# Daily Intelligence Briefing — Wednesday, September 9, 2026

> On 2026-09-09, Threadlinqs published 9 new threat reports and updated 6, 7 rated critical and 8 high, spanning 156 MITRE ATT&CK techniques and 4 named threat actors. Coverage that day added 135 new detection rules and 288 extracted indicators.

- **Edition:** 2026-09-09 (Wednesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-09-09
- **Last updated:** 2026-09-15
- **New threats:** 9 (6 updated)
- **Critical / high:** 7 critical, 8 high, 0 medium, 0 low
- **ATT&CK techniques:** 156
- **Threat actors:** 4
- **Indicators (count only):** 288
- **New detection rules (count only):** 135

## Summary & highlights

Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass. Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes Poultry. Tesla Wall Connector Gen 3: Anti-Downgrade (Security Ratchet) Bypass via Charge Port Connector.

- [TL-2026-2416](https://intel.threadlinqs.com/threat/TL-2026-2416) — Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass
- [TL-2026-2420](https://intel.threadlinqs.com/threat/TL-2026-2420) — Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes Poultry
- [TL-2026-2425](https://intel.threadlinqs.com/threat/TL-2026-2425) — Tesla Wall Connector Gen 3: Anti-Downgrade (Security Ratchet) Bypass via Charge Port Connector
- [TL-2026-2453](https://intel.threadlinqs.com/threat/TL-2026-2453) — Browser-in-the-Browser Phishing Campaign Abuses ScreenConnect RMM to Gain Remote Access
- [TL-2026-2411](https://intel.threadlinqs.com/threat/TL-2026-2411) — Iran Exploits SS7 Roaming Infrastructure and Commercial Ad-Tech to Track US Military Smartphones During Operation Epic Fury

## Theme of the day

Routine activity — no dominant theme emerged.

cisa-kev, privilege-escalation, phishing, session-hijacking, defense-evasion

## Threats published

- [TL-2026-2411](https://intel.threadlinqs.com/threat/TL-2026-2411) — CRITICAL — Iran Exploits SS7 Roaming Infrastructure and Commercial Ad-Tech to Track US Military Smartphones During Operation Epic Fury
- [TL-2026-2412](https://intel.threadlinqs.com/threat/TL-2026-2412) — CRITICAL — DeepSeek Harness Authentication Bypass Lets Sandboxed AI Agents Escape via Single Command (CVE-2026-82533)
- [TL-2026-2413](https://intel.threadlinqs.com/threat/TL-2026-2413) — CRITICAL — China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models
- [TL-2026-2415](https://intel.threadlinqs.com/threat/TL-2026-2415) — CRITICAL — CVE-2026-86218 — Unauthenticated Pre-Auth Remote Code Execution in N-able N-central (Active Exploitation, CISA KEV)
- [TL-2026-2418](https://intel.threadlinqs.com/threat/TL-2026-2418) — CRITICAL — Zero-click Pixel 10 exploit chain: VPU driver mmap flaw (CVE-2026-0106) enables arbitrary kernel read/write, chained with Dolby decoder RCE (CVE-2025-54957)
- [TL-2026-1140](https://intel.threadlinqs.com/threat/TL-2026-1140) — CRITICAL — CitrixBleed 2.0: CVE-2026-8451 NetScaler SAML IDP Memory Overread Under Active Exploitation (update)
- [TL-2026-2407](https://intel.threadlinqs.com/threat/TL-2026-2407) — CRITICAL — Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046) (update)
- [TL-2026-2416](https://intel.threadlinqs.com/threat/TL-2026-2416) — HIGH — Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass
- [TL-2026-2420](https://intel.threadlinqs.com/threat/TL-2026-2420) — HIGH — Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes Poultry
- [TL-2026-2425](https://intel.threadlinqs.com/threat/TL-2026-2425) — HIGH — Tesla Wall Connector Gen 3: Anti-Downgrade (Security Ratchet) Bypass via Charge Port Connector
- [TL-2026-2453](https://intel.threadlinqs.com/threat/TL-2026-2453) — HIGH — Browser-in-the-Browser Phishing Campaign Abuses ScreenConnect RMM to Gain Remote Access
- [TL-2026-0717](https://intel.threadlinqs.com/threat/TL-2026-0717) — HIGH — SolarWinds Serv-U DoS (CVE-2026-28318) — Actively Exploited Uncontrolled Resource Consumption via Content-Encoding: deflate POST (update)
- [TL-2026-1538](https://intel.threadlinqs.com/threat/TL-2026-1538) — HIGH — CVE-2026-26133: Cross-Prompt Injection in Microsoft Copilot Email/Teams Summarization Enables AI-Mediated Phishing (update)
- [TL-2026-1543](https://intel.threadlinqs.com/threat/TL-2026-1543) — HIGH — CVE-2025-29824: Windows CLFS Use-After-Free Privilege Escalation Chained with Cisco ASA Compromise and PipeMagic/Storm-2460 Ransomware Attacks (update)
- [TL-2026-2424](https://intel.threadlinqs.com/threat/TL-2026-2424) — HIGH — Linux Kernel LPE Surge: Copy Fail (CVE-2026-31431), Dirty Frag/Fragnesia (CVE-2026-43284/CVE-2026-43500/CVE-2026-46300), and CrackArmor AppArmor Flaws vs. Defense-in-Depth Mitigations (update)

## Techniques observed

AML.T0008, AML.T0024, AML.T0024.002, AML.T0040, AML.T0042, AML.T0048, AML.T0048.003, [AML.T0051](https://intel.threadlinqs.com/technique/AML.T0051), [AML.T0051.001](https://intel.threadlinqs.com/technique/AML.T0051.001), AML.T0052, [AML.T0053](https://intel.threadlinqs.com/technique/AML.T0053), [AML.T0054](https://intel.threadlinqs.com/technique/AML.T0054), AML.T0057, AML.T0066, AML.T0067, T0822, [T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.001](https://intel.threadlinqs.com/technique/T1003.001), [T1003.002](https://intel.threadlinqs.com/technique/T1003.002), [T1003.003](https://intel.threadlinqs.com/technique/T1003.003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.004](https://intel.threadlinqs.com/technique/T1021.004), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.001, [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1404](https://intel.threadlinqs.com/technique/T1404), [T1426](https://intel.threadlinqs.com/technique/T1426), [T1484](https://intel.threadlinqs.com/technique/T1484), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1495](https://intel.threadlinqs.com/technique/T1495), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1498](https://intel.threadlinqs.com/technique/T1498), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1499.002](https://intel.threadlinqs.com/technique/T1499.002), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1539](https://intel.threadlinqs.com/technique/T1539), T1542.001, [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.001](https://intel.threadlinqs.com/technique/T1548.001), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1558](https://intel.threadlinqs.com/technique/T1558), T1558.001, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1575](https://intel.threadlinqs.com/technique/T1575), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), T1590.005, [T1591](https://intel.threadlinqs.com/technique/T1591), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.001](https://intel.threadlinqs.com/technique/T1595.001), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1596.005](https://intel.threadlinqs.com/technique/T1596.005), [T1598](https://intel.threadlinqs.com/technique/T1598), T1601.002, [T1606](https://intel.threadlinqs.com/technique/T1606), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1626](https://intel.threadlinqs.com/technique/T1626), T1658, T1664, [T1684.001](https://intel.threadlinqs.com/technique/T1684.001), [T1685](https://intel.threadlinqs.com/technique/T1685)

## Threat actors

[Sandworm](https://intel.threadlinqs.com/actor/Sandworm), Iranian state-aligned threat actor, [China AI Distillation Campaign](https://intel.threadlinqs.com/actor/China%20AI%20Distillation%20Campaign), [Storm-2460](https://intel.threadlinqs.com/actor/Storm-2460)

Nation-state attribution: Russia; Iran (contested/suspected false flag), Iran, China

Threat categories: THREAT_INTEL, ICS_SCADA, VULNERABILITY, PHISHING, APT

## Severity breakdown

- critical: 7
- high: 8
- medium: 0
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 288 (network 58, behavioral 53, file 44, infrastructure 29, entity 28, tool 28, malware 17, technique 16, package 12, tool_name 3)
- New detection rules: 135 (100% of the day’s threats covered)

## More editions

- Previous: [2026-09-08](https://intel.threadlinqs.com/debrief/2026-09-08)
- Next: [2026-09-13](https://intel.threadlinqs.com/debrief/2026-09-13)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-09-09
