Summary & highlights
Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users. Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40. Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised.
Highlights
- TL-2026-2643 — TokenGrabber: Python-based MaaS Infostealer Builder
- TL-2026-2645 — Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by Initial Access Brokers
- TL-2026-2646 — SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via FrameworkBase.dll Tampering
- TL-2026-2647 — Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and diverse loaders (DLL side-loading, Donut, Python, process hollowing, BYOVD)
- TL-2026-2648 — Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin skip_block_zeroing residual block reuse
Theme of the day
Today's threat landscape is dominated by critical zero-day exploitation across cloud and network appliances, with credential theft and infostealers as persistent secondary tactics.
- social-engineering
- credential-theft
- infostealer
- masquerading
- phishing
Threats published
18 threat lines in the 2026-09-25 debrief, most severe first. Each links to its full profile.
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow AbuseCRITICAL
- Critical ServiceNow AI Platform Vulnerabilities: Unauthenticated SQL Injection and Authorization Bypasses (CVE-2026-13016, CVE-2026-86857-86860)CRITICAL
- CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint Code InjectionCRITICAL
- TokenGrabber: Python-based MaaS Infostealer BuilderHIGH
- Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by Initial Access BrokersHIGH
- SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via FrameworkBase.dll TamperingHIGH
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and diverse loaders (DLL side-loading, Donut, Python, process hollowing, BYOVD)HIGH
- Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin skip_block_zeroing residual block reuseHIGH
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)HIGH
- Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac usersHIGH
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogsHIGH
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip Android APK + Certum-Signed ITD_Tax_Notice.exe Loader), Cloned e-Filing Portals and Refund ScamsHIGH
- Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day TargetingHIGH
- Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile UsersMEDIUM
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40MEDIUM
- Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly CompromisedMEDIUM
- Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call ScriptMEDIUM
- Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)MEDIUM
Techniques observed
130 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1005
- T1006
- T1012
- T1020
- T1021
- T1021.004
- T1027
- T1027.001
- T1027.002
- T1036
- T1036.005
- T1036.008
- T1040
- T1048
- T1048.003
- T1053
- T1053.005
- T1055
- T1055.012
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.006
- T1059.007
- T1059.008
- T1068
- T1070
- T1070.004
- T1071.001
- T1074.001
- T1078
- T1078.004
- T1082
- T1087
- T1090.002
- T1090.003
- T1095
- T1098
- T1098.004
- T1098.005
- T1106
- T1110.002
- T1111
- T1112
- T1113
- T1114
- T1133
- T1136.001
- T1140
- T1185
- T1190
- T1195.002
- T1199
- T1204
- T1204.001
- T1204.002
- T1212
- T1213
- T1218.010
- T1219
- T1417
- T1485
- T1489
- T1497
- T1497.001
- T1499.004
- T1505
- T1505.003
- T1517
- T1518.001
- T1528
- T1531
- T1537
- T1539
- T1543.003
- T1543.005
- T1547
- T1547.001
- T1547.009
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1555
- T1555.003
- T1555.004
- T1557
- T1560
- T1564
- T1565
- T1565.001
- T1565.002
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1571
- T1572
- T1573.001
- T1574.001
- T1583.001
- T1583.004
- T1583.006
- T1584.008
- T1585
- T1585.001
- T1587.001
- T1588.004
- T1588.005
- T1588.006
- T1589
- T1590.005
- T1591
- T1592.002
- T1595
- T1595.002
- T1602.002
- T1606
- T1608.001
- T1608.005
- T1610
- T1620
- T1621
- T1636.004
- T1657
- T1684.001
- T1685
Threat actors
5 named threat actors across the reports.
Nation-state attribution
- China
- North Korea
Threat categories
- MALWARE
- VULNERABILITY
- DATA_BREACH
- PHISHING
- RANSOMWARE
- APT
- THREAT_INTEL
- ZERO_DAY
Severity breakdown
- critical3
- high10
- medium5
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 100
- file 69
- infrastructure 44
- entity 29
- malware 26
- behavioral 18
- package 11
- tool 11