Threadlinqs IntelligenceStart free

Daily debrief · Friday2026-09-18

Daily Intelligence Briefing — Friday, September 18, 2026

7 critical8 high4 medium

On 2026-09-18, Threadlinqs published 16 new threat reports and updated 3, 7 rated critical and 8 high, spanning 169 MITRE ATT&CK techniques and 6 named threat actors. Coverage that day added 171 new detection rules and 446 extracted indicators.

New threats
163 updated
Critical / high
157 critical · 8 high
ATT&CK techniques
169Observed in the day’s reports
Threat actors
6Named in the reports
Indicators
446Count only · values are Red+
Detection rules
171New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow. AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and PROMPTSTEAL/LAMEHUG (APT28). Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details.

Highlights

  • TL-2026-2558 — AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)
  • TL-2026-2560 — MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2
  • TL-2026-2564 — France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months
  • TL-2026-2566 — Gyazo Data Breach: Helpfeel Discloses 23.62M User Records and ~492M Image Metadata Records Exposed via Image Upload Server Exploit
  • TL-2026-2568 — AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Access

Theme of the day

Activity centered on account-takeover, adversary-in-the-middle, apac.

  • social-engineering
  • privilege-escalation
  • credential-harvesting
  • openai
  • cisa-kev

Threats published

19 threat lines in the 2026-09-18 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

169 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

6 named threat actors across the reports.

Nation-state attribution

  • Russia
  • Russia (NoName057(16) hacktivist track only; Qilin/MedusaLocker/LockBit are financially motivated, non-state RaaS operations)
  • North Korea (DPRK)

Threat categories

  • PHISHING
  • MALWARE
  • VULNERABILITY
  • THREAT_INTEL
  • DATA_BREACH
  • RANSOMWARE
  • ZERO_DAY
  • SUPPLY_CHAIN

Severity breakdown

  • critical7
  • high8
  • medium4
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

446 indicators of compromise · Red and above. Compare plans
  • network 123
  • file 88
  • infrastructure 66
  • entity 61
  • behavioral 36
  • tool 30
  • package 21
  • malware 19
  • technique 2
171 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans