Summary & highlights
Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged). Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian Targets via Exchange/SharePoint Exploitation. Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices.
Highlights
- TL-2026-2514 — Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)
- TL-2026-2515 — Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian Targets via Exchange/SharePoint Exploitation
- TL-2026-2517 — Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices
- TL-2026-2519 — BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL Side-Loading and Kingsoft Office Impersonation
- TL-2026-2520 — BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2
Theme of the day
Unattributed threats dominated the day with no dominant actor or sector, suggesting a broad, low-attribution attack surface.
- cisa-kev
- credential-theft
- cross-platform-malware
- linux-malware
- windows-malware
Threats published
14 threat lines in the 2026-09-15 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and Xcode — Bundles a Previously KEV-Listed Pre-Auth Screen Sharing RCECRITICAL
- Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites AffectedCRITICAL
- CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalog (update)CRITICAL
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit (update)CRITICAL
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)HIGH
- Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian Targets via Exchange/SharePoint ExploitationHIGH
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate DevicesHIGH
- BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL Side-Loading and Kingsoft Office ImpersonationHIGH
- BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2HIGH
- CVE-2026-87886: Actively Exploited Privilege Escalation Flaw in Acronis cPanel Backup PluginHIGH
- KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to Steal Brazilian Bank CredentialsHIGH
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and JournalistsHIGH
- PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network (CVE-2020-16040)HIGH
- Mass Phishing Operation Abuses Fast-Flux DNS to Evade Detection (Yalishanda / ShadowRelay)HIGH
Techniques observed
132 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1005
- T1014
- T1016.001
- T1021.001
- T1021.004
- T1027
- T1027.002
- T1027.013
- T1036
- T1036.001
- T1036.005
- T1041
- T1046
- T1047
- T1048
- T1053
- T1053.003
- T1053.005
- T1055
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1070.002
- T1070.003
- T1070.004
- T1071
- T1071.001
- T1071.005
- T1078
- T1078.003
- T1082
- T1090
- T1090.001
- T1090.002
- T1090.003
- T1102.002
- T1105
- T1110.003
- T1111
- T1113
- T1114
- T1123
- T1125
- T1129
- T1133
- T1136
- T1140
- T1176
- T1190
- T1195.002
- T1203
- T1204.001
- T1204.002
- T1210
- T1213
- T1218.005
- T1219
- T1485
- T1489
- T1490
- T1497
- T1499.004
- T1505.003
- T1518
- T1518.001
- T1529
- T1539
- T1543.003
- T1543.004
- T1546.004
- T1547.001
- T1548
- T1548.001
- T1548.003
- T1550.001
- T1552
- T1552.001
- T1552.004
- T1553.002
- T1554
- T1555
- T1555.001
- T1555.003
- T1560.001
- T1561.001
- T1562.001
- T1564.001
- T1565.001
- T1566
- T1566.003
- T1567.002
- T1568.001
- T1570
- T1571
- T1572
- T1573.001
- T1574
- T1574.001
- T1574.006
- T1583
- T1583.001
- T1583.004
- T1583.006
- T1584.004
- T1584.006
- T1584.008
- T1585.001
- T1587.001
- T1587.004
- T1588.003
- T1588.005
- T1588.006
- T1589
- T1595
- T1595.002
- T1608.001
- T1620
- T1633.001
- T1660
- T1665
- T1684.001
- T1685
- T1685.005
- T1685.006
Threat actors
7 named threat actors across the reports.
- Hacking Cat
- REF9334
- Iran Ministry of Intelligence
- China-aligned APT clusters
- Yalishanda
- UAT-9686
- Red Heron
Nation-state attribution
- Ukraine
- MY
- China
- Iran
- Russia
Threat categories
- DATA_BREACH
- RANSOMWARE
- MALWARE
- VULNERABILITY
- PHISHING
- SUPPLY_CHAIN
- APT
Severity breakdown
- critical4
- high10
- medium0
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 69
- file 59
- infrastructure 40
- entity 33
- malware 30
- tool 23
- package 21
- behavioral 6