Threadlinqs IntelligenceStart free

Daily debrief · Sunday2026-09-27

Daily Intelligence Briefing — Sunday, September 27, 2026

14 critical15 high6 medium

On 2026-09-27, Threadlinqs published 22 new threat reports and updated 13, 14 rated critical and 15 high, spanning 232 MITRE ATT&CK techniques and 10 named threat actors. Coverage that day added 315 new detection rules and 909 extracted indicators.

New threats
2213 updated
Critical / high
2914 critical · 15 high
ATT&CK techniques
232Observed in the day’s reports
Threat actors
10Named in the reports
Indicators
909Count only · values are Red+
Detection rules
315New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt Injection). Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate, RedLine/META/LummaC2/Rhadamanthys Activity. TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplace.

Highlights

  • TL-2026-2682 — Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)
  • TL-2026-2683 — Zero-Permission Android Apps Can Chain AtlasService and olc2 to Gain Root on OnePlus/OPPO Devices via OxygenOS Confused-Deputy Flaws
  • TL-2026-2685 — Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix, Email Bombing, and Remote-Access-Tool Vishing
  • TL-2026-2686 — x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining
  • TL-2026-2687 — The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments

Theme of the day

A broad threat day featuring

  • cisa-kev
  • remote-code-execution
  • credential-theft
  • active-exploitation
  • zero-day

Threats published

35 threat lines in the 2026-09-27 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

232 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

10 named threat actors across the reports.

Nation-state attribution

  • Costa Rica
  • Russia
  • China

Threat categories

  • PHISHING
  • MALWARE
  • VULNERABILITY
  • RANSOMWARE
  • ZERO_DAY
  • DATA_BREACH
  • APT

Severity breakdown

  • critical14
  • high15
  • medium6
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

909 indicators of compromise · Red and above. Compare plans
  • file 219
  • network 197
  • entity 137
  • behavioral 134
  • infrastructure 102
  • tool 56
  • malware 37
  • package 25
  • technique 2
315 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans