# Daily Intelligence Briefing — Friday, September 25, 2026

> On 2026-09-25, Threadlinqs published 18 new threat reports, 3 rated critical and 10 high, spanning 130 MITRE ATT&CK techniques and 5 named threat actors. Coverage that day added 162 new detection rules and 308 extracted indicators.

- **Edition:** 2026-09-25 (Friday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-09-25
- **Last updated:** 2026-10-01
- **New threats:** 18
- **Critical / high:** 3 critical, 10 high, 5 medium, 0 low
- **ATT&CK techniques:** 130
- **Threat actors:** 5
- **Indicators (count only):** 308
- **New detection rules (count only):** 162

## Summary & highlights

Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users. Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40. Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised.

- [TL-2026-2643](https://intel.threadlinqs.com/threat/TL-2026-2643) — TokenGrabber: Python-based MaaS Infostealer Builder
- [TL-2026-2645](https://intel.threadlinqs.com/threat/TL-2026-2645) — Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by Initial Access Brokers
- [TL-2026-2646](https://intel.threadlinqs.com/threat/TL-2026-2646) — SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via FrameworkBase.dll Tampering
- [TL-2026-2647](https://intel.threadlinqs.com/threat/TL-2026-2647) — Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and diverse loaders (DLL side-loading, Donut, Python, process hollowing, BYOVD)
- [TL-2026-2648](https://intel.threadlinqs.com/threat/TL-2026-2648) — Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin skip_block_zeroing residual block reuse

## Theme of the day

Today's threat landscape is dominated by critical zero-day exploitation across cloud and network appliances, with credential theft and infostealers as persistent secondary tactics.

social-engineering, credential-theft, infostealer, masquerading, phishing

## Threats published

- [TL-2026-2650](https://intel.threadlinqs.com/threat/TL-2026-2650) — CRITICAL — Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse
- [TL-2026-2653](https://intel.threadlinqs.com/threat/TL-2026-2653) — CRITICAL — Critical ServiceNow AI Platform Vulnerabilities: Unauthenticated SQL Injection and Authorization Bypasses (CVE-2026-13016, CVE-2026-86857-86860)
- [TL-2026-2680](https://intel.threadlinqs.com/threat/TL-2026-2680) — CRITICAL — CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint Code Injection
- [TL-2026-2643](https://intel.threadlinqs.com/threat/TL-2026-2643) — HIGH — TokenGrabber: Python-based MaaS Infostealer Builder
- [TL-2026-2645](https://intel.threadlinqs.com/threat/TL-2026-2645) — HIGH — Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by Initial Access Brokers
- [TL-2026-2646](https://intel.threadlinqs.com/threat/TL-2026-2646) — HIGH — SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via FrameworkBase.dll Tampering
- [TL-2026-2647](https://intel.threadlinqs.com/threat/TL-2026-2647) — HIGH — Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and diverse loaders (DLL side-loading, Donut, Python, process hollowing, BYOVD)
- [TL-2026-2648](https://intel.threadlinqs.com/threat/TL-2026-2648) — HIGH — Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin skip_block_zeroing residual block reuse
- [TL-2026-2649](https://intel.threadlinqs.com/threat/TL-2026-2649) — HIGH — Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)
- [TL-2026-2651](https://intel.threadlinqs.com/threat/TL-2026-2651) — HIGH — Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac users
- [TL-2026-2652](https://intel.threadlinqs.com/threat/TL-2026-2652) — HIGH — Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs
- [TL-2026-2654](https://intel.threadlinqs.com/threat/TL-2026-2654) — HIGH — Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip Android APK + Certum-Signed ITD_Tax_Notice.exe Loader), Cloned e-Filing Portals and Refund Scams
- [TL-2026-2670](https://intel.threadlinqs.com/threat/TL-2026-2670) — HIGH — Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day Targeting
- [TL-2026-2655](https://intel.threadlinqs.com/threat/TL-2026-2655) — MEDIUM — Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users
- [TL-2026-2658](https://intel.threadlinqs.com/threat/TL-2026-2658) — MEDIUM — Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40
- [TL-2026-2694](https://intel.threadlinqs.com/threat/TL-2026-2694) — MEDIUM — Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised
- [TL-2026-2695](https://intel.threadlinqs.com/threat/TL-2026-2695) — MEDIUM — Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script
- [TL-2026-2713](https://intel.threadlinqs.com/threat/TL-2026-2713) — MEDIUM — Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)

## Techniques observed

[T1001](https://intel.threadlinqs.com/technique/T1001), [T1005](https://intel.threadlinqs.com/technique/T1005), T1006, [T1012](https://intel.threadlinqs.com/technique/T1012), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.004](https://intel.threadlinqs.com/technique/T1021.004), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.001](https://intel.threadlinqs.com/technique/T1027.001), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.008](https://intel.threadlinqs.com/technique/T1036.008), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1048.003](https://intel.threadlinqs.com/technique/T1048.003), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.012](https://intel.threadlinqs.com/technique/T1055.012), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), T1059.008, [T1068](https://intel.threadlinqs.com/technique/T1068), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1074.001](https://intel.threadlinqs.com/technique/T1074.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.004](https://intel.threadlinqs.com/technique/T1098.004), [T1098.005](https://intel.threadlinqs.com/technique/T1098.005), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110.002](https://intel.threadlinqs.com/technique/T1110.002), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1218.010](https://intel.threadlinqs.com/technique/T1218.010), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1417](https://intel.threadlinqs.com/technique/T1417), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1517](https://intel.threadlinqs.com/technique/T1517), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), T1543.005, [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1547.009](https://intel.threadlinqs.com/technique/T1547.009), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1555.004](https://intel.threadlinqs.com/technique/T1555.004), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1564](https://intel.threadlinqs.com/technique/T1564), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1565.002](https://intel.threadlinqs.com/technique/T1565.002), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.004](https://intel.threadlinqs.com/technique/T1566.004), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584.008](https://intel.threadlinqs.com/technique/T1584.008), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), T1588.004, [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), T1590.005, [T1591](https://intel.threadlinqs.com/technique/T1591), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), T1602.002, [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1608.005](https://intel.threadlinqs.com/technique/T1608.005), [T1610](https://intel.threadlinqs.com/technique/T1610), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1636.004](https://intel.threadlinqs.com/technique/T1636.004), [T1657](https://intel.threadlinqs.com/technique/T1657), [T1684.001](https://intel.threadlinqs.com/technique/T1684.001), [T1685](https://intel.threadlinqs.com/technique/T1685)

## Threat actors

[Derian](https://intel.threadlinqs.com/actor/Derian), [Vexy Ransomware](https://intel.threadlinqs.com/actor/Vexy%20Ransomware), [Initial Access Brokers](https://intel.threadlinqs.com/actor/Initial%20Access%20Brokers), [Salt Typhoon - G1045](https://intel.threadlinqs.com/actor/Salt%20Typhoon%20-%20G1045), [TraderTraitor](https://intel.threadlinqs.com/actor/TraderTraitor)

Nation-state attribution: China, North Korea

Threat categories: MALWARE, VULNERABILITY, DATA_BREACH, PHISHING, RANSOMWARE, APT, THREAT_INTEL, ZERO_DAY

## Severity breakdown

- critical: 3
- high: 10
- medium: 5
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 308 (network 100, file 69, infrastructure 44, entity 29, malware 26, behavioral 18, package 11, tool 11)
- New detection rules: 162 (100% of the day’s threats covered)

## More editions

- Previous: [2026-09-21](https://intel.threadlinqs.com/debrief/2026-09-21)
- Next: [2026-09-26](https://intel.threadlinqs.com/debrief/2026-09-26)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-09-25
