Summary & highlights
Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow. AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and PROMPTSTEAL/LAMEHUG (APT28). Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details.
Highlights
- TL-2026-2558 — AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)
- TL-2026-2560 — MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2
- TL-2026-2564 — France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months
- TL-2026-2566 — Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image Upload Server Exploit
- TL-2026-2568 — AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Access
Theme of the day
Activity centered on account-takeover, adversary-in-the-middle, apac.
- social-engineering
- privilege-escalation
- credential-harvesting
- openai
- cisa-kev
Threats published
19 threat lines in the 2026-09-18 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Critical Check Point Management Server Flaw (CVE-2026-91843) Lets Unauthenticated Attackers Run Code as RootCRITICAL
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense IndustryCRITICAL
- Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing Flaws Across Azure and Copilot AI Products, Plus a Windows Secure Kernel EoP (CVE-2026-85921)CRITICAL
- CVE-2025-39682 — Linux Kernel net/tls rx_list Zero-Length Record Use-After-Free Added to CISA KEV CatalogCRITICAL
- Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+ Websites via ClickFix and a Rogue WordPress PluginCRITICAL
- JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos (CVE-2021-29441) (update)CRITICAL
- CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and Acronis Backup Privilege Escalation (CVE-2026-87886) (update)CRITICAL
- AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)HIGH
- MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2HIGH
- France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 MonthsHIGH
- Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image Upload Server ExploitHIGH
- AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code AccessHIGH
- Ransomware Attack Disrupts IT Systems and Services in Ellis County, KansasHIGH
- "LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)HIGH
- EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing Against Microsoft 365 (update)HIGH
- Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting FlowMEDIUM
- AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and PROMPTSTEAL/LAMEHUG (APT28)MEDIUM
- Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank DetailsMEDIUM
- Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google API Open-Redirect and nxcli.io InfrastructureMEDIUM
Techniques observed
169 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0054
- T0814
- T1003
- T1003.001
- T1005
- T1014
- T1016
- T1020
- T1021
- T1021.005
- T1027
- T1027.007
- T1036
- T1036.005
- T1046
- T1053
- T1053.003
- T1053.005
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1069
- T1070
- T1071
- T1071.001
- T1074.001
- T1078
- T1078.001
- T1078.003
- T1078.004
- T1082
- T1083
- T1087
- T1087.004
- T1090
- T1090.002
- T1091
- T1098
- T1098.001
- T1098.005
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110
- T1110.003
- T1110.004
- T1111
- T1113
- T1114.002
- T1114.003
- T1119
- T1132.001
- T1133
- T1136
- T1136.001
- T1137
- T1140
- T1187
- T1190
- T1195
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1211
- T1213
- T1213.002
- T1213.003
- T1222.002
- T1404
- T1485
- T1486
- T1489
- T1490
- T1491.001
- T1497
- T1497.001
- T1498.001
- T1499.004
- T1505
- T1505.003
- T1518
- T1526
- T1528
- T1530
- T1531
- T1534
- T1539
- T1546
- T1547.001
- T1548.002
- T1548.003
- T1550
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1555
- T1556
- T1556.003
- T1557
- T1560.001
- T1562
- T1564
- T1564.008
- T1565
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1567
- T1567.002
- T1570
- T1573.002
- T1574.001
- T1580
- T1583
- T1583.001
- T1583.003
- T1583.006
- T1583.007
- T1584
- T1584.004
- T1584.006
- T1585.001
- T1585.002
- T1587
- T1587.004
- T1588
- T1588.002
- T1588.005
- T1588.006
- T1589.001
- T1589.002
- T1591
- T1592.002
- T1595
- T1595.002
- T1598
- T1598.003
- T1606
- T1608
- T1608.001
- T1608.005
- T1608.006
- T1609
- T1610
- T1611
- T1613
- T1620
- T1621
- T1656
- T1657
- T1684.001
- T1685
- T1685.006
- T1686
- T1688
Threat actors
6 named threat actors across the reports.
Nation-state attribution
- Russia
- Russia (NoName057(16) hacktivist track only; Qilin/MedusaLocker/LockBit are financially motivated, non-state RaaS operations)
- North Korea (DPRK)
Threat categories
- PHISHING
- MALWARE
- VULNERABILITY
- THREAT_INTEL
- DATA_BREACH
- RANSOMWARE
- ZERO_DAY
- SUPPLY_CHAIN
Severity breakdown
- critical7
- high8
- medium4
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 123
- file 88
- infrastructure 66
- entity 61
- behavioral 36
- tool 30
- package 21
- malware 19
- technique 2