Summary & highlights
Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK A26-09-37). AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt Injection. Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem.
Highlights
- TL-2026-2656 — Adform Ad-Tech Platform Compromised: Trojanized Tracking Script Serves Crypto Clipboard Stealer via Supply-Chain Attack
- TL-2026-2657 — Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)
- TL-2026-2659 — Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)
- TL-2026-2661 — Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini Shai-Hulud CI/CD Credential-Theft Payload
- TL-2026-2664 — Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal Browser/Crypto Credentials
Theme of the day
Steady stream of unattributed threats dominated the day, punctuated by
- cisa-kev
- remote-code-execution
- credential-theft
- unauthenticated-rce
- privilege-escalation
Threats published
37 threat lines in the 2026-09-26 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service PrincipalsCRITICAL
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth Bypass (CVE-2026-67279)CRITICAL
- ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak SiteCRITICAL
- Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day (CVE-2026-93616) Actively ExploitedCRITICAL
- CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud Orchestrator Auth Bypass, F5 BIG-IP APM Heap OverflowCRITICAL
- Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day ThreatCRITICAL
- Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A) (update)CRITICAL
- Sorry Ransomware Mass Exploitation of cPanel/WHM Authentication Bypass CVE-2026-41940 (44,000+ Servers Compromised) (update)CRITICAL
- Ghost CMS Content API SQL Injection CVE-2026-26980 — Large-Scale ClickFix Watering-Hole Campaign Compromising 700+ Domains (XLab) (update)CRITICAL
- Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day (CVE-2026-35273) Exploited by ShinyHunters (UNC6240) (update)CRITICAL
- JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion Attack (update)CRITICAL
- wp2shell: WordPress Core REST API Batch-Route Confusion Chained with author__not_in SQL Injection (CVE-2026-63030 / CVE-2026-60137) Yields Unauthenticated Pre-Auth RCE (update)CRITICAL
- Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected Imminently (update)CRITICAL
- Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616) (update)CRITICAL
- CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE) (update)CRITICAL
- Adform Ad-Tech Platform Compromised: Trojanized Tracking Script Serves Crypto Clipboard Stealer via Supply-Chain AttackHIGH
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)HIGH
- Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)HIGH
- Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini Shai-Hulud CI/CD Credential-Theft PayloadHIGH
- Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal Browser/Crypto CredentialsHIGH
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm PackagesHIGH
- BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum LimitedHIGH
- Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account Creation (v4.3.0-4.3.1)HIGH
- Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via Google Cloud Storage / Vercel / Google Sites Redirect ChainHIGH
- PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method PersistenceHIGH
- Microsoft Titan Analytics JWT 'alg:none' Authentication Bypass Exposed Access to 17.3 Trillion ClickHouse RowsHIGH
- Microsoft 365 Device Code Phishing Campaign Abusing the OAuth 2.0 Device Authorization Grant Flow (EvilTokens PhaaS) (update)HIGH
- EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing Against Microsoft 365 (update)HIGH
- Pre-Release Domain Abuse Campaign Targets GTA 6 (Grand Theft Auto VI) — 922 Malicious Domains Across Typosquatting, Purchase Fraud, Crypto Lures, and Malware Distribution (update)HIGH
- Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and Journalists (update)HIGH
- AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882) (update)HIGH
- RemControl Android Banking Trojan Targets Italy and France via Fake TVTap IPTV App (update)HIGH
- Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day Targeting (update)HIGH
- Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK A26-09-37)MEDIUM
- AI-Powered Cyber Attacks: Emerging TTPs Across Phishing, Deepfake BEC, Polymorphic Malware, and Prompt InjectionMEDIUM
- Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS (update)MEDIUM
- Exploit.in Forum Database Analysis Traces Structural Roots of Modern Ransomware-as-a-Service Ecosystem
Techniques observed
326 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0040
- AML.T0051
- AML.T0054
- T0806
- T0807
- T0809
- T0811
- T0813
- T0814
- T0819
- T0821
- T0822
- T0826
- T0827
- T0828
- T0829
- T0831
- T0832
- T0835
- T0836
- T0837
- T0838
- T0843
- T0846
- T0853
- T0858
- T0859
- T0861
- T0866
- T0868
- T0869
- T0873
- T0878
- T0880
- T0883
- T0884
- T0885
- T0886
- T0888
- T0889
- T1003.007
- T1005
- T1012
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.004
- T1027
- T1027.002
- T1027.013
- T1033
- T1036
- T1036.001
- T1036.005
- T1037
- T1040
- T1041
- T1046
- T1048
- T1048.003
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.001
- T1056
- T1056.001
- T1056.002
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1059.008
- T1059.011
- T1068
- T1069
- T1069.002
- T1070
- T1070.002
- T1070.004
- T1070.006
- T1071
- T1071.001
- T1072
- T1074
- T1078
- T1078.001
- T1078.003
- T1078.004
- T1082
- T1083
- T1087
- T1087.001
- T1087.004
- T1090
- T1090.002
- T1090.003
- T1095
- T1098
- T1098.001
- T1098.004
- T1098.005
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110
- T1110.001
- T1110.002
- T1110.004
- T1113
- T1114
- T1114.002
- T1114.003
- T1115
- T1119
- T1123
- T1125
- T1129
- T1132.001
- T1133
- T1135
- T1136
- T1136.001
- T1137
- T1140
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1210
- T1211
- T1212
- T1213
- T1213.002
- T1213.003
- T1213.004
- T1218
- T1218.007
- T1219
- T1406
- T1406.002
- T1417.001
- T1417.002
- T1418
- T1481.001
- T1482
- T1485
- T1486
- T1489
- T1490
- T1491
- T1491.001
- T1491.002
- T1496
- T1497
- T1497.001
- T1497.002
- T1498
- T1499.004
- T1505
- T1505.003
- T1513
- T1516
- T1518
- T1521
- T1526
- T1528
- T1530
- T1531
- T1534
- T1537
- T1539
- T1543
- T1543.001
- T1543.002
- T1546
- T1546.004
- T1547.001
- T1547.015
- T1548
- T1548.001
- T1548.002
- T1550
- T1550.001
- T1550.002
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1553
- T1553.001
- T1553.002
- T1555
- T1555.001
- T1555.003
- T1556
- T1556.006
- T1557
- T1560
- T1560.001
- T1562
- T1562.001
- T1562.004
- T1564
- T1564.001
- T1564.008
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1566.004
- T1567
- T1567.001
- T1567.002
- T1568
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574
- T1580
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.005
- T1583.006
- T1583.007
- T1583.008
- T1584
- T1584.001
- T1584.004
- T1584.005
- T1584.006
- T1585
- T1585.001
- T1586.003
- T1587
- T1587.001
- T1587.003
- T1587.004
- T1588
- T1588.001
- T1588.002
- T1588.005
- T1588.006
- T1588.007
- T1589
- T1589.001
- T1589.002
- T1591
- T1591.004
- T1592
- T1592.002
- T1593
- T1593.003
- T1594
- T1595
- T1595.001
- T1595.002
- T1596
- T1596.003
- T1596.005
- T1598
- T1598.003
- T1599
- T1601
- T1602
- T1606
- T1606.001
- T1608
- T1608.001
- T1608.004
- T1608.005
- T1608.006
- T1611
- T1613
- T1614
- T1619
- T1620
- T1621
- T1627
- T1627.001
- T1629
- T1629.001
- T1629.003
- T1637
- T1646
- T1655
- T1655.001
- T1656
- T1657
- T1659
- T1660
- T1665
- T1677
- T1684.001
- T1685
- T1685.005
- T1685.006
- T1686
- T1692.001
- T1692.002
- T1694.001
Threat actors
14 named threat actors across the reports.
- ShinyHunters
- TeamPCP
- Blue Locker ransomware operators
- Storm-3168
- Storm-2992 (EvilTokens PhaaS operators)
- Storm-2992 (EvilTokens administrators)
- Iran Ministry of Intelligence
- Hacktron AI
- UNKK
- Cyber Av3ngers
- Mr_Rot13
- Multi-cluster
- UNC6240
- JADEPUFFER
Nation-state attribution
- Russia, China, Iran, North Korea (multiple, per-case attribution -- see timeline/description)
- France
- North Korea (MIDNIGHT NEPTUNE/UNC1069, UNC4899/TraderTraitor); UNC6780 and UNC6863 not government-attributed (UNC6863 suspected Chinese-speaking based on artifact analysis); UNC6688/Notepad-++ cluster separately attributed by Unit 42 to China-nexus Lotus Blossom
- Russia
- Iran
Threat categories
- VULNERABILITY
- THREAT_INTEL
- SUPPLY_CHAIN
- MALWARE
- RANSOMWARE
- PHISHING
- ZERO_DAY
- APT
Severity breakdown
- critical15
- high18
- medium3
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 372
- file 227
- behavioral 166
- entity 104
- infrastructure 94
- tool 71
- malware 60
- package 45
- technique 9
- financial 1