# Daily Intelligence Briefing — Monday, September 21, 2026

> On 2026-09-21, Threadlinqs published 16 new threat reports, 4 rated critical and 10 high, spanning 125 MITRE ATT&CK techniques and 7 named threat actors. Coverage that day added 144 new detection rules and 306 extracted indicators.

- **Edition:** 2026-09-21 (Monday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-09-21
- **Last updated:** 2026-09-27
- **New threats:** 16
- **Critical / high:** 4 critical, 10 high, 2 medium, 0 low
- **ATT&CK techniques:** 125
- **Threat actors:** 7
- **Indicators (count only):** 306
- **New detection rules (count only):** 144

## Summary & highlights

Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security Evaluation. BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection. Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites).

- [TL-2026-2595](https://intel.threadlinqs.com/threat/TL-2026-2595) — Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)
- [TL-2026-2596](https://intel.threadlinqs.com/threat/TL-2026-2596) — F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)
- [TL-2026-2598](https://intel.threadlinqs.com/threat/TL-2026-2598) — Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated
- [TL-2026-2599](https://intel.threadlinqs.com/threat/TL-2026-2599) — Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors
- [TL-2026-2601](https://intel.threadlinqs.com/threat/TL-2026-2601) — Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack Chain

## Theme of the day

GrayBravo and PolinRider remained active alongside unattributed threats, with a focus on application-layer DoS, AnyDesk abuse, and Azure Blob Storage exploitation.

credential-theft, cryptocurrency-theft, third-party-risk, supply-chain-attack, credential-harvesting

## Threats published

- [TL-2026-2597](https://intel.threadlinqs.com/threat/TL-2026-2597) — CRITICAL — Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Install
- [TL-2026-2600](https://intel.threadlinqs.com/threat/TL-2026-2600) — CRITICAL — EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
- [TL-2026-2606](https://intel.threadlinqs.com/threat/TL-2026-2606) — CRITICAL — NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and DCSync to Compromise Russian Active Directory
- [TL-2026-2611](https://intel.threadlinqs.com/threat/TL-2026-2611) — CRITICAL — Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273) Actively Exploited by Kapibala/Red Heron in Global 996-Device Campaign — Added to CISA KEV
- [TL-2026-2595](https://intel.threadlinqs.com/threat/TL-2026-2595) — HIGH — Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)
- [TL-2026-2596](https://intel.threadlinqs.com/threat/TL-2026-2596) — HIGH — F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)
- [TL-2026-2598](https://intel.threadlinqs.com/threat/TL-2026-2598) — HIGH — Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated
- [TL-2026-2599](https://intel.threadlinqs.com/threat/TL-2026-2599) — HIGH — Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors
- [TL-2026-2601](https://intel.threadlinqs.com/threat/TL-2026-2601) — HIGH — Unauthenticated AWS API Gateway + Over-Permissioned Lambda: Credential Extraction Attack Chain
- [TL-2026-2602](https://intel.threadlinqs.com/threat/TL-2026-2602) — HIGH — Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator GitHub Repos
- [TL-2026-2603](https://intel.threadlinqs.com/threat/TL-2026-2603) — HIGH — Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)
- [TL-2026-2604](https://intel.threadlinqs.com/threat/TL-2026-2604) — HIGH — Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused Across SectopRAT, MacSync, and AMOS Campaigns
- [TL-2026-2605](https://intel.threadlinqs.com/threat/TL-2026-2605) — HIGH — GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcp
- [TL-2026-2609](https://intel.threadlinqs.com/threat/TL-2026-2609) — HIGH — Iran Exploits SS7 Cellular Interconnect Infrastructure to Track US Military Personnel
- [TL-2026-2607](https://intel.threadlinqs.com/threat/TL-2026-2607) — MEDIUM — Google Gemini AI Model Autonomously Breached Three Real Companies During Authorized Security Evaluation
- [TL-2026-2610](https://intel.threadlinqs.com/threat/TL-2026-2610) — MEDIUM — BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection

## Techniques observed

AML.T0003, AML.T0012, [AML.T0051.001](https://intel.threadlinqs.com/technique/AML.T0051.001), [AML.T0053](https://intel.threadlinqs.com/technique/AML.T0053), AML.T0055, [T1003.006](https://intel.threadlinqs.com/technique/T1003.006), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1056.004](https://intel.threadlinqs.com/technique/T1056.004), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.002](https://intel.threadlinqs.com/technique/T1059.002), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), T1059.009, [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), T1071.002, [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.001](https://intel.threadlinqs.com/technique/T1078.001), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1087.004](https://intel.threadlinqs.com/technique/T1087.004), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1095](https://intel.threadlinqs.com/technique/T1095), T1098.007, [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1110.001](https://intel.threadlinqs.com/technique/T1110.001), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), T1176.001, [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1204.004](https://intel.threadlinqs.com/technique/T1204.004), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1430](https://intel.threadlinqs.com/technique/T1430), T1430.002, [T1499.002](https://intel.threadlinqs.com/technique/T1499.002), [T1499.003](https://intel.threadlinqs.com/technique/T1499.003), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1553.001](https://intel.threadlinqs.com/technique/T1553.001), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.001](https://intel.threadlinqs.com/technique/T1555.001), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1555.004](https://intel.threadlinqs.com/technique/T1555.004), [T1558](https://intel.threadlinqs.com/technique/T1558), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), [T1564](https://intel.threadlinqs.com/technique/T1564), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.004](https://intel.threadlinqs.com/technique/T1566.004), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1568.002](https://intel.threadlinqs.com/technique/T1568.002), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584.005](https://intel.threadlinqs.com/technique/T1584.005), [T1584.006](https://intel.threadlinqs.com/technique/T1584.006), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.002](https://intel.threadlinqs.com/technique/T1589.002), T1590.002, T1590.006, [T1591](https://intel.threadlinqs.com/technique/T1591), T1591.001, [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1593.003](https://intel.threadlinqs.com/technique/T1593.003), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1598.003](https://intel.threadlinqs.com/technique/T1598.003), [T1599](https://intel.threadlinqs.com/technique/T1599), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1608.004](https://intel.threadlinqs.com/technique/T1608.004), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1620](https://intel.threadlinqs.com/technique/T1620), T1638, [T1650](https://intel.threadlinqs.com/technique/T1650), [T1657](https://intel.threadlinqs.com/technique/T1657), [T1684.001](https://intel.threadlinqs.com/technique/T1684.001), [T1685](https://intel.threadlinqs.com/technique/T1685), T1685.001

## Threat actors

[Vexy Ransomware](https://intel.threadlinqs.com/actor/Vexy%20Ransomware), [Jade Sleet](https://intel.threadlinqs.com/actor/Jade%20Sleet), [APT38](https://intel.threadlinqs.com/actor/APT38), [PolinRider](https://intel.threadlinqs.com/actor/PolinRider), Iran), [NightEagle](https://intel.threadlinqs.com/actor/NightEagle), [Kapibala](https://intel.threadlinqs.com/actor/Kapibala)

Nation-state attribution: North Korea (DPRK), North Korea, Iran, China

Threat categories: THREAT_INTEL, DATA_BREACH, PHISHING, VULNERABILITY, RANSOMWARE, MALWARE, CLOUD, SUPPLY_CHAIN, APT

## Severity breakdown

- critical: 4
- high: 10
- medium: 2
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 306 (network 90, file 67, entity 47, infrastructure 44, tool 24, package 17, malware 12, behavioral 5)
- New detection rules: 144 (100% of the day’s threats covered)

## More editions

- Previous: [2026-09-18](https://intel.threadlinqs.com/debrief/2026-09-18)
- Next: [2026-09-25](https://intel.threadlinqs.com/debrief/2026-09-25)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-09-21
