Summary & highlights
The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA). Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394. ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix).
Highlights
- TL-2026-2852 — The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)
- TL-2026-2857 — Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394
- TL-2026-2858 — ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix)
- TL-2026-2864 — Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization Flaw
- TL-2026-2868 — Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva Aerobus-Linked Intrusion
Theme of the day
Unattributed threats dominated the day, with only one activity linked to UAT-11587. No common tags emerged across the tracked incidents.
- credential-theft
- authentication-bypass
- vulnerability
- ransomware
- command-injection
Threats published
21 threat lines in the 2026-10-03 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898, CVE-2026-12627)CRITICAL
- AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal Credentials - CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019CRITICAL
- Rejetto HTTP File Server (HFS) 3.x session forgery via predictable Math.random() signing key leads to unauthenticated admin access and RCE (CVE-2026-61500) under active exploitationCRITICAL
- Red Hat Satellite Foreman template preview authorization flaw (CVE-2026-96659) enables root password theft and code executionCRITICAL
- TeamPCP Supply Chain Campaign: LiteLLM PyPI Compromise, CanisterWorm npm Propagation, and Multi-Ecosystem Attack (CVE-2026-33634) (update)CRITICAL
- Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware) (update)CRITICAL
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772) (update)CRITICAL
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273) (update)CRITICAL
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)HIGH
- Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394HIGH
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix)HIGH
- Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization FlawHIGH
- Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva Aerobus-Linked IntrusionHIGH
- EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled Deepfake and Crypto Drainer Fraud (TRM Labs)HIGH
- BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances (SMTP/TCP 25 C2)HIGH
- AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app exploitation, and AI-enabled attacker tooling (s1ngularity, PromptLock, JADEPUFFER/ENCFORGE)HIGH
- Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated Large-Scale Attacks, incl. CVE-2025-7775 Citrix NetScalerHIGH
- Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks (update)HIGH
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587) (update)HIGH
- City of Vicksburg, Mississippi shuts down systems after ransomware attack (update)MEDIUM
- Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69) (update)MEDIUM
Techniques observed
185 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0018
- AML.T0053
- AML.T0054
- T1001
- T1003
- T1003.001
- T1003.002
- T1003.003
- T1003.007
- T1005
- T1008
- T1021.002
- T1027
- T1027.003
- T1027.004
- T1027.010
- T1027.013
- T1033
- T1036
- T1036.004
- T1036.005
- T1036.008
- T1037.004
- T1041
- T1046
- T1047
- T1048
- T1053.003
- T1053.005
- T1055
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1070
- T1070.002
- T1070.004
- T1070.006
- T1071
- T1071.001
- T1071.003
- T1071.004
- T1078
- T1078.001
- T1078.002
- T1078.004
- T1082
- T1083
- T1087
- T1087.003
- T1087.004
- T1090
- T1095
- T1098
- T1098.003
- T1098.005
- T1098.006
- T1102
- T1102.001
- T1102.002
- T1105
- T1110
- T1110.002
- T1110.003
- T1114
- T1114.002
- T1119
- T1129
- T1132.001
- T1133
- T1136
- T1136.001
- T1140
- T1176
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1202
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1205.002
- T1210
- T1211
- T1212
- T1218.005
- T1219
- T1480
- T1482
- T1485
- T1489
- T1490
- T1491
- T1496
- T1498.001
- T1499.004
- T1505.001
- T1505.003
- T1528
- T1534
- T1539
- T1543
- T1543.002
- T1546
- T1546.004
- T1546.013
- T1546.018
- T1547
- T1547.001
- T1548
- T1548.001
- T1550
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1552.005
- T1552.007
- T1554
- T1555
- T1555.003
- T1555.004
- T1555.006
- T1556
- T1557
- T1558
- T1558.003
- T1560
- T1560.001
- T1564.001
- T1564.003
- T1564.008
- T1566
- T1566.001
- T1566.002
- T1567
- T1567.001
- T1567.002
- T1568
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1574.001
- T1574.002
- T1580
- T1583
- T1583.001
- T1583.004
- T1583.006
- T1584.008
- T1586
- T1587
- T1587.004
- T1588.002
- T1588.005
- T1588.006
- T1588.007
- T1589
- T1592.002
- T1595.002
- T1606
- T1606.001
- T1608.001
- T1610
- T1611
- T1614
- T1620
- T1657
- T1658
- T1664
- T1684.001
- T1686
Threat actors
4 named threat actors across the reports.
Nation-state attribution
- China
Threat categories
- RANSOMWARE
- MALWARE
- VULNERABILITY
- THREAT_INTEL
- PHISHING
- CLOUD
- APT
- SUPPLY_CHAIN
Severity breakdown
- critical8
- high11
- medium2
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- file 153
- network 114
- behavioral 60
- package 55
- entity 43
- infrastructure 30
- malware 28
- tool 28
- technique 1