Threadlinqs IntelligenceStart free

Daily debrief · Friday2026-09-25

Daily Intelligence Briefing — Friday, September 25, 2026

3 critical10 high5 medium

On 2026-09-25, Threadlinqs published 18 new threat reports, 3 rated critical and 10 high, spanning 130 MITRE ATT&CK techniques and 5 named threat actors. Coverage that day added 162 new detection rules and 308 extracted indicators.

New threats
1818 threat lines
Critical / high
133 critical · 10 high
ATT&CK techniques
130Observed in the day’s reports
Threat actors
5Named in the reports
Indicators
308Count only · values are Red+
Detection rules
162New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users. Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40. Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised.

Highlights

  • TL-2026-2643 — TokenGrabber: Python-based MaaS Infostealer Builder
  • TL-2026-2645 — Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by Initial Access Brokers
  • TL-2026-2646 — SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via FrameworkBase.dll Tampering
  • TL-2026-2647 — Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and diverse loaders (DLL side-loading, Donut, Python, process hollowing, BYOVD)
  • TL-2026-2648 — Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin skip_block_zeroing residual block reuse

Theme of the day

Today's threat landscape is dominated by critical zero-day exploitation across cloud and network appliances, with credential theft and infostealers as persistent secondary tactics.

  • social-engineering
  • credential-theft
  • infostealer
  • masquerading
  • phishing

Threats published

18 threat lines in the 2026-09-25 debrief, most severe first. Each links to its full profile.

Techniques observed

130 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

5 named threat actors across the reports.

Nation-state attribution

  • China
  • North Korea

Threat categories

  • MALWARE
  • VULNERABILITY
  • DATA_BREACH
  • PHISHING
  • RANSOMWARE
  • APT
  • THREAT_INTEL
  • ZERO_DAY

Severity breakdown

  • critical3
  • high10
  • medium5
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

308 indicators of compromise · Red and above. Compare plans
  • network 100
  • file 69
  • infrastructure 44
  • entity 29
  • malware 26
  • behavioral 18
  • package 11
  • tool 11
162 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans