Summary & highlights
Ransomware Extortion Campaigns Shift Targeting to Mid-Level IT and Business Managers, Zscaler ThreatLabz Finds. BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detection. City of Coweta, Oklahoma Hit by Anubis Ransomware Attack.
Highlights
- TL-2026-1948 — City of Coweta, Oklahoma Hit by Anubis Ransomware Attack
- TL-2026-1949 — SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local Privilege Escalation
- TL-2026-1951 — Suspected Russian Actor Uses AI Slopsquatting to Publish 1,000+ Malicious npm Packages (WEL1DROPPER / "Flooding Dropper")
- TL-2026-1952 — Malware Abuses Windows Hello for Business Key to Authenticate to Microsoft Entra ID
- TL-2026-1953 — Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts
Theme of the day
Unattributed threats dominated the day, with emerging actors like Head Mare and FirewallFalcon active alongside ransomware and CitrixBleed-related tags.
- credential-theft
- social-engineering
- privilege-escalation
- ransomware
- mfa-bypass
Threats published
26 threat lines in the 2026-08-09 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Metabase Unauthenticated SQL Injection 0-Day (GHSA-vwf4-m7j8-wcjf) Exploited in the Wild for Admin TakeoverCRITICAL
- UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for ExtortionCRITICAL
- CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) (update)CRITICAL
- CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol (update)CRITICAL
- ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account Hijack (update)CRITICAL
- Pre-auth RCE chains in Bonita BPM 10.4.3 and Apache OFBiz 24.09.05 (CVE-2026-31986) (update)CRITICAL
- ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Models (update)CRITICAL
- Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws (update)CRITICAL
- City of Coweta, Oklahoma Hit by Anubis Ransomware AttackHIGH
- SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local Privilege EscalationHIGH
- Suspected Russian Actor Uses AI Slopsquatting to Publish 1,000+ Malicious npm Packages (WEL1DROPPER / "Flooding Dropper")HIGH
- Malware Abuses Windows Hello for Business Key to Authenticate to Microsoft Entra IDHIGH
- Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai AccountsHIGH
- Ransomware Gangs Shift Targeting from Executives to Mid-Level IT/Finance Managers (Zscaler ThreatLabz Research)HIGH
- CSS Bomb: JavaScript-Free CSS Keylogging and Token-Theft Attacks Against Gmail, Outlook, Yahoo Mail, AOL Mail, Fastmail, and ProtonMailHIGH
- U.S. Defense Manufacturer IEH Corporation Breached via Phishing, Potential Export-Controlled Data ExposureHIGH
- AI-Assisted "HTTP Terminator" Uncovers Novel HTTP Desync Techniques and Apache Traffic Server Zero-Day (CVE-2026-63078)HIGH
- UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data for ExtortionHIGH
- AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671 (BlackFile/Redact) Extortion GroupHIGH
- CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux Host (update)HIGH
- Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance Emails (update)HIGH
- WordPress Core XSS2Shell Vulnerability Chains Pre-Auth XSS to RCE (CVE-2026-64638) (update)HIGH
- Fake Zoom Installer Delivers Overlord RAT to macOS via .NET Downloader (ZoomMeetings) (update)HIGH
- TONTOU: Interrupt-Injection Attack Bypasses Spectre v2 (eIBRS/Safe RET) Defenses on Intel and AMD CPUs (update)HIGH
- Ransomware Extortion Campaigns Shift Targeting to Mid-Level IT and Business Managers, Zscaler ThreatLabz FindsMEDIUM
- BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human DetectionMEDIUM
Techniques observed
192 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0011.001
- AML.T0051
- AML.T0051.001
- AML.T0052.000
- AML.T0053
- AML.T0054
- AML.T0091.001
- T1003
- T1003.001
- T1003.008
- T1005
- T1008
- T1014
- T1016
- T1020
- T1021
- T1021.001
- T1021.007
- T1027
- T1027.010
- T1036
- T1036.004
- T1036.005
- T1037.004
- T1041
- T1048
- T1053
- T1053.005
- T1055
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.006
- T1059.007
- T1068
- T1069
- T1070
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1074
- T1078
- T1078.003
- T1078.004
- T1082
- T1083
- T1087
- T1087.004
- T1090
- T1090.002
- T1095
- T1098
- T1098.005
- T1102.002
- T1105
- T1106
- T1110
- T1111
- T1112
- T1113
- T1114
- T1114.002
- T1119
- T1123
- T1125
- T1133
- T1134
- T1134.002
- T1136
- T1136.001
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1195.003
- T1199
- T1202
- T1203
- T1204
- T1204.001
- T1204.002
- T1205
- T1210
- T1211
- T1213
- T1213.003
- T1219
- T1475
- T1484
- T1485
- T1486
- T1489
- T1490
- T1497.001
- T1499.004
- T1505
- T1505.003
- T1518
- T1526
- T1528
- T1530
- T1531
- T1537
- T1538
- T1539
- T1543
- T1543.001
- T1543.002
- T1543.004
- T1547.001
- T1550
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1552.005
- T1553.002
- T1555
- T1556
- T1556.006
- T1557
- T1560
- T1560.001
- T1560.003
- T1562
- T1564.008
- T1565
- T1565.001
- T1565.002
- T1566
- T1566.001
- T1566.002
- T1567
- T1567.002
- T1570
- T1571
- T1572
- T1573
- T1574
- T1574.001
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.006
- T1583.008
- T1585.002
- T1587.001
- T1587.004
- T1588
- T1588.002
- T1588.005
- T1588.006
- T1588.007
- T1589
- T1589.002
- T1589.003
- T1590
- T1591
- T1591.002
- T1591.004
- T1592
- T1592.002
- T1592.004
- T1593.001
- T1595
- T1595.002
- T1596
- T1598
- T1601
- T1606
- T1608
- T1608.001
- T1608.005
- T1611
- T1613
- T1622
- T1657
- T1660
- T1684.001
- T1685
Threat actors
6 named threat actors across the reports.
Nation-state attribution
- Russia
- North Korea
- China
Threat categories
- RANSOMWARE
- PHISHING
- VULNERABILITY
- SUPPLY_CHAIN
- DATA_BREACH
- MALWARE
Severity breakdown
- critical8
- high16
- medium2
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 164
- file 109
- behavioral 77
- entity 74
- infrastructure 59
- tool 48
- package 27
- malware 25