Summary & highlights
Threat Actors Impersonate OpenAI, Anthropic, and DeepSeek AI Crawlers to Harvest Credentials and Secrets. Emperador ransomware group claims breach of Uniguaçu (Brazilian education sector). Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware.
Highlights
- TL-2026-2197 — Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware
- TL-2026-2199 — ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked to Vanilla Tempest
- TL-2026-2201 — Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations System
- TL-2026-2202 — TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and India
- TL-2026-2203 — Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel via ClickFix-Style DLL Sideloading
Theme of the day
Unattributed threats dominated the day, with Qilin ransomware and Silent Ransom Group also active, alongside diverse malware like AMOS and ArechClient2.
- privilege-escalation
- remote-code-execution
- double-extortion
- scheduled-task-persistence
- social-engineering
Threats published
32 threat lines in the 2026-08-29 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and Salesforce/Snowflake CompromiseCRITICAL
- Five Critical WordPress Plugin/Theme Flaws (CVSS up to 10.0) Enable Site Takeover or RCE: WPMU DEV Dashboard, Avada/Fusion Builder, TranslatePress, Pods, GiveWPCRITICAL
- Pre-Authentication Remote Code Execution in SPIP CMS (CVE-2026-77806) — Actively ExploitedCRITICAL
- TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload (update)CRITICAL
- Gitea Remote Code Execution via diffpatch Git Hook Installation (CVE-2026-60004) (update)CRITICAL
- Gogs Critical RCE via Path Traversal in Organization Names (CVE-2026-52813) (update)CRITICAL
- Critical Avada WordPress Theme Flaw (CVE-2026-18431) Enables Zero-Click RCE (update)CRITICAL
- CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Execution (update)CRITICAL
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation (update)CRITICAL
- ServiceNow Patches Four Critical Flaws Including Three CVSS 10.0 Unauthenticated RCE/SQLi Bugs (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, CVE-2026-6876) (update)CRITICAL
- UniBLEed: Unauthenticated Root RCE Chain Over Bluetooth in Unitree G1 EDU Humanoid Robot (CVE-2026-76639, CVE-2026-76640) (update)CRITICAL
- Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute MalwareHIGH
- ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked to Vanilla TempestHIGH
- Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations SystemHIGH
- TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and IndiaHIGH
- Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel via ClickFix-Style DLL SideloadingHIGH
- Rhysida Ransomware Claims Berlin State Government Breach Ahead of September ElectionHIGH
- PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)HIGH
- APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and TürkiyeHIGH
- Hundreds of WordPress Sites Hijacked via Malicious Plugins to Deploy Amatera Stealer through EtherHiding and ClickFixHIGH
- Fake Beijing Institute of Technology Resume Lure Delivers SNOWLIGHT Shellcode and Fileless VShell RAT to Chinese Academic ResearchersHIGH
- Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela BreachHIGH
- CVE-2026-53362 ("ipv6_frag_escape"): Linux Kernel IPv6 Fragmentation Flaw Enables Container-to-Host Privilege Escalation, Actively Exploited — Added to CISA KEVHIGH
- Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access (CVE-2025-31718 + Unpatched MPU Privilege Escalation)HIGH
- BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling Large-Scale Credential Harvesting, AiTM MFA Bypass, and Account Takeover (update)HIGH
- FishMonger (I-SOON / Winnti) Ports SprySOCKS Backdoor to Windows — WIN_DRV (RawWNPF Kernel Rootkit) & WIN_PLUS Variants (update)HIGH
- BlueDelta (GRU/APT28) Targets Defense and Diplomacy with HOOKEDGE Backdoor (update)HIGH
- SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governments (update)HIGH
- Chaos Ransomware Claims MacAllister (macallister.com) — 75GB Data Exfiltration Claimed, Leadership Refused Engagement (update)HIGH
- Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Theft (update)HIGH
- Threat Actors Impersonate OpenAI, Anthropic, and DeepSeek AI Crawlers to Harvest Credentials and SecretsMEDIUM
- Emperador ransomware group claims breach of Uniguaçu (Brazilian education sector)MEDIUM
Techniques observed
221 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1003
- T1003.003
- T1005
- T1007
- T1008
- T1010
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1021.005
- T1027
- T1027.002
- T1027.003
- T1027.010
- T1027.013
- T1033
- T1036
- T1036.005
- T1036.008
- T1041
- T1046
- T1047
- T1048
- T1053
- T1053.003
- T1053.005
- T1055
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1069.002
- T1070
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1074
- T1074.001
- T1078
- T1078.003
- T1078.004
- T1080
- T1082
- T1083
- T1087
- T1087.002
- T1090
- T1090.001
- T1090.003
- T1091
- T1095
- T1098
- T1098.004
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110.003
- T1110.004
- T1111
- T1112
- T1113
- T1114
- T1115
- T1119
- T1124
- T1125
- T1132
- T1132.002
- T1133
- T1134
- T1136
- T1136.001
- T1140
- T1185
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1205
- T1210
- T1211
- T1212
- T1213
- T1218
- T1218.005
- T1218.007
- T1218.011
- T1219
- T1480
- T1482
- T1485
- T1486
- T1490
- T1491
- T1491.002
- T1496
- T1496.001
- T1497
- T1497.001
- T1497.003
- T1499.004
- T1505
- T1505.003
- T1518
- T1518.001
- T1526
- T1528
- T1529
- T1530
- T1537
- T1539
- T1542.003
- T1543
- T1543.001
- T1543.002
- T1546
- T1547
- T1547.001
- T1547.013
- T1548
- T1550
- T1550.001
- T1552
- T1552.001
- T1552.004
- T1552.005
- T1553
- T1553.002
- T1554
- T1555
- T1555.001
- T1555.003
- T1556
- T1557
- T1558.003
- T1560
- T1564
- T1564.001
- T1564.003
- T1564.004
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1567.001
- T1567.002
- T1567.004
- T1569
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1574.001
- T1580
- T1583
- T1583.001
- T1583.006
- T1584
- T1584.004
- T1585
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.001
- T1588.002
- T1588.005
- T1588.006
- T1589.002
- T1590
- T1591
- T1592
- T1595
- T1595.002
- T1595.003
- T1598
- T1601.001
- T1606
- T1608
- T1610
- T1611
- T1613
- T1614
- T1620
- T1621
- T1622
- T1656
- T1657
- T1664
- T1665
- T1681
- T1684.001
- T1685
- T1685.005
Threat actors
16 named threat actors across the reports.
- Emperador
- Vanilla Tempest
- Qilin
- TA4922
- Rhysida
- PEAR
- APT28
- Dark Caracal
- ShinyHunters
- BlueKit operators
- Earth Lusca
- BlueDelta
- SilkParasite
- Chaos
- Interlock
- TeamPCP
Nation-state attribution
- Russia
- CN
- Lebanon
- China
Threat categories
- THREAT_INTEL
- RANSOMWARE
- MALWARE
- DATA_BREACH
- VULNERABILITY
- PHISHING
- APT
- SUPPLY_CHAIN
Severity breakdown
- critical11
- high19
- medium2
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- file 214
- network 193
- entity 90
- behavioral 83
- infrastructure 64
- tool 58
- malware 43
- package 36
- technique 3