Summary & highlights
Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence Group Q3 2026 AI Threat Tracker). QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service. The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy RATs and Infostealers.
Highlights
- TL-2026-2390 — Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence Group Q3 2026 AI Threat Tracker)
- TL-2026-2397 — QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service
- TL-2026-2402 — The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy RATs and Infostealers
- TL-2026-2405 — China-Based AI Companies Conducting Industrial-Scale Knowledge Distillation Campaigns Against U.S. Frontier AI Models
- TL-2026-2387 — ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport Manager 12.44 (UAT-10820)
Theme of the day
A steady stream of new threats surfaced today, dominated by unattributed activity, with APT-C-60, General Boss, and Lovely also emerging; no common tags were reported, indicating varied, low-signature campaigns.
- credential-theft
- lateral-movement
- financially-motivated
- persistence
- defense-evasion
Threats published
16 threat lines in the 2026-09-08 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport Manager 12.44 (UAT-10820)CRITICAL
- Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745 Unauthenticated Deserialization RCE, CVE-2026-12645-12647 Missing Authorization RCE, CVE-2026-18851 EPMM Privilege Escalation, CVE-2026-83527 Sentry Auth Bypass)CRITICAL
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEsCRITICAL
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)CRITICAL
- Adobe Campaign Classic Critical OS Command Injection (CVE-2026-82004, APSB26-142, CVSS 10.0)CRITICAL
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint DefensesCRITICAL
- FortiBleed Credential Theft Campaign Linked to INC and Lynx Ransomware Operations (update)CRITICAL
- AsyncAPI npm Supply Chain Attack: Pwn-Request GitHub Actions Compromise Deploys Miasma Tasking Framework (update)CRITICAL
- Daxin Returns: China-Linked Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Backdoor (update)CRITICAL
- StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores (update)CRITICAL
- BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass (update)CRITICAL
- Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence Group Q3 2026 AI Threat Tracker)HIGH
- QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-ServiceHIGH
- The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy RATs and InfostealersHIGH
- China-Based AI Companies Conducting Industrial-Scale Knowledge Distillation Campaigns Against U.S. Frontier AI ModelsHIGH
- "Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaign (update)HIGH
Techniques observed
182 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0006
- AML.T0008
- AML.T0010
- AML.T0012
- AML.T0024.002
- AML.T0040
- AML.T0042
- AML.T0048.004
- AML.T0051
- AML.T0053
- AML.T0054
- T1001.003
- T1003
- T1003.003
- T1005
- T1008
- T1014
- T1016
- T1018
- T1021
- T1021.001
- T1021.004
- T1027
- T1027.002
- T1027.007
- T1027.013
- T1036
- T1036.003
- T1036.004
- T1036.005
- T1036.008
- T1037.001
- T1039
- T1040
- T1041
- T1046
- T1048
- T1048.003
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.001
- T1055.012
- T1056
- T1056.001
- T1056.003
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1070
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1078
- T1078.004
- T1082
- T1083
- T1087
- T1090
- T1090.002
- T1095
- T1098
- T1102
- T1102.001
- T1102.002
- T1102.003
- T1105
- T1106
- T1110
- T1110.001
- T1110.004
- T1111
- T1113
- T1114
- T1115
- T1119
- T1133
- T1134
- T1136
- T1140
- T1185
- T1190
- T1195.001
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1205
- T1210
- T1211
- T1218
- T1218.011
- T1219
- T1480.001
- T1485
- T1486
- T1489
- T1490
- T1491
- T1497
- T1497.001
- T1505
- T1505.002
- T1505.003
- T1518.001
- T1528
- T1539
- T1543
- T1543.001
- T1543.002
- T1543.003
- T1546.003
- T1546.004
- T1547
- T1547.001
- T1550
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1552.005
- T1553
- T1555
- T1555.001
- T1555.003
- T1555.005
- T1556
- T1556.006
- T1557
- T1558
- T1558.001
- T1560
- T1562
- T1564.001
- T1566
- T1566.001
- T1566.002
- T1567
- T1569
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1574.001
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1584
- T1585.001
- T1586.003
- T1587
- T1587.001
- T1588
- T1588.001
- T1588.002
- T1589
- T1592
- T1595
- T1595.001
- T1596
- T1597.002
- T1598.003
- T1600
- T1608.001
- T1614
- T1620
- T1622
- T1657
- T1685
- T1690
Threat actors
9 named threat actors across the reports.
- nethoodus
- China-Based AI Companies
- UAT-10820
- Hyadina
- bandcampro
- FortiBleed Initial Access Broker
- M-Red-Team
- China-linked espionage group
- General Boss
Nation-state attribution
- China
- Russia
Threat categories
- THREAT_INTEL
- MALWARE
- APT
- VULNERABILITY
- RANSOMWARE
- THREAT_ACTOR
- SUPPLY_CHAIN
- PHISHING
Severity breakdown
- critical11
- high5
- medium0
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 174
- file 139
- behavioral 80
- tool 26
- infrastructure 22
- malware 20
- entity 8
- package 6