Summary & highlights
Hospital for Sick Children (SickKids) Data Breach Exposes Employee Information via Third-Party Software Vulnerability. Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and captive portal compromise targeting academia, defense, and government across Europe and the US. LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp).
Highlights
- TL-2026-2091 — Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and captive portal compromise targeting academia, defense, and government across Europe and the US
- TL-2026-2094 — LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)
- TL-2026-2095 — iAuthFlow V2 Phishing Toolkit Enrolls Attacker-Controlled Passkeys That Survive Password Resets
- TL-2026-2096 — Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web servers
- TL-2026-2098 — SynkLoader: New Multi-Module Malware Family Distributed via Microsoft Teams Phishing Campaign Targeting Enterprise Active Directory Environments
Theme of the day
AI-powered attacks and autonomous agents drove today's threat landscape, targeting critical infrastructure and crypto wallets, while APT groups like APT38 and APT29 remained active.
- credential-theft
- social-engineering
- data-exfiltration
- defense-evasion
- supply-chain-attack
Threats published
16 threat lines in the 2026-08-21 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593) by RondoDox BotnetCRITICAL
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2CRITICAL
- 91 Spring Framework CVEs Disclosed by Broadcom, Including Critical Deserialization Flaw CVE-2026-59285CRITICAL
- Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites (CVE-2026-32475) (update)CRITICAL
- Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and captive portal compromise targeting academia, defense, and government across Europe and the USHIGH
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)HIGH
- iAuthFlow V2 Phishing Toolkit Enrolls Attacker-Controlled Passkeys That Survive Password ResetsHIGH
- Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web serversHIGH
- SynkLoader: New Multi-Module Malware Family Distributed via Microsoft Teams Phishing Campaign Targeting Enterprise Active Directory EnvironmentsHIGH
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetHIGH
- SmartApeSG ClickFix Campaign Delivering Two-Stage RAT Infection via Fake CAPTCHA Social Engineering on Windows HostsHIGH
- Visa Kernel 3 EMV Protocol Flaw — Zombie Card Relay Attack Enables Expired Contactless Card PurchasesHIGH
- Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical Intrusion)HIGH
- SDLC Supply Chain Attacks: ChainDrop npm Worm and Developer Pipeline TargetingHIGH
- Deepfake Investment Scam Ads Funnel Victims Into Fake-Analyst WhatsApp Groups (GoldBull, CoinLure)HIGH
- Hospital for Sick Children (SickKids) Data Breach Exposes Employee Information via Third-Party Software VulnerabilityMEDIUM
Techniques observed
157 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0010.003
- AML.T0051.001
- AML.T0053
- T1003
- T1003.001
- T1005
- T1007
- T1014
- T1016
- T1020
- T1021
- T1021.001
- T1027
- T1033
- T1036
- T1036.005
- T1037.003
- T1037.004
- T1041
- T1046
- T1048
- T1048.002
- T1052.001
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.001
- T1055.004
- T1055.012
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.007
- T1070.004
- T1070.006
- T1071
- T1071.001
- T1078
- T1082
- T1083
- T1087
- T1090
- T1090.001
- T1090.002
- T1095
- T1098
- T1098.005
- T1105
- T1106
- T1110
- T1112
- T1114
- T1115
- T1119
- T1123
- T1125
- T1133
- T1134.001
- T1135
- T1136.001
- T1140
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1213
- T1213.002
- T1218
- T1219
- T1222.002
- T1485
- T1489
- T1496
- T1497
- T1497.001
- T1498.001
- T1499.003
- T1499.004
- T1505
- T1505.002
- T1505.003
- T1518
- T1528
- T1530
- T1534
- T1539
- T1543
- T1543.002
- T1543.003
- T1546
- T1547
- T1547.001
- T1547.015
- T1548
- T1548.002
- T1550
- T1550.001
- T1552
- T1552.004
- T1553
- T1553.002
- T1554
- T1555
- T1555.003
- T1557
- T1560
- T1564.001
- T1565
- T1565.001
- T1565.002
- T1566
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1567.002
- T1568
- T1569
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1583
- T1583.001
- T1583.006
- T1583.008
- T1584
- T1585.001
- T1585.002
- T1587.001
- T1588.006
- T1588.007
- T1589
- T1591
- T1595
- T1598
- T1608.006
- T1620
- T1649
- T1657
- T1684.001
- T1685
- T1685.005
- T1686
Threat actors
9 named threat actors across the reports.
Nation-state attribution
- Russia
- China
Threat categories
- DATA_BREACH
- APT
- RANSOMWARE
- MALWARE
- THREAT_INTEL
- VULNERABILITY
- PHISHING
- SUPPLY_CHAIN
Severity breakdown
- critical4
- high11
- medium1
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 138
- file 99
- infrastructure 25
- package 23
- tool 23
- entity 19
- behavioral 13
- malware 12