Summary & highlights
Polymorphic Phishing Page at addresses.performs.vu Regenerates Its Code on Every Load, Defeating Hash-Based Detection. Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake Video-Conference Lures Bypass MFA and Security Awareness Training. Ghost SPN: Active Directory SPN Misconfigurations Enable Stealthy Kerberoasting.
Highlights
- TL-2026-2174 — Ghost SPN: Active Directory SPN Misconfigurations Enable Stealthy Kerberoasting
- TL-2026-2175 — TonRAT Phishing Campaign Impersonating Booking.com Targets Hotel Industry
- TL-2026-2176 — Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion
- TL-2026-2180 — July 2026 Domestic APT Attack Trends (South Korea): LNK-Based Spear Phishing Delivering XenoRAT and Info-Stealers
- TL-2026-2182 — Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)
Theme of the day
Russian state actors targeted EU officials via Signal/WhatsApp account takeover, while unknown groups exploited PaperCut and WatchGuard flaws.
- phishing
- social-engineering
- credential-theft
- lateral-movement
- data-exfiltration
Threats published
30 threat lines in the 2026-08-28 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code ExecutionCRITICAL
- PaperCut NG/MF Actively Exploited Zero-Day Vulnerability Affects All Supported Versions (No CVE Assigned)CRITICAL
- PaperCut NG/MF Application Server Zero-Day: Unauthenticated RCE Under Active Exploitation, No CVE AssignedCRITICAL
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active ExploitationCRITICAL
- Qilin-Linked Campaign Exploits MCP Gateway and LLM Framework Flaws (CVE-2026-59822, CVE-2026-42271, CVE-2026-48710) for RCE and CryptominingCRITICAL
- Shai-Hulud npm Supply-Chain Worm: Two Alleged TeamPCP Members Charged by AFP/FBICRITICAL
- GiveWP WordPress Donation Plugin Flaw (CVE-2026-82222) Lets Attackers Execute Server CommandsCRITICAL
- npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting WormCRITICAL
- Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2) Actively Exploited Across Six BlockchainsCRITICAL
- ServiceNow Patches Four Critical Flaws Including Three CVSS 10.0 Unauthenticated RCE/SQLi Bugs (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, CVE-2026-6876)CRITICAL
- UniBLEed: Unauthenticated Root RCE Chain Over Bluetooth in Unitree G1 EDU Humanoid Robot (CVE-2026-76639, CVE-2026-76640)CRITICAL
- Ghost SPN: Active Directory SPN Misconfigurations Enable Stealthy KerberoastingHIGH
- TonRAT Phishing Campaign Impersonating Booking.com Targets Hotel IndustryHIGH
- Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical IntrusionHIGH
- July 2026 Domestic APT Attack Trends (South Korea): LNK-Based Spear Phishing Delivering XenoRAT and Info-StealersHIGH
- Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)HIGH
- HOOKEDGE: New BlueDelta (APT28/Fancy Bear) Backdoor Abuses Microsoft Edge and webhook.site for C2HIGH
- Snowflake GitHub Actions Workflow Injection Exposes Internal Jira CredentialsHIGH
- TITAN Ransomware Claims AI Platform Analyzes 700GB of Stolen Data Per HourHIGH
- Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached, Attribution UnconfirmedHIGH
- TerminalFix Campaign: ClickFix-Style Lure Deploys Steganographic DLL Sideload and Custom Reverse Tunnel in Multistage IntrusionHIGH
- Chaos Ransomware Claims MacAllister (macallister.com) — 75GB Data Exfiltration Claimed, Leadership Refused EngagementHIGH
- Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data TheftHIGH
- OceanLotus (APT32) Supply-Chain Compromise of FireAnt MetaKit Delivers SPECTRALVIPER Backdoor to Vietnamese Stock Investors (update)HIGH
- Deno-Based Modular RAT & Internal Proxy Delivered via Mailbombing + Microsoft Teams Vishing ("DenoJSEnv") (update)HIGH
- UNC6508 (PRC-Nexus) Trojanizes Unpatched REDCap Research Servers with INFINITERED Malware to Spy on North American Medical, Academic & Military Research (update)HIGH
- ARToken Phishing Panel Abuses Microsoft OAuth Device Code Flow to Hijack Microsoft 365 Accounts (EvilTokens PhaaS) (update)HIGH
- Four Methods for Azure Blob Storage Ransomware: Client-Side Bulk Encryption, CPK, Encryption Scope, and CMK Abuse (update)HIGH
- Polymorphic Phishing Page at addresses.performs.vu Regenerates Its Code on Every Load, Defeating Hash-Based DetectionMEDIUM
- Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake Video-Conference Lures Bypass MFA and Security Awareness TrainingMEDIUM
Techniques observed
209 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0051
- T1003
- T1003.001
- T1003.006
- T1003.007
- T1005
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1021.004
- T1021.006
- T1027
- T1027.003
- T1027.010
- T1027.013
- T1027.014
- T1033
- T1036
- T1036.005
- T1039
- T1041
- T1046
- T1047
- T1048
- T1048.002
- T1052.001
- T1053
- T1053.003
- T1053.005
- T1055
- T1056
- T1056.001
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1059.010
- T1068
- T1069.002
- T1069.003
- T1070
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1074
- T1074.001
- T1074.002
- T1078
- T1078.002
- T1078.003
- T1078.004
- T1082
- T1083
- T1087
- T1087.002
- T1087.004
- T1090
- T1090.003
- T1091
- T1098
- T1098.001
- T1098.004
- T1098.005
- T1102
- T1102.001
- T1102.002
- T1105
- T1110.002
- T1110.004
- T1111
- T1112
- T1114
- T1114.002
- T1114.003
- T1119
- T1129
- T1132
- T1132.001
- T1133
- T1134
- T1136
- T1136.001
- T1140
- T1187
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1210
- T1211
- T1213
- T1213.002
- T1216
- T1218.010
- T1218.011
- T1219
- T1482
- T1484.001
- T1484.002
- T1485
- T1489
- T1490
- T1491.002
- T1496
- T1497
- T1497.001
- T1505
- T1505.003
- T1518
- T1526
- T1528
- T1529
- T1530
- T1531
- T1534
- T1537
- T1543
- T1543.001
- T1543.002
- T1547
- T1547.001
- T1548
- T1550
- T1550.001
- T1550.003
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1552.005
- T1553.002
- T1554
- T1555
- T1555.003
- T1558.003
- T1559
- T1560.001
- T1562.001
- T1564
- T1564.001
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1567.001
- T1567.002
- T1567.004
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.002
- T1574
- T1574.001
- T1574.002
- T1580
- T1583
- T1583.001
- T1583.006
- T1584
- T1584.008
- T1585
- T1586.003
- T1587.001
- T1587.004
- T1588.002
- T1588.005
- T1588.006
- T1589
- T1589.002
- T1591
- T1592.002
- T1593
- T1593.003
- T1594
- T1595
- T1595.002
- T1598
- T1598.002
- T1598.003
- T1598.004
- T1608.005
- T1611
- T1620
- T1621
- T1656
- T1657
- T1684.001
- T1685
- T1685.005
- T1689
Threat actors
12 named threat actors across the reports.
- Silent Ransom Group
- BlueDelta
- TITAN
- Qilin
- Chaos
- Interlock
- Qilin ransomware group
- TeamPCP
- APT32
- MuddyWater
- UNC6508
- EvilTokens (eviltokensadmin)
Nation-state attribution
- Russia
- Vietnam
- Iran
- China
Threat categories
- PHISHING
- THREAT_INTEL
- MALWARE
- RANSOMWARE
- APT
- VULNERABILITY
- SUPPLY_CHAIN
Severity breakdown
- critical11
- high17
- medium2
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- file 158
- network 151
- tool 82
- entity 72
- behavioral 61
- infrastructure 55
- malware 36
- package 27