# Daily Intelligence Briefing — Friday, October 2, 2026

> On 2026-10-02, Threadlinqs published 15 new threat reports and updated 3, 5 rated critical and 9 high, spanning 96 MITRE ATT&CK techniques and 2 named threat actors. Coverage that day added 162 new detection rules and 276 extracted indicators.

- **Edition:** 2026-10-02 (Friday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-10-02
- **Last updated:** 2026-10-05
- **New threats:** 15 (3 updated)
- **Critical / high:** 5 critical, 9 high, 4 medium, 0 low
- **ATT&CK techniques:** 96
- **Threat actors:** 2
- **Indicators (count only):** 276
- **New detection rules (count only):** 162

## Summary & highlights

Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on Firmware 7.00-13.60. City of Vicksburg, Mississippi shuts down systems after ransomware attack. Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69).

- [TL-2026-2839](https://intel.threadlinqs.com/threat/TL-2026-2839) — Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data breach
- [TL-2026-2840](https://intel.threadlinqs.com/threat/TL-2026-2840) — CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer
- [TL-2026-2844](https://intel.threadlinqs.com/threat/TL-2026-2844) — Frontline Education data breach via exploited third-party software vulnerability exposes school district employee SSNs
- [TL-2026-2848](https://intel.threadlinqs.com/threat/TL-2026-2848) — Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)
- [TL-2026-2892](https://intel.threadlinqs.com/threat/TL-2026-2892) — Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and Enables User and Admin Impersonation

## Theme of the day

Routine activity — no dominant theme emerged.

no-known-exploitation, no-cve, patched, vulnerability, social-engineering

## Threats published

- [TL-2026-2838](https://intel.threadlinqs.com/threat/TL-2026-2838) — CRITICAL — Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)
- [TL-2026-2843](https://intel.threadlinqs.com/threat/TL-2026-2843) — CRITICAL — CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD
- [TL-2026-2846](https://intel.threadlinqs.com/threat/TL-2026-2846) — CRITICAL — GitLab AI Gateway critical RCE via prompt template sandbox escape (CVE-2026-90970)
- [TL-2026-2851](https://intel.threadlinqs.com/threat/TL-2026-2851) — CRITICAL — Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)
- [TL-2026-2902](https://intel.threadlinqs.com/threat/TL-2026-2902) — CRITICAL — Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)
- [TL-2026-2839](https://intel.threadlinqs.com/threat/TL-2026-2839) — HIGH — Revolut customers targeted by phishing texts and fake liveness-check page days after social-engineering data breach
- [TL-2026-2840](https://intel.threadlinqs.com/threat/TL-2026-2840) — HIGH — CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer
- [TL-2026-2844](https://intel.threadlinqs.com/threat/TL-2026-2844) — HIGH — Frontline Education data breach via exploited third-party software vulnerability exposes school district employee SSNs
- [TL-2026-2848](https://intel.threadlinqs.com/threat/TL-2026-2848) — HIGH — Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)
- [TL-2026-2892](https://intel.threadlinqs.com/threat/TL-2026-2892) — HIGH — Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and Enables User and Admin Impersonation
- [TL-2026-2905](https://intel.threadlinqs.com/threat/TL-2026-2905) — HIGH — Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371, CVE-2026-19743)
- [TL-2026-2916](https://intel.threadlinqs.com/threat/TL-2026-2916) — HIGH — Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)
- [TL-2026-2250](https://intel.threadlinqs.com/threat/TL-2026-2250) — HIGH — BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation (update)
- [TL-2026-2849](https://intel.threadlinqs.com/threat/TL-2026-2849) — HIGH — Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux kernel CVEs (privilege escalation, DoS, information leaks) (update)
- [TL-2026-2841](https://intel.threadlinqs.com/threat/TL-2026-2841) — MEDIUM — Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on Firmware 7.00-13.60
- [TL-2026-2862](https://intel.threadlinqs.com/threat/TL-2026-2862) — MEDIUM — City of Vicksburg, Mississippi shuts down systems after ransomware attack
- [TL-2026-2876](https://intel.threadlinqs.com/threat/TL-2026-2876) — MEDIUM — Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69)
- [TL-2026-2842](https://intel.threadlinqs.com/threat/TL-2026-2842) — MEDIUM — Free Mobile phishing emails (unpaid €9.99 invoice lure) follow earlier Free Mobile data breach (update)

## Techniques observed

[T1005](https://intel.threadlinqs.com/technique/T1005), [T1010](https://intel.threadlinqs.com/technique/T1010), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1056.002](https://intel.threadlinqs.com/technique/T1056.002), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.002](https://intel.threadlinqs.com/technique/T1059.002), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.001](https://intel.threadlinqs.com/technique/T1078.001), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1098](https://intel.threadlinqs.com/technique/T1098), T1098.006, [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110.003](https://intel.threadlinqs.com/technique/T1110.003), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1132.001](https://intel.threadlinqs.com/technique/T1132.001), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1202](https://intel.threadlinqs.com/technique/T1202), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1204.004](https://intel.threadlinqs.com/technique/T1204.004), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218.005](https://intel.threadlinqs.com/technique/T1218.005), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.003](https://intel.threadlinqs.com/technique/T1548.003), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1552.007](https://intel.threadlinqs.com/technique/T1552.007), [T1553.001](https://intel.threadlinqs.com/technique/T1553.001), [T1555.001](https://intel.threadlinqs.com/technique/T1555.001), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1564.003](https://intel.threadlinqs.com/technique/T1564.003), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), T1574.002, [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1583.008](https://intel.threadlinqs.com/technique/T1583.008), [T1586.002](https://intel.threadlinqs.com/technique/T1586.002), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1598.003](https://intel.threadlinqs.com/technique/T1598.003), [T1606](https://intel.threadlinqs.com/technique/T1606), T1606.001, [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1657](https://intel.threadlinqs.com/technique/T1657), [T1684.001](https://intel.threadlinqs.com/technique/T1684.001)

## Threat actors

[UAT-11587](https://intel.threadlinqs.com/actor/UAT-11587), [Exilware](https://intel.threadlinqs.com/actor/Exilware)

Nation-state attribution: China, Brazil

Threat categories: VULNERABILITY, RANSOMWARE, PHISHING, MALWARE, DATA_BREACH, APT

## Severity breakdown

- critical: 5
- high: 9
- medium: 4
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 276 (network 73, file 65, entity 40, package 38, infrastructure 25, behavioral 18, malware 11, tool 4, technique 2)
- New detection rules: 162 (100% of the day’s threats covered)

## More editions

- Previous: [2026-09-30](https://intel.threadlinqs.com/debrief/2026-09-30)
- Next: [2026-10-03](https://intel.threadlinqs.com/debrief/2026-10-03)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-10-02
