Summary & highlights
Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on Firmware 7.00-13.60. City of Vicksburg, Mississippi shuts down systems after ransomware attack. Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69).
Highlights
- TL-2026-2839 — Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data breach
- TL-2026-2840 — CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer
- TL-2026-2844 — Frontline Education data breach via exploited third-party software vulnerability exposes school district employee SSNs
- TL-2026-2848 — Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)
- TL-2026-2892 — Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and Enables User and Admin Impersonation
Theme of the day
Routine activity — no dominant theme emerged.
- no-known-exploitation
- no-cve
- patched
- vulnerability
- social-engineering
Threats published
18 threat lines in the 2026-10-02 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)CRITICAL
- CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVDCRITICAL
- GitLab AI Gateway critical RCE via prompt template sandbox escape (CVE-2026-90970)CRITICAL
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)CRITICAL
- Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)CRITICAL
- Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data breachHIGH
- CloudSyncD macOS Backdoor Delivered via Fake Zoom InstallerHIGH
- Frontline Education data breach via exploited third-party software vulnerability exposes school district employee SSNsHIGH
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)HIGH
- Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and Enables User and Admin ImpersonationHIGH
- Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371, CVE-2026-19743)HIGH
- Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)HIGH
- BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation (update)HIGH
- Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux kernel CVEs (privilege escalation, DoS, information leaks) (update)HIGH
- Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on Firmware 7.00-13.60MEDIUM
- City of Vicksburg, Mississippi shuts down systems after ransomware attackMEDIUM
- Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69)MEDIUM
- Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breach (update)MEDIUM
Techniques observed
96 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1005
- T1010
- T1012
- T1016
- T1021
- T1027
- T1027.002
- T1033
- T1036
- T1036.005
- T1041
- T1046
- T1056.002
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.005
- T1059.007
- T1068
- T1071.001
- T1078
- T1078.001
- T1078.004
- T1082
- T1083
- T1087
- T1098
- T1098.006
- T1102.001
- T1102.002
- T1105
- T1106
- T1110.003
- T1113
- T1132.001
- T1133
- T1140
- T1190
- T1199
- T1202
- T1203
- T1204.001
- T1204.002
- T1204.004
- T1211
- T1212
- T1213
- T1217
- T1218.005
- T1219
- T1490
- T1497.001
- T1499.004
- T1518
- T1528
- T1539
- T1547.001
- T1548
- T1548.003
- T1550
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1552.007
- T1553.001
- T1555.001
- T1555.003
- T1557
- T1560.001
- T1564.001
- T1564.003
- T1565.001
- T1566.001
- T1566.002
- T1567.002
- T1573.001
- T1574.001
- T1574.002
- T1583.001
- T1583.006
- T1583.008
- T1586.002
- T1589
- T1598.003
- T1606
- T1606.001
- T1608.001
- T1611
- T1620
- T1657
- T1684.001
Threat actors
2 named threat actors across the reports.
Nation-state attribution
- China
- Brazil
Threat categories
- VULNERABILITY
- RANSOMWARE
- PHISHING
- MALWARE
- DATA_BREACH
- APT
Severity breakdown
- critical5
- high9
- medium4
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 73
- file 65
- entity 40
- package 38
- infrastructure 25
- behavioral 18
- malware 11
- tool 4
- technique 2