Summary & highlights
Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injection. Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration. OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 / UNK_OutFlareAZ).
Highlights
- TL-2026-2472 — Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration
- TL-2026-2476 — OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 / UNK_OutFlareAZ)
- TL-2026-2477 — CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege Escalation
- TL-2026-2479 — CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument Injection
- TL-2026-2480 — CVE-2025-59201: Windows Network Connection Status Indicator (NCSI) Elevation of Privilege via Registry Symbolic Link Abuse
Theme of the day
Routine activity — no dominant theme emerged.
- privilege-escalation
- local-privilege-escalation
- siemens
- remote-code-execution
- social-engineering
Threats published
17 threat lines in the 2026-09-13 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit MalwareCRITICAL
- Dell ObjectScale Critical Deserialization Flaw (CVE-2026-70416, CVSS 10.0) Enables Unauthenticated RCECRITICAL
- Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)CRITICAL
- Multiple Fortinet FortiOS Vulnerabilities (incl. CVE-2024-23113) Affect Siemens RUGGEDCOM APE1808 via Bundled Fortinet NGFW < V7.4.3 (SSA-832273)CRITICAL
- TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload (update)CRITICAL
- GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for Golden Gh0st RAT and Zhong Stealer Distribution (update)CRITICAL
- CVE-2024-49775: Unauthenticated Heap-Based Buffer Overflow in Siemens User Management Component (UMC) Enables Remote Code Execution (update)CRITICAL
- Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data ExfiltrationHIGH
- OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 / UNK_OutFlareAZ)HIGH
- CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege EscalationHIGH
- CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument InjectionHIGH
- CVE-2025-59201: Windows Network Connection Status Indicator (NCSI) Elevation of Privilege via Registry Symbolic Link AbuseHIGH
- Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC BypassHIGH
- SmokeLoader Backdoor/Loader: Process Hollowing Injection into explorer.exe with Anti-VM/Anti-Debug Evasion (Smoky Spider)HIGH
- Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding, JADESNOW/INVISIBLEFERRET, SharkStealer)HIGH
- Multiple Vulnerabilities in Nozomi Guardian/CMC Before 25.4.0 on Siemens RUGGEDCOM APE1808 Devices (CVE-2024-13089, CVE-2024-13090, CVE-2025-3719, CVE-2025-40889, et al.)HIGH
- Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment InjectionMEDIUM
Techniques observed
179 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T0819
- T0822
- T0859
- T1001
- T1003
- T1005
- T1007
- T1012
- T1016
- T1020
- T1021
- T1021.001
- T1027
- T1027.003
- T1027.011
- T1027.013
- T1033
- T1036
- T1036.005
- T1041
- T1046
- T1047
- T1048
- T1053.005
- T1055
- T1055.012
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1059.008
- T1069.003
- T1070
- T1070.004
- T1070.008
- T1071
- T1071.001
- T1074
- T1078
- T1078.003
- T1078.004
- T1080
- T1082
- T1083
- T1087
- T1087.004
- T1090
- T1090.002
- T1095
- T1098
- T1102
- T1102.001
- T1105
- T1106
- T1110.004
- T1112
- T1113
- T1114.001
- T1114.002
- T1119
- T1134.001
- T1134.002
- T1134.004
- T1136.001
- T1140
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1210
- T1213
- T1213.002
- T1218.005
- T1218.007
- T1480
- T1485
- T1486
- T1489
- T1490
- T1496
- T1497
- T1497.001
- T1499.004
- T1505
- T1518
- T1518.001
- T1526
- T1528
- T1529
- T1530
- T1531
- T1543
- T1543.002
- T1543.003
- T1546
- T1547
- T1547.001
- T1547.013
- T1548
- T1548.001
- T1548.002
- T1548.003
- T1550
- T1552
- T1552.001
- T1552.005
- T1553
- T1553.002
- T1554
- T1555
- T1555.003
- T1556
- T1556.006
- T1556.009
- T1557
- T1559
- T1560
- T1562.001
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1567.001
- T1567.004
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1574.001
- T1574.002
- T1574.006
- T1574.011
- T1580
- T1583
- T1583.001
- T1583.006
- T1584
- T1585
- T1585.002
- T1587.001
- T1587.004
- T1588
- T1588.003
- T1588.005
- T1588.006
- T1589.001
- T1589.002
- T1589.003
- T1591
- T1595
- T1595.002
- T1598.003
- T1608
- T1610
- T1611
- T1613
- T1620
- T1622
- T1656
- T1657
- T1685
- T1685.005
Threat actors
6 named threat actors across the reports.
Nation-state attribution
- Russia
- North Korea (DPRK)
- China
Threat categories
- VULNERABILITY
- PHISHING
- CLOUD
- RANSOMWARE
- MALWARE
- THREAT_INTEL
- SUPPLY_CHAIN
Severity breakdown
- critical7
- high9
- medium1
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 123
- file 97
- infrastructure 42
- entity 39
- package 27
- behavioral 24
- tool 23
- malware 21
- credential 1
- technique 1