqs.com/threat/TL-2026-2901) — HIGH — Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to Bypass MFA
- [TL-2026-2908](https://intel.threadlinqs.com/threat/TL-2026-2908) — HIGH — Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guilty
- [TL-2026-2919](https://intel.threadlinqs.com/threat/TL-2026-2919) — HIGH — Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA
- [TL-2026-2894](https://intel.threadlinqs.com/threat/TL-2026-2894) — CRITICAL — Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features (CVE-2026-103922)
- [TL-2026-2912](https://intel.threadlinqs.com/threat/TL-2026-2912) — CRITICAL — Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698, CVE-2026-93029, CVE-2026-93697) Enable Root Code Execution and Admin Session Hijacking
- [TL-2026-2858](https://intel.threadlinqs.com/threat/TL-2026-2858) — HIGH — ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix) (update)
- [TL-2026-2892](https://intel.threadlinqs.com/threat/TL-2026-2892) — HIGH — Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and Enables User and Admin Impersonation (update)
- [TL-2026-2897](https://intel.threadlinqs.com/threat/TL-2026-2897) — HIGH — Ransomware Moves up the Org Chart: Managers Are Prime Targets (Zscaler ThreatLabz, 351 Victims / 334 Organizations) (update)
- [TL-2026-2905](https://intel.threadlinqs.com/threat/TL-2026-2905) — HIGH — Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371, CVE-2026-19743) (update)
- [TL-2026-2916](https://intel.threadlinqs.com/threat/TL-2026-2916) — HIGH — Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style) (update)
- [TL-2026-1083](https://intel.threadlinqs.com/threat/TL-2026-1083) — CRITICAL — JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos (CVE-2021-29441) (update)
- [TL-2026-1875](https://intel.threadlinqs.com/threat/TL-2026-1875) — CRITICAL — ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting 444+ Packages (update)
- [TL-2026-2830](https://intel.threadlinqs.com/threat/TL-2026-2830) — CRITICAL — Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attacks (update)
- [TL-2026-2833](https://intel.threadlinqs.com/threat/TL-2026-2833) — CRITICAL — Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs / Storm-2603) (update)
- [TL-2026-2843](https://intel.threadlinqs.com/threat/TL-2026-2843) — CRITICAL — CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD (update)
- [TL-2026-2902](https://intel.threadlinqs.com/threat/TL-2026-2902) — CRITICAL — Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149) (update)

## Recent debriefs

- [2026-10-04](https://intel.threadlinqs.com/debrief/2026-10-04) — 12 new threats
- [2026-10-03](https://intel.threadlinqs.com/debrief/2026-10-03) — 13 new threats
- [2026-10-02](https://intel.threadlinqs.com/debrief/2026-10-02) — 15 new threats
- [2026-09-30](https://intel.threadlinqs.com/debrief/2026-09-30) — 13 new threats
- [2026-09-29](https://intel.threadlinqs.com/debrief/2026-09-29) — 18 new threats
- [2026-09-28](https://intel.threadlinqs.com/debrief/2026-09-28) — 12 new threats
- [2026-09-27](https://intel.threadlinqs.com/debrief/2026-09-27) — 22 new threats
- [2026-09-26](https://intel.threadlinqs.com/debrief/2026-09-26) — 20 new threats
- [2026-09-25](https://intel.threadlinqs.com/debrief/2026-09-25) — 18 new threats
- [2026-09-21](https://intel.threadlinqs.com/debrief/2026-09-21) — 16 new threats
- [2026-09-18](https://intel.threadlinqs.com/debrief/2026-09-18) — 16 new threats
- [2026-09-15](https://intel.threadlinqs.com/debrief/2026-09-15) — 12 new threats
- [2026-09-13](https://intel.threadlinqs.com/debrief/2026-09-13) — 14 new threats
- [2026-09-09](https://intel.threadlinqs.com/debrief/2026-09-09) — 9 new threats
- [2026-09-08](https://intel.threadlinqs.com/debrief/2026-09-08) — 10 new threats
- [2026-09-03](https://intel.threadlinqs.com/debrief/2026-09-03) — 15 new threats
- [2026-09-02](https://intel.threadlinqs.com/debrief/2026-09-02) — 12 new threats
- [2026-09-01](https://intel.threadlinqs.com/debrief/2026-09-01) — 12 new threats
- [2026-08-31](https://intel.threadlinqs.com/debrief/2026-08-31) — 14 new threats
- [2026-08-29](https://intel.threadlinqs.com/debrief/2026-08-29) — 18 new threats
- [2026-08-28](https://intel.threadlinqs.com/debrief/2026-08-28) — 25 new threats
- [2026-08-26](https://intel.threadlinqs.com/debrief/2026-08-26) — 14 new threats
- [2026-08-23](https://intel.threadlinqs.com/debrief/2026-08-23) — 6 new threats
- [2026-08-21](https://intel.threadlinqs.com/debrief/2026-08-21) — 15 new threats
- [2026-08-20](https://intel.threadlinqs.com/debrief/2026-08-20) — 15 new threats
- [2026-08-17](https://intel.threadlinqs.com/debrief/2026-08-17) — 14 new threats
- [2026-08-16](https://intel.threadlinqs.com/debrief/2026-08-16) — 12 new threats
- [2026-08-13](https://intel.threadlinqs.com/debrief/2026-08-13) — 12 new threats
- [2026-08-10](https://intel.threadlinqs.com/debrief/2026-08-10) — 17 new threats
- [2026-08-09](https://intel.threadlinqs.com/debrief/2026-08-09) — 15 new threats
- [Archive of every daily debrief](https://intel.threadlinqs.com/debrief/archive)

## Full data

Detection query text (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Machine-readable overview: https://intel.threadlinqs.com/llms.txt

Canonical: https://intel.threadlinqs.com/debrief
