Summary & highlights
Dissection of a PHP Backdoor Leveraging php-win.exe for Stealthy Windows Persistence. 24 Malicious npm Packages Abuse Registry Mirrors as Phishing Infrastructure (Fake Cloudflare/Microsoft Login Pages). Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demon.
Highlights
- TL-2026-2148 — Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demon
- TL-2026-2151 — CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain Patch-Pinning Risk
- TL-2026-2153 — Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter Devices
- TL-2026-2154 — Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption Campaigns Against NATO/EU Infrastructure
- TL-2026-2155 — "The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware distribution, extortion, and predatory recruitment
Theme of the day
Routine activity — no dominant theme emerged.
- authentication-bypass
- remote-code-execution
- dead-drop-resolver
- phishing
- social-engineering
Threats published
17 threat lines in the 2026-08-26 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic ChainCRITICAL
- Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free (CVE-2026-78899) and ANGLE RCE (CVE-2026-79282)CRITICAL
- Critical Avada WordPress Theme Flaw (CVE-2026-18431) Enables Zero-Click RCECRITICAL
- Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth Fail-Open Flaws — NVD Scores 5 of 11 CRITICAL/HIGH Despite Apache's Low/Moderate RatingsCRITICAL
- CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted Data (update)CRITICAL
- Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc DemonHIGH
- CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain Patch-Pinning RiskHIGH
- Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter DevicesHIGH
- Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption Campaigns Against NATO/EU InfrastructureHIGH
- "The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware distribution, extortion, and predatory recruitmentHIGH
- Dark Caracal Expands Espionage Arsenal with GoCaracal Framework and AsioGate BackdoorHIGH
- CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud Enumeration (AA26-237A)HIGH
- Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp Linked-Device and OAuth Account TakeoverHIGH
- Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw CVE-2025-8088 (update)HIGH
- Dissection of a PHP Backdoor Leveraging php-win.exe for Stealthy Windows PersistenceMEDIUM
- 24 Malicious npm Packages Abuse Registry Mirrors as Phishing Infrastructure (Fake Cloudflare/Microsoft Login Pages)MEDIUM
- StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited by supply-chain attacks (update)
Techniques observed
151 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1003.006
- T1005
- T1008
- T1012
- T1018
- T1021
- T1021.001
- T1027
- T1027.007
- T1027.009
- T1036
- T1036.005
- T1046
- T1053.005
- T1055
- T1055.012
- T1056
- T1057
- T1059
- T1059.003
- T1059.004
- T1059.006
- T1059.007
- T1059.010
- T1068
- T1069.002
- T1071
- T1071.001
- T1078
- T1078.004
- T1082
- T1083
- T1087.002
- T1087.004
- T1090
- T1090.002
- T1090.003
- T1091
- T1095
- T1098.001
- T1098.003
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1111
- T1114.002
- T1119
- T1123
- T1133
- T1136.001
- T1136.002
- T1136.003
- T1140
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1210
- T1211
- T1212
- T1213
- T1218.005
- T1219
- T1451
- T1484
- T1491.002
- T1497
- T1498.001
- T1499
- T1499.003
- T1499.004
- T1505.003
- T1518
- T1526
- T1528
- T1537
- T1539
- T1543.003
- T1547
- T1548
- T1550
- T1550.001
- T1552
- T1552.001
- T1552.004
- T1552.005
- T1554
- T1555
- T1556
- T1556.009
- T1557
- T1558.001
- T1560.001
- T1561.001
- T1562.001
- T1564.003
- T1565
- T1566
- T1566.001
- T1566.003
- T1567
- T1567.001
- T1567.002
- T1570
- T1571
- T1572
- T1573
- T1573.002
- T1574.001
- T1574.002
- T1574.006
- T1583
- T1583.001
- T1583.003
- T1583.005
- T1583.006
- T1584
- T1584.004
- T1585.001
- T1586.002
- T1587
- T1587.004
- T1588.006
- T1589
- T1589.001
- T1589.002
- T1592.002
- T1595.002
- T1598
- T1598.004
- T1606.001
- T1606.002
- T1608
- T1608.001
- T1608.004
- T1611
- T1615
- T1620
- T1621
- T1649
- T1657
- T1684.001
- T1685
Threat actors
8 named threat actors across the reports.
Nation-state attribution
- China, Russia, Iran, North Korea (multi-nexus convergence; also financially motivated/unattributed criminal actors)
- Russia, Iran
- Lebanon
- Russia
Threat categories
- MALWARE
- SUPPLY_CHAIN
- APT
- VULNERABILITY
- THREAT_INTEL
- PHISHING
Severity breakdown
- critical5
- high9
- medium2
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 73
- file 55
- infrastructure 53
- entity 52
- package 46
- malware 36
- tool 22
- behavioral 11
- technique 1