# Daily Intelligence Briefing — Saturday, October 3, 2026

> On 2026-10-03, Threadlinqs published 13 new threat reports and updated 8, 8 rated critical and 11 high, spanning 185 MITRE ATT&CK techniques and 4 named threat actors. Coverage that day added 189 new detection rules and 512 extracted indicators.

- **Edition:** 2026-10-03 (Saturday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-10-03
- **Last updated:** 2026-10-05
- **New threats:** 13 (8 updated)
- **Critical / high:** 8 critical, 11 high, 2 medium, 0 low
- **ATT&CK techniques:** 185
- **Threat actors:** 4
- **Indicators (count only):** 512
- **New detection rules (count only):** 189

## Summary & highlights

The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA). Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394. ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix).

- [TL-2026-2852](https://intel.threadlinqs.com/threat/TL-2026-2852) — The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)
- [TL-2026-2857](https://intel.threadlinqs.com/threat/TL-2026-2857) — Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394
- [TL-2026-2858](https://intel.threadlinqs.com/threat/TL-2026-2858) — ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix)
- [TL-2026-2864](https://intel.threadlinqs.com/threat/TL-2026-2864) — Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization Flaw
- [TL-2026-2868](https://intel.threadlinqs.com/threat/TL-2026-2868) — Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva Aerobus-Linked Intrusion

## Theme of the day

Unattributed threats dominated the day, with only one activity linked to UAT-11587. No common tags emerged across the tracked incidents.

credential-theft, authentication-bypass, vulnerability, ransomware, command-injection

## Threats published

- [TL-2026-2854](https://intel.threadlinqs.com/threat/TL-2026-2854) — CRITICAL — Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898, CVE-2026-12627)
- [TL-2026-2860](https://intel.threadlinqs.com/threat/TL-2026-2860) — CRITICAL — AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal Credentials - CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019
- [TL-2026-2865](https://intel.threadlinqs.com/threat/TL-2026-2865) — CRITICAL — Rejetto HTTP File Server (HFS) 3.x session forgery via predictable Math.random() signing key leads to unauthenticated admin access and RCE (CVE-2026-61500) under active exploitation
- [TL-2026-2874](https://intel.threadlinqs.com/threat/TL-2026-2874) — CRITICAL — Red Hat Satellite Foreman template preview authorization flaw (CVE-2026-96659) enables root password theft and code execution
- [TL-2026-0279](https://intel.threadlinqs.com/threat/TL-2026-0279) — CRITICAL — TeamPCP Supply Chain Campaign: LiteLLM PyPI Compromise, CanisterWorm npm Propagation, and Multi-Ecosystem Attack (CVE-2026-33634) (update)
- [TL-2026-1861](https://intel.threadlinqs.com/threat/TL-2026-1861) — CRITICAL — Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware) (update)
- [TL-2026-2703](https://intel.threadlinqs.com/threat/TL-2026-2703) — CRITICAL — Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772) (update)
- [TL-2026-2851](https://intel.threadlinqs.com/threat/TL-2026-2851) — CRITICAL — Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273) (update)
- [TL-2026-2852](https://intel.threadlinqs.com/threat/TL-2026-2852) — HIGH — The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)
- [TL-2026-2857](https://intel.threadlinqs.com/threat/TL-2026-2857) — HIGH — Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394
- [TL-2026-2858](https://intel.threadlinqs.com/threat/TL-2026-2858) — HIGH — ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix)
- [TL-2026-2864](https://intel.threadlinqs.com/threat/TL-2026-2864) — HIGH — Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization Flaw
- [TL-2026-2868](https://intel.threadlinqs.com/threat/TL-2026-2868) — HIGH — Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva Aerobus-Linked Intrusion
- [TL-2026-2873](https://intel.threadlinqs.com/threat/TL-2026-2873) — HIGH — EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled Deepfake and Crypto Drainer Fraud (TRM Labs)
- [TL-2026-2875](https://intel.threadlinqs.com/threat/TL-2026-2875) — HIGH — BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances (SMTP/TCP 25 C2)
- [TL-2026-2880](https://intel.threadlinqs.com/threat/TL-2026-2880) — HIGH — AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app exploitation, and AI-enabled attacker tooling (s1ngularity, PromptLock, JADEPUFFER/ENCFORGE)
- [TL-2026-2881](https://intel.threadlinqs.com/threat/TL-2026-2881) — HIGH — Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated Large-Scale Attacks, incl. CVE-2025-7775 Citrix NetScaler
- [TL-2026-2745](https://intel.threadlinqs.com/threat/TL-2026-2745) — HIGH — Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks (update)
- [TL-2026-2848](https://intel.threadlinqs.com/threat/TL-2026-2848) — HIGH — Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587) (update)
- [TL-2026-2862](https://intel.threadlinqs.com/threat/TL-2026-2862) — MEDIUM — City of Vicksburg, Mississippi shuts down systems after ransomware attack (update)
- [TL-2026-2876](https://intel.threadlinqs.com/threat/TL-2026-2876) — MEDIUM — Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69) (update)

## Techniques observed

AML.T0018, [AML.T0053](https://intel.threadlinqs.com/technique/AML.T0053), [AML.T0054](https://intel.threadlinqs.com/technique/AML.T0054), [T1001](https://intel.threadlinqs.com/technique/T1001), [T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.001](https://intel.threadlinqs.com/technique/T1003.001), [T1003.002](https://intel.threadlinqs.com/technique/T1003.002), [T1003.003](https://intel.threadlinqs.com/technique/T1003.003), [T1003.007](https://intel.threadlinqs.com/technique/T1003.007), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.003](https://intel.threadlinqs.com/technique/T1027.003), [T1027.004](https://intel.threadlinqs.com/technique/T1027.004), [T1027.010](https://intel.threadlinqs.com/technique/T1027.010), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.004](https://intel.threadlinqs.com/technique/T1036.004), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.008](https://intel.threadlinqs.com/technique/T1036.008), [T1037.004](https://intel.threadlinqs.com/technique/T1037.004), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1053.003](https://intel.threadlinqs.com/technique/T1053.003), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.002, [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1070.006](https://intel.threadlinqs.com/technique/T1070.006), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), T1071.003, [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.001](https://intel.threadlinqs.com/technique/T1078.001), [T1078.002](https://intel.threadlinqs.com/technique/T1078.002), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), T1087.003, [T1087.004](https://intel.threadlinqs.com/technique/T1087.004), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.003](https://intel.threadlinqs.com/technique/T1098.003), [T1098.005](https://intel.threadlinqs.com/technique/T1098.005), T1098.006, [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.002](https://intel.threadlinqs.com/technique/T1110.002), [T1110.003](https://intel.threadlinqs.com/technique/T1110.003), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1114.002](https://intel.threadlinqs.com/technique/T1114.002), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1129](https://intel.threadlinqs.com/technique/T1129), [T1132.001](https://intel.threadlinqs.com/technique/T1132.001), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1202](https://intel.threadlinqs.com/technique/T1202), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1204.004](https://intel.threadlinqs.com/technique/T1204.004), T1205.002, [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1218.005](https://intel.threadlinqs.com/technique/T1218.005), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1480](https://intel.threadlinqs.com/technique/T1480), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1498.001](https://intel.threadlinqs.com/technique/T1498.001), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), T1505.001, [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1534](https://intel.threadlinqs.com/technique/T1534), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1546.004](https://intel.threadlinqs.com/technique/T1546.004), T1546.013, T1546.018, [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.001](https://intel.threadlinqs.com/technique/T1548.001), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1552.007](https://intel.threadlinqs.com/technique/T1552.007), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1555.004](https://intel.threadlinqs.com/technique/T1555.004), T1555.006, [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1558](https://intel.threadlinqs.com/technique/T1558), [T1558.003](https://intel.threadlinqs.com/technique/T1558.003), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1564.003](https://intel.threadlinqs.com/technique/T1564.003), [T1564.008](https://intel.threadlinqs.com/technique/T1564.008), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.001](https://intel.threadlinqs.com/technique/T1567.001), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), T1574.002, [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584.008](https://intel.threadlinqs.com/technique/T1584.008), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1588.007](https://intel.threadlinqs.com/technique/T1588.007), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1606](https://intel.threadlinqs.com/technique/T1606), T1606.001, [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1610](https://intel.threadlinqs.com/technique/T1610), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1657](https://intel.threadlinqs.com/technique/T1657), T1658, T1664, [T1684.001](https://intel.threadlinqs.com/technique/T1684.001), [T1686](https://intel.threadlinqs.com/technique/T1686)

## Threat actors

[Akira](https://intel.threadlinqs.com/actor/Akira), [Storm-2992](https://intel.threadlinqs.com/actor/Storm-2992), [UAT-11587](https://intel.threadlinqs.com/actor/UAT-11587), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP)

Nation-state attribution: China

Threat categories: RANSOMWARE, MALWARE, VULNERABILITY, THREAT_INTEL, PHISHING, CLOUD, APT, SUPPLY_CHAIN

## Severity breakdown

- critical: 8
- high: 11
- medium: 2
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 512 (file 153, network 114, behavioral 60, package 55, entity 43, infrastructure 30, malware 28, tool 28, technique 1)
- New detection rules: 189 (100% of the day’s threats covered)

## More editions

- Previous: [2026-10-02](https://intel.threadlinqs.com/debrief/2026-10-02)
- Next: [2026-10-04](https://intel.threadlinqs.com/debrief/2026-10-04)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-10-03
