Summary & highlights
Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security Evaluation. BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection. Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites).
Highlights
- TL-2026-2595 — Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)
- TL-2026-2596 — F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)
- TL-2026-2598 — Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated
- TL-2026-2599 — Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors
- TL-2026-2601 — Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack Chain
Theme of the day
GrayBravo and PolinRider remained active alongside unattributed threats, with a focus on application-layer DoS, AnyDesk abuse, and Azure Blob Storage exploitation.
- credential-theft
- cryptocurrency-theft
- third-party-risk
- supply-chain-attack
- credential-harvesting
Threats published
16 threat lines in the 2026-09-21 debrief, most severe first. Each links to its full profile.
- Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme InstallCRITICAL
- EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking CredentialsCRITICAL
- NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and DCSync to Compromise Russian Active DirectoryCRITICAL
- Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273) Actively Exploited by Kapibala/Red Heron in Global 996-Device Campaign — Added to CISA KEVCRITICAL
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)HIGH
- F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)HIGH
- Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB ExfiltratedHIGH
- Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS BackdoorsHIGH
- Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack ChainHIGH
- Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator GitHub ReposHIGH
- Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)HIGH
- Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused Across SectopRAT, MacSync, and AMOS CampaignsHIGH
- GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcpHIGH
- Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military PersonnelHIGH
- Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security EvaluationMEDIUM
- BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script InjectionMEDIUM
Techniques observed
125 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0003
- AML.T0012
- AML.T0051.001
- AML.T0053
- AML.T0055
- T1003.006
- T1005
- T1008
- T1021.001
- T1027
- T1027.002
- T1033
- T1036
- T1036.005
- T1053.005
- T1055
- T1056.004
- T1059.001
- T1059.002
- T1059.004
- T1059.006
- T1059.007
- T1059.009
- T1070.004
- T1071.001
- T1071.002
- T1078
- T1078.001
- T1078.004
- T1082
- T1087.004
- T1090
- T1090.001
- T1095
- T1098.007
- T1102.001
- T1102.002
- T1110.001
- T1113
- T1133
- T1136.001
- T1140
- T1176.001
- T1190
- T1195.001
- T1195.002
- T1199
- T1203
- T1204.001
- T1204.002
- T1204.004
- T1213
- T1219
- T1430
- T1430.002
- T1499.002
- T1499.003
- T1499.004
- T1505
- T1505.003
- T1526
- T1528
- T1530
- T1539
- T1543.001
- T1543.002
- T1543.003
- T1547.001
- T1548.002
- T1550.001
- T1552
- T1552.001
- T1553.001
- T1553.002
- T1555
- T1555.001
- T1555.003
- T1555.004
- T1558
- T1560
- T1560.001
- T1564
- T1566.002
- T1566.004
- T1567
- T1568.002
- T1571
- T1572
- T1573.001
- T1573.002
- T1574.001
- T1580
- T1583
- T1583.001
- T1583.006
- T1584.005
- T1584.006
- T1585.001
- T1587.001
- T1587.004
- T1588.002
- T1588.006
- T1589
- T1589.002
- T1590.002
- T1590.006
- T1591
- T1591.001
- T1592.002
- T1593
- T1593.003
- T1595
- T1595.002
- T1598.003
- T1599
- T1608.001
- T1608.004
- T1611
- T1620
- T1638
- T1650
- T1657
- T1684.001
- T1685
- T1685.001
Threat actors
7 named threat actors across the reports.
Nation-state attribution
- North Korea (DPRK)
- North Korea
- Iran
- China
Threat categories
- THREAT_INTEL
- DATA_BREACH
- PHISHING
- VULNERABILITY
- RANSOMWARE
- MALWARE
- CLOUD
- SUPPLY_CHAIN
- APT
Severity breakdown
- critical4
- high10
- medium2
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 90
- file 67
- entity 47
- infrastructure 44
- tool 24
- package 17
- malware 12
- behavioral 5