Summary & highlights
Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt Injection). Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate, RedLine/META/LummaC2/Rhadamanthys Activity. TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplace.
Highlights
- TL-2026-2682 — Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)
- TL-2026-2683 — Zero-Permission Android Apps Can Chain AtlasService and olc2 to Gain Root on OnePlus/OPPO Devices via OxygenOS Confused-Deputy Flaws
- TL-2026-2685 — Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix, Email Bombing, and Remote-Access-Tool Vishing
- TL-2026-2686 — x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining
- TL-2026-2687 — The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments
Theme of the day
A broad threat day featuring
- cisa-kev
- remote-code-execution
- credential-theft
- active-exploitation
- zero-day
Threats published
35 threat lines in the 2026-09-27 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy CLEANGULP MalwareCRITICAL
- Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days Under Active ExploitationCRITICAL
- Kiteworks Urges Customers to Shut Down Systems After Federal Threat Intelligence Warning of Possible Zero-Day AttackCRITICAL
- Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active ExploitationCRITICAL
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)CRITICAL
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV CatalogCRITICAL
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit (update)CRITICAL
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) (update)CRITICAL
- SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE (update)CRITICAL
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for Unauthenticated Remote Code Execution (update)CRITICAL
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth Bypass (CVE-2026-67279) (update)CRITICAL
- Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day (CVE-2026-93616) Actively Exploited (update)CRITICAL
- CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint Code Injection (update)CRITICAL
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS Servers (update)CRITICAL
- Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)HIGH
- Zero-Permission Android Apps Can Chain AtlasService and olc2 to Gain Root on OnePlus/OPPO Devices via OxygenOS Confused-Deputy FlawsHIGH
- Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix, Email Bombing, and Remote-Access-Tool VishingHIGH
- x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit DrainingHIGH
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI EnvironmentsHIGH
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key TheftHIGH
- Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)HIGH
- ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic StealerHIGH
- OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM HarvestersHIGH
- SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM Data Exfiltration in Salesforce AgentforceHIGH
- Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)HIGH
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto Wallet CampaignHIGH
- Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT DeploymentsHIGH
- Roundcube Webmail Pre-Auth SQL Injection in virtuser_query Plugin (CVE-2026-48842) — Patched in 1.6.16 / 1.7.1 Alongside 7 Other Vulnerabilities (update)HIGH
- Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Prompts (update)HIGH
- Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt Injection)MEDIUM
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate, RedLine/META/LummaC2/Rhadamanthys ActivityMEDIUM
- TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover MarketplaceMEDIUM
- Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised (update)MEDIUM
- Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script (update)MEDIUM
- Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya) (update)MEDIUM
Techniques observed
232 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0034
- AML.T0051
- AML.T0051.001
- AML.T0051.002
- AML.T0052
- AML.T0053
- AML.T0057
- T0814
- T0866
- T0890
- T1003
- T1003.001
- T1003.003
- T1005
- T1014
- T1018
- T1021
- T1021.001
- T1021.002
- T1021.004
- T1027
- T1027.002
- T1027.003
- T1027.010
- T1027.013
- T1033
- T1036
- T1036.004
- T1036.005
- T1036.008
- T1037.004
- T1040
- T1041
- T1046
- T1048
- T1048.003
- T1049
- T1053
- T1053.003
- T1053.005
- T1053.006
- T1055
- T1055.012
- T1056
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.006
- T1059.007
- T1059.008
- T1068
- T1069
- T1070
- T1070.002
- T1070.003
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1074.001
- T1078
- T1078.004
- T1082
- T1083
- T1087
- T1087.001
- T1087.002
- T1090
- T1090.001
- T1090.002
- T1090.003
- T1095
- T1098
- T1098.004
- T1098.005
- T1102
- T1102.002
- T1105
- T1106
- T1110
- T1110.002
- T1111
- T1113
- T1114
- T1119
- T1129
- T1132.001
- T1133
- T1134.001
- T1135
- T1136
- T1136.001
- T1140
- T1176
- T1185
- T1190
- T1195.002
- T1203
- T1204
- T1204.002
- T1204.004
- T1210
- T1211
- T1212
- T1213
- T1217
- T1218.007
- T1219
- T1222.002
- T1404
- T1409
- T1418
- T1424
- T1482
- T1484
- T1485
- T1489
- T1496
- T1497
- T1497.001
- T1497.003
- T1498.001
- T1498.002
- T1499
- T1499.002
- T1499.003
- T1499.004
- T1505
- T1505.003
- T1518.001
- T1526
- T1528
- T1529
- T1531
- T1534
- T1537
- T1539
- T1543
- T1543.001
- T1543.002
- T1543.003
- T1546
- T1546.004
- T1547
- T1547.001
- T1548.001
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1553.001
- T1555
- T1555.001
- T1555.003
- T1556
- T1557
- T1558
- T1562.001
- T1562.004
- T1564.001
- T1565
- T1565.001
- T1565.003
- T1566
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1567.002
- T1567.004
- T1568.001
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574.001
- T1574.006
- T1575
- T1580
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.006
- T1584.001
- T1584.004
- T1584.005
- T1585
- T1585.001
- T1587
- T1587.001
- T1587.003
- T1587.004
- T1588.001
- T1588.005
- T1588.006
- T1589
- T1591
- T1592
- T1592.002
- T1595
- T1595.001
- T1595.002
- T1598
- T1606
- T1608
- T1608.001
- T1608.004
- T1608.005
- T1609
- T1610
- T1611
- T1614
- T1614.001
- T1620
- T1621
- T1622
- T1623
- T1623.001
- T1625.001
- T1629
- T1629.003
- T1649
- T1657
- T1667
- T1684.001
- T1685
Threat actors
10 named threat actors across the reports.
- Distributed MaaS operator
- S4ur0n
- WraithTools
- Infostealer operators & Initial Access Brokers
- G-MLOGS Operator Group
- Storm-2570
- UTA0565
- Derian
- Vexy Ransomware
- Red Heron
Nation-state attribution
- Costa Rica
- Russia
- China
Threat categories
- PHISHING
- MALWARE
- VULNERABILITY
- RANSOMWARE
- ZERO_DAY
- DATA_BREACH
- APT
Severity breakdown
- critical14
- high15
- medium6
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- file 219
- network 197
- entity 137
- behavioral 134
- infrastructure 102
- tool 56
- malware 37
- package 25
- technique 2