# Daily Intelligence Briefing — Sunday, September 27, 2026

> On 2026-09-27, Threadlinqs published 22 new threat reports and updated 13, 14 rated critical and 15 high, spanning 232 MITRE ATT&CK techniques and 10 named threat actors. Coverage that day added 315 new detection rules and 909 extracted indicators.

- **Edition:** 2026-09-27 (Sunday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-09-27
- **Last updated:** 2026-10-03
- **New threats:** 22 (13 updated)
- **Critical / high:** 14 critical, 15 high, 6 medium, 0 low
- **ATT&CK techniques:** 232
- **Threat actors:** 10
- **Indicators (count only):** 909
- **New detection rules (count only):** 315

## Summary & highlights

Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt Injection). Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate, RedLine/META/LummaC2/Rhadamanthys Activity. TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplace.

- [TL-2026-2682](https://intel.threadlinqs.com/threat/TL-2026-2682) — Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)
- [TL-2026-2683](https://intel.threadlinqs.com/threat/TL-2026-2683) — Zero-Permission Android Apps Can Chain AtlasService and olc2 to Gain Root on OnePlus/OPPO Devices via OxygenOS Confused-Deputy Flaws
- [TL-2026-2685](https://intel.threadlinqs.com/threat/TL-2026-2685) — Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix, Email Bombing, and Remote-Access-Tool Vishing
- [TL-2026-2686](https://intel.threadlinqs.com/threat/TL-2026-2686) — x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining
- [TL-2026-2687](https://intel.threadlinqs.com/threat/TL-2026-2687) — The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments

## Theme of the day

A broad threat day featuring

cisa-kev, remote-code-execution, credential-theft, active-exploitation, zero-day

## Threats published

- [TL-2026-2681](https://intel.threadlinqs.com/threat/TL-2026-2681) — CRITICAL — UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy CLEANGULP Malware
- [TL-2026-2688](https://intel.threadlinqs.com/threat/TL-2026-2688) — CRITICAL — Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days Under Active Exploitation
- [TL-2026-2690](https://intel.threadlinqs.com/threat/TL-2026-2690) — CRITICAL — Kiteworks Urges Customers to Shut Down Systems After Federal Threat Intelligence Warning of Possible Zero-Day Attack
- [TL-2026-2693](https://intel.threadlinqs.com/threat/TL-2026-2693) — CRITICAL — Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitation
- [TL-2026-2703](https://intel.threadlinqs.com/threat/TL-2026-2703) — CRITICAL — Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)
- [TL-2026-2711](https://intel.threadlinqs.com/threat/TL-2026-2711) — CRITICAL — CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog
- [TL-2026-2516](https://intel.threadlinqs.com/threat/TL-2026-2516) — CRITICAL — Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit (update)
- [TL-2026-2582](https://intel.threadlinqs.com/threat/TL-2026-2582) — CRITICAL — CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) (update)
- [TL-2026-2585](https://intel.threadlinqs.com/threat/TL-2026-2585) — CRITICAL — SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE (update)
- [TL-2026-2632](https://intel.threadlinqs.com/threat/TL-2026-2632) — CRITICAL — CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for Unauthenticated Remote Code Execution (update)
- [TL-2026-2669](https://intel.threadlinqs.com/threat/TL-2026-2669) — CRITICAL — CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth Bypass (CVE-2026-67279) (update)
- [TL-2026-2677](https://intel.threadlinqs.com/threat/TL-2026-2677) — CRITICAL — Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day (CVE-2026-93616) Actively Exploited (update)
- [TL-2026-2680](https://intel.threadlinqs.com/threat/TL-2026-2680) — CRITICAL — CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint Code Injection (update)
- [TL-2026-2726](https://intel.threadlinqs.com/threat/TL-2026-2726) — CRITICAL — CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS Servers (update)
- [TL-2026-2682](https://intel.threadlinqs.com/threat/TL-2026-2682) — HIGH — Citrix NetScaler: Two Unpatched Zero-Day RCE Flaws Allegedly Exploited in the Wild (watchTowr Forensic Alert)
- [TL-2026-2683](https://intel.threadlinqs.com/threat/TL-2026-2683) — HIGH — Zero-Permission Android Apps Can Chain AtlasService and olc2 to Gain Root on OnePlus/OPPO Devices via OxygenOS Confused-Deputy Flaws
- [TL-2026-2685](https://intel.threadlinqs.com/threat/TL-2026-2685) — HIGH — Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix, Email Bombing, and Remote-Access-Tool Vishing
- [TL-2026-2686](https://intel.threadlinqs.com/threat/TL-2026-2686) — HIGH — x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining
- [TL-2026-2687](https://intel.threadlinqs.com/threat/TL-2026-2687) — HIGH — The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments
- [TL-2026-2689](https://intel.threadlinqs.com/threat/TL-2026-2689) — HIGH — CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft
- [TL-2026-2698](https://intel.threadlinqs.com/threat/TL-2026-2698) — HIGH — Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)
- [TL-2026-2699](https://intel.threadlinqs.com/threat/TL-2026-2699) — HIGH — ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealer
- [TL-2026-2704](https://intel.threadlinqs.com/threat/TL-2026-2704) — HIGH — OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters
- [TL-2026-2710](https://intel.threadlinqs.com/threat/TL-2026-2710) — HIGH — SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM Data Exfiltration in Salesforce Agentforce
- [TL-2026-2717](https://intel.threadlinqs.com/threat/TL-2026-2717) — HIGH — Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)
- [TL-2026-2723](https://intel.threadlinqs.com/threat/TL-2026-2723) — HIGH — MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto Wallet Campaign
- [TL-2026-2729](https://intel.threadlinqs.com/threat/TL-2026-2729) — HIGH — Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deployments
- [TL-2026-0616](https://intel.threadlinqs.com/threat/TL-2026-0616) — HIGH — Roundcube Webmail Pre-Auth SQL Injection in virtuser_query Plugin (CVE-2026-48842) — Patched in 1.6.16 / 1.7.1 Alongside 7 Other Vulnerabilities (update)
- [TL-2026-2622](https://intel.threadlinqs.com/threat/TL-2026-2622) — HIGH — Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Prompts (update)
- [TL-2026-2707](https://intel.threadlinqs.com/threat/TL-2026-2707) — MEDIUM — Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt Injection)
- [TL-2026-2708](https://intel.threadlinqs.com/threat/TL-2026-2708) — MEDIUM — Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate, RedLine/META/LummaC2/Rhadamanthys Activity
- [TL-2026-2715](https://intel.threadlinqs.com/threat/TL-2026-2715) — MEDIUM — TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplace
- [TL-2026-2694](https://intel.threadlinqs.com/threat/TL-2026-2694) — MEDIUM — Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised (update)
- [TL-2026-2695](https://intel.threadlinqs.com/threat/TL-2026-2695) — MEDIUM — Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script (update)
- [TL-2026-2713](https://intel.threadlinqs.com/threat/TL-2026-2713) — MEDIUM — Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya) (update)

## Techniques observed

AML.T0034, [AML.T0051](https://intel.threadlinqs.com/technique/AML.T0051), [AML.T0051.001](https://intel.threadlinqs.com/technique/AML.T0051.001), AML.T0051.002, AML.T0052, [AML.T0053](https://intel.threadlinqs.com/technique/AML.T0053), AML.T0057, T0814, T0866, T0890, [T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.001](https://intel.threadlinqs.com/technique/T1003.001), [T1003.003](https://intel.threadlinqs.com/technique/T1003.003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1021.004](https://intel.threadlinqs.com/technique/T1021.004), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1027.003](https://intel.threadlinqs.com/technique/T1027.003), [T1027.010](https://intel.threadlinqs.com/technique/T1027.010), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.004](https://intel.threadlinqs.com/technique/T1036.004), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.008](https://intel.threadlinqs.com/technique/T1036.008), [T1037.004](https://intel.threadlinqs.com/technique/T1037.004), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1048.003](https://intel.threadlinqs.com/technique/T1048.003), [T1049](https://intel.threadlinqs.com/technique/T1049), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.003](https://intel.threadlinqs.com/technique/T1053.003), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), T1053.006, [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.012](https://intel.threadlinqs.com/technique/T1055.012), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), T1059.008, [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.002, [T1070.003](https://intel.threadlinqs.com/technique/T1070.003), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1074.001](https://intel.threadlinqs.com/technique/T1074.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.001](https://intel.threadlinqs.com/technique/T1087.001), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.004](https://intel.threadlinqs.com/technique/T1098.004), [T1098.005](https://intel.threadlinqs.com/technique/T1098.005), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.002](https://intel.threadlinqs.com/technique/T1110.002), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1129](https://intel.threadlinqs.com/technique/T1129), [T1132.001](https://intel.threadlinqs.com/technique/T1132.001), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134.001](https://intel.threadlinqs.com/technique/T1134.001), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1204.004](https://intel.threadlinqs.com/technique/T1204.004), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218.007](https://intel.threadlinqs.com/technique/T1218.007), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1222.002](https://intel.threadlinqs.com/technique/T1222.002), [T1404](https://intel.threadlinqs.com/technique/T1404), [T1409](https://intel.threadlinqs.com/technique/T1409), [T1418](https://intel.threadlinqs.com/technique/T1418), T1424, [T1482](https://intel.threadlinqs.com/technique/T1482), [T1484](https://intel.threadlinqs.com/technique/T1484), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1497.003](https://intel.threadlinqs.com/technique/T1497.003), [T1498.001](https://intel.threadlinqs.com/technique/T1498.001), T1498.002, [T1499](https://intel.threadlinqs.com/technique/T1499), [T1499.002](https://intel.threadlinqs.com/technique/T1499.002), [T1499.003](https://intel.threadlinqs.com/technique/T1499.003), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1534](https://intel.threadlinqs.com/technique/T1534), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1546.004](https://intel.threadlinqs.com/technique/T1546.004), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1548.001](https://intel.threadlinqs.com/technique/T1548.001), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1553.001](https://intel.threadlinqs.com/technique/T1553.001), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.001](https://intel.threadlinqs.com/technique/T1555.001), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1558](https://intel.threadlinqs.com/technique/T1558), T1562.001, T1562.004, [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), T1565.003, [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.004](https://intel.threadlinqs.com/technique/T1566.004), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1567.004](https://intel.threadlinqs.com/technique/T1567.004), T1568.001, [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), [T1574.006](https://intel.threadlinqs.com/technique/T1574.006), [T1575](https://intel.threadlinqs.com/technique/T1575), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584.001](https://intel.threadlinqs.com/technique/T1584.001), [T1584.004](https://intel.threadlinqs.com/technique/T1584.004), [T1584.005](https://intel.threadlinqs.com/technique/T1584.005), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), T1587.003, [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588.001](https://intel.threadlinqs.com/technique/T1588.001), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.001](https://intel.threadlinqs.com/technique/T1595.001), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1608.004](https://intel.threadlinqs.com/technique/T1608.004), [T1608.005](https://intel.threadlinqs.com/technique/T1608.005), [T1609](https://intel.threadlinqs.com/technique/T1609), [T1610](https://intel.threadlinqs.com/technique/T1610), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1614.001](https://intel.threadlinqs.com/technique/T1614.001), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1622](https://intel.threadlinqs.com/technique/T1622), T1623, T1623.001, T1625.001, [T1629](https://intel.threadlinqs.com/technique/T1629), T1629.003, [T1649](https://intel.threadlinqs.com/technique/T1649), [T1657](https://intel.threadlinqs.com/technique/T1657), T1667, [T1684.001](https://intel.threadlinqs.com/technique/T1684.001), [T1685](https://intel.threadlinqs.com/technique/T1685)

## Threat actors

[Distributed MaaS operator](https://intel.threadlinqs.com/actor/Distributed%20MaaS%20operator), [S4ur0n](https://intel.threadlinqs.com/actor/S4ur0n), [WraithTools](https://intel.threadlinqs.com/actor/WraithTools), [Infostealer operators & Initial Access Brokers](https://intel.threadlinqs.com/actor/Infostealer%20operators%20%26%20Initial%20Access%20Brokers), [G-MLOGS Operator Group](https://intel.threadlinqs.com/actor/G-MLOGS%20Operator%20Group), [Storm-2570](https://intel.threadlinqs.com/actor/Storm-2570), [UTA0565](https://intel.threadlinqs.com/actor/UTA0565), [Derian](https://intel.threadlinqs.com/actor/Derian), [Vexy Ransomware](https://intel.threadlinqs.com/actor/Vexy%20Ransomware), [Red Heron](https://intel.threadlinqs.com/actor/Red%20Heron)

Nation-state attribution: Costa Rica, Russia, China

Threat categories: PHISHING, MALWARE, VULNERABILITY, RANSOMWARE, ZERO_DAY, DATA_BREACH, APT

## Severity breakdown

- critical: 14
- high: 15
- medium: 6
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 909 (file 219, network 197, entity 137, behavioral 134, infrastructure 102, tool 56, malware 37, package 25, technique 2)
- New detection rules: 315 (100% of the day’s threats covered)

## More editions

- Previous: [2026-09-26](https://intel.threadlinqs.com/debrief/2026-09-26)
- Next: [2026-09-28](https://intel.threadlinqs.com/debrief/2026-09-28)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-09-27
