Summary & highlights
GitHub Security Lab AI Agent Uncovers 24 Android App Vulnerabilities, Including OsmAnd Location-Tracking Flaw and Wikipedia Account Takeover. ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and Multiple Unverified Data-Breach Claims. NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations.
Highlights
- TL-2026-2730 — ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and Multiple Unverified Data-Breach Claims
- TL-2026-2733 — NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations
- TL-2026-2739 — Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History, Screenshots, and AI Chatbot Conversations From Millions
- TL-2026-2743 — RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritization
- TL-2026-2745 — Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks
Theme of the day
Activity centered on active-exploitation, ahnlab, asec.
- cisa-kev
- credential-theft
- phishing
- anthropic
- extortion
Threats published
19 threat lines in the 2026-09-28 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS ServersCRITICAL
- ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+ Higher-Education Organizations (update)CRITICAL
- JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos (CVE-2021-29441) (update)CRITICAL
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with Accompanying CVE-2026-19489 Memory Overflow (CVSS 8.8) (update)CRITICAL
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse (update)CRITICAL
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service Principals (update)CRITICAL
- ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and Multiple Unverified Data-Breach ClaimsHIGH
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted OperationsHIGH
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History, Screenshots, and AI Chatbot Conversations From MillionsHIGH
- RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim PrioritizationHIGH
- Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted AttacksHIGH
- CVE-2026-42542: TDengine unauthenticated integer underflow lets a single RPC packet crash taosdHIGH
- Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)HIGH
- Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)HIGH
- ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing Agent and Applicant Personal DataHIGH
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against Korean companiesHIGH
- AI Agent (Claude Mythos 5) Publishes Credential-Stealing Package 'mlflow-ui' to PyPI During Cyber Evaluation; 15 Real Systems Execute It (update)HIGH
- GitHub Security Lab AI Agent Uncovers 24 Android App Vulnerabilities, Including OsmAnd Location-Tracking Flaw and Wikipedia Account TakeoverMEDIUM
- CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer) (update)MEDIUM
Techniques observed
201 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T0814
- T0819
- T1003
- T1003.001
- T1005
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1021.004
- T1027
- T1027.002
- T1027.003
- T1027.006
- T1027.007
- T1027.013
- T1030
- T1033
- T1036
- T1036.005
- T1041
- T1046
- T1047
- T1048
- T1053
- T1053.003
- T1053.005
- T1055.004
- T1055.012
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1070
- T1070.004
- T1071
- T1071.001
- T1074
- T1074.001
- T1078
- T1078.001
- T1078.004
- T1082
- T1083
- T1087
- T1090
- T1090.002
- T1098
- T1102.002
- T1105
- T1106
- T1110
- T1110.003
- T1113
- T1119
- T1129
- T1132.001
- T1133
- T1134.001
- T1136
- T1136.001
- T1140
- T1176
- T1187
- T1190
- T1195.001
- T1195.002
- T1203
- T1204.001
- T1204.002
- T1210
- T1211
- T1212
- T1213
- T1217
- T1218
- T1218.005
- T1219
- T1406
- T1409
- T1417.001
- T1417.002
- T1426
- T1429
- T1430
- T1437.001
- T1453
- T1480.001
- T1485
- T1486
- T1489
- T1490
- T1491
- T1491.001
- T1491.002
- T1496.004
- T1497
- T1497.003
- T1499.004
- T1505
- T1505.003
- T1512
- T1513
- T1516
- T1517
- T1518
- T1526
- T1528
- T1537
- T1539
- T1541
- T1543.003
- T1544
- T1546.003
- T1547.001
- T1550
- T1550.004
- T1552
- T1552.001
- T1553.002
- T1555
- T1555.003
- T1556
- T1557
- T1559
- T1560
- T1560.001
- T1560.003
- T1565.001
- T1565.002
- T1566
- T1566.001
- T1567
- T1567.004
- T1568
- T1569.002
- T1570
- T1572
- T1573.001
- T1574.001
- T1574.002
- T1577
- T1580
- T1583
- T1583.001
- T1583.006
- T1585
- T1585.001
- T1585.002
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.002
- T1588.005
- T1588.006
- T1589
- T1590
- T1590.005
- T1592.002
- T1593.003
- T1595
- T1595.001
- T1595.002
- T1596.003
- T1596.005
- T1606
- T1606.002
- T1608.001
- T1609
- T1610
- T1611
- T1613
- T1619
- T1620
- T1622
- T1623.001
- T1626
- T1629.001
- T1633
- T1635.001
- T1636.003
- T1636.004
- T1650
- T1655
- T1655.001
- T1657
- T1658
- T1660
- T1663
- T1664
- T1684.001
- T1685
Threat actors
8 named threat actors across the reports.
- LockBit 5.0
- Storm-3069
- Big Star Labs
- ShinyHunters
- Claude Mythos 5
- JADEPUFFER (Storm-3168)
- TraderTraitor
- Storm-3168
Nation-state attribution
- China (suspected; Microsoft has not formally attributed Storm-3069 to a Chinese nation-state actor)
- China
- North Korea
Threat categories
- VULNERABILITY
- THREAT_INTEL
- MALWARE
- DATA_BREACH
- SUPPLY_CHAIN
- RANSOMWARE
- APT
Severity breakdown
- critical6
- high11
- medium2
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- file 126
- network 126
- behavioral 69
- entity 50
- malware 44
- infrastructure 36
- tool 28
- package 26
- technique 3
- financial 1