Threadlinqs IntelligenceStart free

Daily debrief · Monday2026-09-28

Daily Intelligence Briefing — Monday, September 28, 2026

6 critical11 high2 medium

On 2026-09-28, Threadlinqs published 12 new threat reports and updated 7, 6 rated critical and 11 high, spanning 201 MITRE ATT&CK techniques and 8 named threat actors. Coverage that day added 171 new detection rules and 509 extracted indicators.

New threats
127 updated
Critical / high
176 critical · 11 high
ATT&CK techniques
201Observed in the day’s reports
Threat actors
8Named in the reports
Indicators
509Count only · values are Red+
Detection rules
171New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

GitHub Security Lab AI Agent Uncovers 24 Android App Vulnerabilities, Including OsmAnd Location-Tracking Flaw and Wikipedia Account Takeover. ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and Multiple Unverified Data-Breach Claims. NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations.

Highlights

  • TL-2026-2730 — ASEC August 2026 Financial Sector Threat Landscape: LockBit 5.0 Ransomware Activity, Phishing Dominance, and Multiple Unverified Data-Breach Claims
  • TL-2026-2733 — NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations
  • TL-2026-2739 — Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History, Screenshots, and AI Chatbot Conversations From Millions
  • TL-2026-2743 — RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritization
  • TL-2026-2745 — Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks

Theme of the day

Activity centered on active-exploitation, ahnlab, asec.

  • cisa-kev
  • credential-theft
  • phishing
  • anthropic
  • extortion

Threats published

19 threat lines in the 2026-09-28 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

201 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

8 named threat actors across the reports.

Nation-state attribution

  • China (suspected; Microsoft has not formally attributed Storm-3069 to a Chinese nation-state actor)
  • China
  • North Korea

Threat categories

  • VULNERABILITY
  • THREAT_INTEL
  • MALWARE
  • DATA_BREACH
  • SUPPLY_CHAIN
  • RANSOMWARE
  • APT

Severity breakdown

  • critical6
  • high11
  • medium2
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

509 indicators of compromise · Red and above. Compare plans
  • file 126
  • network 126
  • behavioral 69
  • entity 50
  • malware 44
  • infrastructure 36
  • tool 28
  • package 26
  • technique 3
  • financial 1
171 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans