Threadlinqs IntelligenceStart free

Daily debrief · Saturday2026-09-26

Daily Intelligence Briefing — Saturday, September 26, 2026

15 critical18 high3 medium

On 2026-09-26, Threadlinqs published 20 new threat reports and updated 17, 15 rated critical and 18 high, spanning 326 MITRE ATT&CK techniques and 14 named threat actors. Coverage that day added 333 new detection rules and 1149 extracted indicators.

New threats
2017 updated
Critical / high
3315 critical · 18 high
ATT&CK techniques
326Observed in the day’s reports
Threat actors
14Named in the reports
Indicators
1149Count only · values are Red+
Detection rules
333New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK A26-09-37). AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt Injection. Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem.

Highlights

  • TL-2026-2656 — Adform Ad-Tech Platform Compromised: Trojanized Tracking Script Serves Crypto Clipboard Stealer via Supply-Chain Attack
  • TL-2026-2657 — Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)
  • TL-2026-2659 — Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)
  • TL-2026-2661 — Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini Shai-Hulud CI/CD Credential-Theft Payload
  • TL-2026-2664 — Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal Browser/Crypto Credentials

Theme of the day

Steady stream of unattributed threats dominated the day, punctuated by

  • cisa-kev
  • remote-code-execution
  • credential-theft
  • unauthenticated-rce
  • privilege-escalation

Threats published

37 threat lines in the 2026-09-26 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

326 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

14 named threat actors across the reports.

Nation-state attribution

  • Russia, China, Iran, North Korea (multiple, per-case attribution -- see timeline/description)
  • France
  • North Korea (MIDNIGHT NEPTUNE/UNC1069, UNC4899/TraderTraitor); UNC6780 and UNC6863 not government-attributed (UNC6863 suspected Chinese-speaking based on artifact analysis); UNC6688/Notepad-++ cluster separately attributed by Unit 42 to China-nexus Lotus Blossom
  • Russia
  • Iran

Threat categories

  • VULNERABILITY
  • THREAT_INTEL
  • SUPPLY_CHAIN
  • MALWARE
  • RANSOMWARE
  • PHISHING
  • ZERO_DAY
  • APT

Severity breakdown

  • critical15
  • high18
  • medium3
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

1149 indicators of compromise · Red and above. Compare plans
  • network 372
  • file 227
  • behavioral 166
  • entity 104
  • infrastructure 94
  • tool 71
  • malware 60
  • package 45
  • technique 9
  • financial 1
333 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans