Summary & highlights
"Download More RAM" Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing (CVE-2026-23670). AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub, Canva, Geek Squad, Temu, Target and the FTC. CVE-2026-40126: DOM-based XSS in OutSystems Service Center via malicious file upload filenames.
Highlights
- TL-2026-2040 — Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor (QUICAgent)
- TL-2026-2045 — Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)
- TL-2026-2049 — Unisoc VoLTE Video-Call Exploit Chain Escalates Modem RCE to Full Android Kernel Access
- TL-2026-2050 — Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chains
- TL-2026-2051 — GitHub Actions Workflow Injection in Snowflake .NET Connector Repo Exposed Jira Credentials
Theme of the day
Critical zero-day exploits (Metabase SQLi, Defender EDR bypass) and massive credential leaks dominate, with GRU-linked APT and unattributed actors driving active attacks.
- credential-theft
- social-engineering
- infostealer
- anti-analysis
- cryptocurrency-theft
Threats published
20 threat lines in the 2026-08-17 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Unisoc VoLTE Video Call Exploit Chain Grants Full Android Kernel AccessCRITICAL
- Critical GitLab GraphQL Flaw (CVE-2026-19478, CVSS 9.4) Could Let Unauthenticated Attackers Delete Public ProjectsCRITICAL
- CVE-2026-15748: Forminator WordPress Plugin Arbitrary File Upload Enables Unauthenticated RCECRITICAL
- Coruna iOS Exploit Kit — 23 Exploits Across 5 Chains Targeting iOS 13-17.2.1 (CVE-2021-30952, CVE-2023-41974, CVE-2023-43000 + 20 More) (update)CRITICAL
- DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors (CVE-2026-20700, CVE-2025-43529, CVE-2025-31277) (update)CRITICAL
- Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor (QUICAgent)HIGH
- Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)HIGH
- Unisoc VoLTE Video-Call Exploit Chain Escalates Modem RCE to Full Android Kernel AccessHIGH
- Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack ChainsHIGH
- GitHub Actions Workflow Injection in Snowflake .NET Connector Repo Exposed Jira CredentialsHIGH
- Cavern Manticore's CAV3RN C2 Framework Adds DNS-Based Channel Selection and Google Apps Script RelayHIGH
- MacSync Stealer: Malvertising Campaign Impersonates Claude/Apple Support to Deploy macOS InfostealerHIGH
- PamStealer: Rust-Based macOS Infostealer Masquerades as Maccy Clipboard Manager, Validates Stolen Passwords via PAM (update)HIGH
- CrashStealer: Native C++ macOS Infostealer Masquerading as Apple's CrashReporter via Notarized 'Werkbit' Dropper (update)HIGH
- Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRig (update)HIGH
- AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Control (update)HIGH
- "Download More RAM" Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing (CVE-2026-23670)MEDIUM
- AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub, Canva, Geek Squad, Temu, Target and the FTCMEDIUM
- CVE-2026-40126: DOM-based XSS in OutSystems Service Center via malicious file upload filenamesMEDIUM
- Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap, Vodafone, TCS, and Six Others via Password Spray/MFA Fatigue; TCS and Gap Dispute the ClaimsMEDIUM
Techniques observed
175 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003.004
- T1005
- T1008
- T1014
- T1020
- T1021.001
- T1027
- T1027.009
- T1036
- T1036.004
- T1036.005
- T1036.008
- T1041
- T1047
- T1048
- T1053.002
- T1055
- T1055.004
- T1056
- T1056.002
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.004
- T1059.007
- T1068
- T1069
- T1070
- T1070.003
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1074
- T1074.001
- T1078
- T1078.004
- T1082
- T1083
- T1087
- T1087.002
- T1090.004
- T1098
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110
- T1111
- T1112
- T1113
- T1114.001
- T1115
- T1119
- T1123
- T1133
- T1135
- T1140
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1211
- T1213
- T1218
- T1218.011
- T1219
- T1222
- T1484.001
- T1485
- T1490
- T1495
- T1496
- T1497
- T1497.001
- T1497.003
- T1499.004
- T1505.003
- T1518
- T1518.001
- T1528
- T1531
- T1539
- T1542.001
- T1543
- T1543.004
- T1546
- T1547
- T1547.001
- T1547.006
- T1547.009
- T1547.015
- T1548
- T1548.003
- T1548.004
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1553
- T1553.001
- T1553.002
- T1553.006
- T1554
- T1555
- T1555.001
- T1555.003
- T1556
- T1557
- T1560
- T1562.001
- T1564.001
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1566.004
- T1567
- T1567.002
- T1568
- T1571
- T1572
- T1573
- T1573.001
- T1574.001
- T1574.002
- T1583
- T1583.001
- T1583.006
- T1584
- T1584.004
- T1585
- T1585.001
- T1585.002
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.002
- T1588.004
- T1588.005
- T1588.006
- T1588.007
- T1589
- T1589.001
- T1591.004
- T1592
- T1592.002
- T1593.001
- T1595.002
- T1601
- T1601.001
- T1608
- T1608.001
- T1614
- T1614.001
- T1620
- T1621
- T1622
- T1650
- T1657
- T1658
- T1664
- T1684.001
- T1685
Threat actors
6 named threat actors across the reports.
Nation-state attribution
- China
- Iran
- Russia / China
- Russia
Threat categories
- VULNERABILITY
- PHISHING
- DATA_BREACH
- MALWARE
- RANSOMWARE
- ZERO_DAY
Severity breakdown
- critical5
- high11
- medium4
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 139
- file 112
- entity 56
- behavioral 46
- infrastructure 44
- tool 29
- malware 22
- package 15
- technique 2