Threadlinqs IntelligenceStart free

Daily debrief · Monday2026-09-21

Daily Intelligence Briefing — Monday, September 21, 2026

4 critical10 high2 medium

On 2026-09-21, Threadlinqs published 16 new threat reports, 4 rated critical and 10 high, spanning 125 MITRE ATT&CK techniques and 7 named threat actors. Coverage that day added 144 new detection rules and 306 extracted indicators.

New threats
1616 threat lines
Critical / high
144 critical · 10 high
ATT&CK techniques
125Observed in the day’s reports
Threat actors
7Named in the reports
Indicators
306Count only · values are Red+
Detection rules
144New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security Evaluation. BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection. Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites).

Highlights

  • TL-2026-2595 — Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)
  • TL-2026-2596 — F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)
  • TL-2026-2598 — Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated
  • TL-2026-2599 — Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors
  • TL-2026-2601 — Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack Chain

Theme of the day

GrayBravo and PolinRider remained active alongside unattributed threats, with a focus on application-layer DoS, AnyDesk abuse, and Azure Blob Storage exploitation.

  • credential-theft
  • cryptocurrency-theft
  • third-party-risk
  • supply-chain-attack
  • credential-harvesting

Threats published

16 threat lines in the 2026-09-21 debrief, most severe first. Each links to its full profile.

Techniques observed

125 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

7 named threat actors across the reports.

Nation-state attribution

  • North Korea (DPRK)
  • North Korea
  • Iran
  • China

Threat categories

  • THREAT_INTEL
  • DATA_BREACH
  • PHISHING
  • VULNERABILITY
  • RANSOMWARE
  • MALWARE
  • CLOUD
  • SUPPLY_CHAIN
  • APT

Severity breakdown

  • critical4
  • high10
  • medium2
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

306 indicators of compromise · Red and above. Compare plans
  • network 90
  • file 67
  • entity 47
  • infrastructure 44
  • tool 24
  • package 17
  • malware 12
  • behavioral 5
144 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans