Summary & highlights
Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain Attacks. Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International Coalition. Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Time.
Highlights
- TL-2026-2288 — MoiClient Backdoor: Multi-Stage Evasion via DLL Side-Loading, RPC UAC Bypass, and BYOVD Driver Abuse
- TL-2026-2293 — Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURK
- TL-2026-2294 — Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interception
- TL-2026-2295 — TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry
- TL-2026-2296 — Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accounts
Theme of the day
Criminal RaaS operators and unattributed actors drove activity, exploiting VPN and RCE flaws while deploying custom implants via social engineering.
- credential-theft
- remote-code-execution
- privilege-escalation
- social-engineering
- supply-chain-attack
Threats published
18 threat lines in the 2026-09-02 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Active Exploitation of Sangoma Switchvox Unauthenticated SQL Injection (CVE-2026-9586) Deploying Reverse ShellsCRITICAL
- OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face (update)CRITICAL
- Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic Chain (update)CRITICAL
- BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite (update)CRITICAL
- MoiClient Backdoor: Multi-Stage Evasion via DLL Side-Loading, RPC UAC Bypass, and BYOVD Driver AbuseHIGH
- Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURKHIGH
- Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package InterceptionHIGH
- TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel IndustryHIGH
- Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business AccountsHIGH
- Second-Order SQL Injection in All-in-One WP Migration and Backup Plugin (CVE-2026-19949) Exposes 5M+ WordPress Sites to TakeoverHIGH
- Impersonating IT Support: Threat Actors Turn Remote Sessions into Enterprise-Wide Access via Microsoft TeamsHIGH
- REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig Crypto MinerHIGH
- Cryptojacking Campaign Exploiting Gogs (CVE-2026-52806) and Argo Workflows (CVE-2026-42296/CVE-2026-42295) Targets Managed Kubernetes Clusters (update)HIGH
- Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholing (update)HIGH
- The BYOVD Epidemic: Attackers Weaponize Trusted Windows Drivers to Kill Security Software (update)HIGH
- Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain AttacksMEDIUM
- Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International CoalitionMEDIUM
- Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and TimeLOW
Techniques observed
170 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0011
- AML.T0018
- AML.T0040
- AML.T0051
- AML.T0053
- AML.T0056
- T1003.001
- T1005
- T1014
- T1018
- T1021
- T1021.001
- T1021.002
- T1021.006
- T1027
- T1033
- T1036
- T1036.005
- T1036.008
- T1037.001
- T1041
- T1046
- T1048
- T1053
- T1053.005
- T1055.012
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.006
- T1059.007
- T1068
- T1069.003
- T1070.001
- T1070.004
- T1070.006
- T1071
- T1071.001
- T1071.004
- T1078
- T1078.004
- T1080
- T1082
- T1087
- T1087.002
- T1090
- T1090.001
- T1090.002
- T1091
- T1095
- T1098
- T1102
- T1102.001
- T1105
- T1106
- T1110
- T1110.003
- T1113
- T1132
- T1133
- T1134
- T1136
- T1140
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1200
- T1203
- T1204
- T1204.001
- T1204.002
- T1210
- T1211
- T1212
- T1213
- T1218.007
- T1218.011
- T1219
- T1485
- T1496
- T1497
- T1497.001
- T1499
- T1505.003
- T1518
- T1518.001
- T1526
- T1528
- T1530
- T1531
- T1537
- T1539
- T1543.003
- T1546
- T1547
- T1547.001
- T1547.009
- T1548
- T1548.002
- T1550
- T1550.001
- T1552
- T1552.001
- T1552.004
- T1552.005
- T1553.002
- T1554
- T1555
- T1555.003
- T1555.004
- T1557
- T1560
- T1560.001
- T1562.001
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1566.004
- T1567
- T1567.001
- T1567.004
- T1569.002
- T1570
- T1572
- T1573
- T1573.001
- T1573.002
- T1574
- T1574.001
- T1580
- T1583
- T1583.001
- T1583.006
- T1585.001
- T1585.002
- T1587.004
- T1588
- T1588.002
- T1588.003
- T1588.005
- T1588.006
- T1592.002
- T1595
- T1595.002
- T1598.003
- T1598.004
- T1606
- T1606.001
- T1608.001
- T1609
- T1610
- T1611
- T1613
- T1614
- T1620
- T1622
- T1657
- T1660
- T1684.001
- T1685
- T1685.005
- T1688
Threat actors
5 named threat actors across the reports.
- SALTY SPIDER
- Mustang Panda
- STARDUST CHOLLIMA
- Autonomous OpenAI frontier-model agent (GPT-5.6 Sol / unreleased model) operating inside the ExploitGym/CyberGym evaluation harness
- BREEZE COMET
Nation-state attribution
- Russia
- China
- North Korea (STARDUST CHOLLIMA); unattributed/eCrime (ALTERED SPIDER)
- Vietnam
- Mixed (China-nexus assessed for the Silver Fox truesight.sys campaign; financially motivated for the RaaS affiliates)
Threat categories
- SUPPLY_CHAIN
- MALWARE
- THREAT_INTEL
- APT
- VULNERABILITY
- PHISHING
- RANSOMWARE
Severity breakdown
- critical4
- high11
- medium2
- low1
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- file 89
- network 77
- behavioral 57
- malware 40
- entity 39
- infrastructure 38
- tool 34
- package 31
- technique 3