Threadlinqs IntelligenceStart free

Daily debrief · Wednesday2026-09-09

Daily Intelligence Briefing — Wednesday, September 9, 2026

7 critical8 high

On 2026-09-09, Threadlinqs published 9 new threat reports and updated 6, 7 rated critical and 8 high, spanning 156 MITRE ATT&CK techniques and 4 named threat actors. Coverage that day added 135 new detection rules and 288 extracted indicators.

New threats
96 updated
Critical / high
157 critical · 8 high
ATT&CK techniques
156Observed in the day’s reports
Threat actors
4Named in the reports
Indicators
288Count only · values are Red+
Detection rules
135New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass. Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes Poultry. Tesla Wall Connector Gen 3: Anti-Downgrade (Security Ratchet) Bypass via Charge Port Connector.

Highlights

  • TL-2026-2416 — Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass
  • TL-2026-2420 — Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes Poultry
  • TL-2026-2425 — Tesla Wall Connector Gen 3: Anti-Downgrade (Security Ratchet) Bypass via Charge Port Connector
  • TL-2026-2453 — Browser-in-the-Browser Phishing Campaign Abuses ScreenConnect RMM to Gain Remote Access
  • TL-2026-2411 — Iran Exploits SS7 Roaming Infrastructure and Commercial Ad-Tech to Track US Military Smartphones During Operation Epic Fury

Theme of the day

Routine activity — no dominant theme emerged.

  • cisa-kev
  • privilege-escalation
  • phishing
  • session-hijacking
  • defense-evasion

Threats published

15 threat lines in the 2026-09-09 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

156 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

4 named threat actors across the reports.

Nation-state attribution

  • Russia; Iran (contested/suspected false flag)
  • Iran
  • China

Threat categories

  • THREAT_INTEL
  • ICS_SCADA
  • VULNERABILITY
  • PHISHING
  • APT

Severity breakdown

  • critical7
  • high8
  • medium0
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

288 indicators of compromise · Red and above. Compare plans
  • network 58
  • behavioral 53
  • file 44
  • infrastructure 29
  • entity 28
  • tool 28
  • malware 17
  • technique 16
  • package 12
  • tool_name 3
135 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans