# Daily Intelligence Briefing — Sunday, September 13, 2026

> On 2026-09-13, Threadlinqs published 14 new threat reports and updated 3, 7 rated critical and 9 high, spanning 179 MITRE ATT&CK techniques and 6 named threat actors. Coverage that day added 153 new detection rules and 398 extracted indicators.

- **Edition:** 2026-09-13 (Sunday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-09-13
- **Last updated:** 2026-09-19
- **New threats:** 14 (3 updated)
- **Critical / high:** 7 critical, 9 high, 1 medium, 0 low
- **ATT&CK techniques:** 179
- **Threat actors:** 6
- **Indicators (count only):** 398
- **New detection rules (count only):** 153

## Summary & highlights

Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injection. Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration. OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 / UNK_OutFlareAZ).

- [TL-2026-2472](https://intel.threadlinqs.com/threat/TL-2026-2472) — Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration
- [TL-2026-2476](https://intel.threadlinqs.com/threat/TL-2026-2476) — OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 / UNK_OutFlareAZ)
- [TL-2026-2477](https://intel.threadlinqs.com/threat/TL-2026-2477) — CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege Escalation
- [TL-2026-2479](https://intel.threadlinqs.com/threat/TL-2026-2479) — CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument Injection
- [TL-2026-2480](https://intel.threadlinqs.com/threat/TL-2026-2480) — CVE-2025-59201: Windows Network Connection Status Indicator (NCSI) Elevation of Privilege via Registry Symbolic Link Abuse

## Theme of the day

Routine activity — no dominant theme emerged.

privilege-escalation, local-privilege-escalation, siemens, remote-code-execution, social-engineering

## Threats published

- [TL-2026-2474](https://intel.threadlinqs.com/threat/TL-2026-2474) — CRITICAL — CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware
- [TL-2026-2475](https://intel.threadlinqs.com/threat/TL-2026-2475) — CRITICAL — Dell ObjectScale Critical Deserialization Flaw (CVE-2026-70416, CVSS 10.0) Enables Unauthenticated RCE
- [TL-2026-2486](https://intel.threadlinqs.com/threat/TL-2026-2486) — CRITICAL — Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)
- [TL-2026-2489](https://intel.threadlinqs.com/threat/TL-2026-2489) — CRITICAL — Multiple Fortinet FortiOS Vulnerabilities (incl. CVE-2024-23113) Affect Siemens RUGGEDCOM APE1808 via Bundled Fortinet NGFW < V7.4.3 (SSA-832273)
- [TL-2026-0304](https://intel.threadlinqs.com/threat/TL-2026-0304) — CRITICAL — TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload (update)
- [TL-2026-1579](https://intel.threadlinqs.com/threat/TL-2026-1579) — CRITICAL — GoldenEyeDog / CylindricalCanine Breaches DigiCert Support System to Hijack EV Code-Signing Certificates for Golden Gh0st RAT and Zhong Stealer Distribution (update)
- [TL-2026-2488](https://intel.threadlinqs.com/threat/TL-2026-2488) — CRITICAL — CVE-2024-49775: Unauthenticated Heap-Based Buffer Overflow in Siemens User Management Component (UMC) Enables Remote Code Execution (update)
- [TL-2026-2472](https://intel.threadlinqs.com/threat/TL-2026-2472) — HIGH — Passkey-Themed Help Desk Phishing Hijacks Microsoft 365 Cloud Accounts for Data Exfiltration
- [TL-2026-2476](https://intel.threadlinqs.com/threat/TL-2026-2476) — HIGH — OAuth Client ID Spoofing Enables Stealthy Enumeration of Microsoft Entra ID Accounts (UNK_pyreq2323 / UNK_OutFlareAZ)
- [TL-2026-2477](https://intel.threadlinqs.com/threat/TL-2026-2477) — HIGH — CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege Escalation
- [TL-2026-2479](https://intel.threadlinqs.com/threat/TL-2026-2479) — HIGH — CVE-2026-20817: Windows Error Reporting Service (WerSvc.dll) Local Privilege Escalation via ALPC Argument Injection
- [TL-2026-2480](https://intel.threadlinqs.com/threat/TL-2026-2480) — HIGH — CVE-2025-59201: Windows Network Connection Status Indicator (NCSI) Elevation of Privilege via Registry Symbolic Link Abuse
- [TL-2026-2481](https://intel.threadlinqs.com/threat/TL-2026-2481) — HIGH — Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypass
- [TL-2026-2482](https://intel.threadlinqs.com/threat/TL-2026-2482) — HIGH — SmokeLoader Backdoor/Loader: Process Hollowing Injection into explorer.exe with Anti-VM/Anti-Debug Evasion (Smoky Spider)
- [TL-2026-2484](https://intel.threadlinqs.com/threat/TL-2026-2484) — HIGH — Blockchain-Based C2 Evolution: Nation-State Actors Adopt Smart-Contract C2 (EtherHiding, JADESNOW/INVISIBLEFERRET, SharkStealer)
- [TL-2026-2487](https://intel.threadlinqs.com/threat/TL-2026-2487) — HIGH — Multiple Vulnerabilities in Nozomi Guardian/CMC Before 25.4.0 on Siemens RUGGEDCOM APE1808 Devices (CVE-2024-13089, CVE-2024-13090, CVE-2025-3719, CVE-2025-40889, et al.)
- [TL-2026-2478](https://intel.threadlinqs.com/threat/TL-2026-2478) — MEDIUM — Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injection

## Techniques observed

T0819, T0822, T0859, [T1001](https://intel.threadlinqs.com/technique/T1001), [T1003](https://intel.threadlinqs.com/technique/T1003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1007](https://intel.threadlinqs.com/technique/T1007), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.003](https://intel.threadlinqs.com/technique/T1027.003), T1027.011, [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.012](https://intel.threadlinqs.com/technique/T1055.012), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), T1059.008, [T1069.003](https://intel.threadlinqs.com/technique/T1069.003), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), T1070.008, [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.003](https://intel.threadlinqs.com/technique/T1078.003), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1080](https://intel.threadlinqs.com/technique/T1080), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.004](https://intel.threadlinqs.com/technique/T1087.004), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114.001](https://intel.threadlinqs.com/technique/T1114.001), [T1114.002](https://intel.threadlinqs.com/technique/T1114.002), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1134.001](https://intel.threadlinqs.com/technique/T1134.001), [T1134.002](https://intel.threadlinqs.com/technique/T1134.002), T1134.004, [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1213.002](https://intel.threadlinqs.com/technique/T1213.002), [T1218.005](https://intel.threadlinqs.com/technique/T1218.005), [T1218.007](https://intel.threadlinqs.com/technique/T1218.007), [T1480](https://intel.threadlinqs.com/technique/T1480), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1547.013](https://intel.threadlinqs.com/technique/T1547.013), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.001](https://intel.threadlinqs.com/technique/T1548.001), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1548.003](https://intel.threadlinqs.com/technique/T1548.003), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1556.006](https://intel.threadlinqs.com/technique/T1556.006), T1556.009, [T1557](https://intel.threadlinqs.com/technique/T1557), [T1559](https://intel.threadlinqs.com/technique/T1559), [T1560](https://intel.threadlinqs.com/technique/T1560), T1562.001, [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.004](https://intel.threadlinqs.com/technique/T1566.004), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.001](https://intel.threadlinqs.com/technique/T1567.001), [T1567.004](https://intel.threadlinqs.com/technique/T1567.004), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), T1574.002, [T1574.006](https://intel.threadlinqs.com/technique/T1574.006), T1574.011, [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.002](https://intel.threadlinqs.com/technique/T1585.002), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.003](https://intel.threadlinqs.com/technique/T1588.003), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589.001](https://intel.threadlinqs.com/technique/T1589.001), [T1589.002](https://intel.threadlinqs.com/technique/T1589.002), [T1589.003](https://intel.threadlinqs.com/technique/T1589.003), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1598.003](https://intel.threadlinqs.com/technique/T1598.003), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1610](https://intel.threadlinqs.com/technique/T1610), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1622](https://intel.threadlinqs.com/technique/T1622), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657), [T1685](https://intel.threadlinqs.com/technique/T1685), [T1685.005](https://intel.threadlinqs.com/technique/T1685.005)

## Threat actors

[Storm-3121](https://intel.threadlinqs.com/actor/Storm-3121), [SMOKY SPIDER](https://intel.threadlinqs.com/actor/SMOKY%20SPIDER), [UNC5342](https://intel.threadlinqs.com/actor/UNC5342), [UNC3569](https://intel.threadlinqs.com/actor/UNC3569), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP), [DragonBreath](https://intel.threadlinqs.com/actor/DragonBreath)

Nation-state attribution: Russia, North Korea (DPRK), China

Threat categories: VULNERABILITY, PHISHING, CLOUD, RANSOMWARE, MALWARE, THREAT_INTEL, SUPPLY_CHAIN

## Severity breakdown

- critical: 7
- high: 9
- medium: 1
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 398 (network 123, file 97, infrastructure 42, entity 39, package 27, behavioral 24, tool 23, malware 21, credential 1, technique 1)
- New detection rules: 153 (100% of the day’s threats covered)

## More editions

- Previous: [2026-09-09](https://intel.threadlinqs.com/debrief/2026-09-09)
- Next: [2026-09-15](https://intel.threadlinqs.com/debrief/2026-09-15)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-09-13
