# Daily Intelligence Briefing — Sunday, October 4, 2026

> On 2026-10-04, Threadlinqs published 12 new threat reports and updated 11, 8 rated critical and 13 high, spanning 173 MITRE ATT&CK techniques and 8 named threat actors. Coverage that day added 207 new detection rules and 457 extracted indicators.

- **Edition:** 2026-10-04 (Sunday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-10-04
- **Last updated:** 2026-10-05
- **New threats:** 12 (11 updated)
- **Critical / high:** 8 critical, 13 high, 2 medium, 0 low
- **ATT&CK techniques:** 173
- **Threat actors:** 8
- **Indicators (count only):** 457
- **New detection rules (count only):** 207

## Summary & highlights

Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC. Coordinated model-distillation campaign against OpenAI: 15,000+ accounts attempt to extract protected model reasoning, linked to Moonshot AI-associated individuals. Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root on Host) via Sandbox Bug Bounty; $50,000 Bounty Awarded.

- [TL-2026-2878](https://intel.threadlinqs.com/threat/TL-2026-2878) — Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root on Host) via Sandbox Bug Bounty; $50,000 Bounty Awarded
- [TL-2026-2884](https://intel.threadlinqs.com/threat/TL-2026-2884) — China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)
- [TL-2026-2889](https://intel.threadlinqs.com/threat/TL-2026-2889) — TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files (CVE-2026-60137, CVE-2026-63030)
- [TL-2026-2896](https://intel.threadlinqs.com/threat/TL-2026-2896) — CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Catalog
- [TL-2026-2898](https://intel.threadlinqs.com/threat/TL-2026-2898) — Kairos Data-Extortion Group Claims Slate Valley Unified School District (Vermont); 762 GB Claimed, Board Declines Ransom, Leak Imminent

## Theme of the day

Unattributed threats dominated the day, with notable activity from Akira ransomware and Storm-2992, targeting cloud and sandbox environments.

cisa-kev, brand-impersonation, privilege-escalation, zero-day, adversary-in-the-middle

## Threats published

- [TL-2026-2894](https://intel.threadlinqs.com/threat/TL-2026-2894) — CRITICAL — Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features (CVE-2026-103922)
- [TL-2026-2912](https://intel.threadlinqs.com/threat/TL-2026-2912) — CRITICAL — Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698, CVE-2026-93029, CVE-2026-93697) Enable Root Code Execution and Admin Session Hijacking
- [TL-2026-1083](https://intel.threadlinqs.com/threat/TL-2026-1083) — CRITICAL — JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos (CVE-2021-29441) (update)
- [TL-2026-1875](https://intel.threadlinqs.com/threat/TL-2026-1875) — CRITICAL — ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting 444+ Packages (update)
- [TL-2026-2830](https://intel.threadlinqs.com/threat/TL-2026-2830) — CRITICAL — Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attacks (update)
- [TL-2026-2833](https://intel.threadlinqs.com/threat/TL-2026-2833) — CRITICAL — Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs / Storm-2603) (update)
- [TL-2026-2843](https://intel.threadlinqs.com/threat/TL-2026-2843) — CRITICAL — CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD (update)
- [TL-2026-2902](https://intel.threadlinqs.com/threat/TL-2026-2902) — CRITICAL — Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149) (update)
- [TL-2026-2878](https://intel.threadlinqs.com/threat/TL-2026-2878) — HIGH — Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root on Host) via Sandbox Bug Bounty; $50,000 Bounty Awarded
- [TL-2026-2884](https://intel.threadlinqs.com/threat/TL-2026-2884) — HIGH — China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)
- [TL-2026-2889](https://intel.threadlinqs.com/threat/TL-2026-2889) — HIGH — TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files (CVE-2026-60137, CVE-2026-63030)
- [TL-2026-2896](https://intel.threadlinqs.com/threat/TL-2026-2896) — HIGH — CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Catalog
- [TL-2026-2898](https://intel.threadlinqs.com/threat/TL-2026-2898) — HIGH — Kairos Data-Extortion Group Claims Slate Valley Unified School District (Vermont); 762 GB Claimed, Board Declines Ransom, Leak Imminent
- [TL-2026-2901](https://intel.threadlinqs.com/threat/TL-2026-2901) — HIGH — Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to Bypass MFA
- [TL-2026-2908](https://intel.threadlinqs.com/threat/TL-2026-2908) — HIGH — Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guilty
- [TL-2026-2919](https://intel.threadlinqs.com/threat/TL-2026-2919) — HIGH — Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA
- [TL-2026-2858](https://intel.threadlinqs.com/threat/TL-2026-2858) — HIGH — ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix) (update)
- [TL-2026-2892](https://intel.threadlinqs.com/threat/TL-2026-2892) — HIGH — Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and Enables User and Admin Impersonation (update)
- [TL-2026-2897](https://intel.threadlinqs.com/threat/TL-2026-2897) — HIGH — Ransomware Moves up the Org Chart: Managers Are Prime Targets (Zscaler ThreatLabz, 351 Victims / 334 Organizations) (update)
- [TL-2026-2905](https://intel.threadlinqs.com/threat/TL-2026-2905) — HIGH — Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371, CVE-2026-19743) (update)
- [TL-2026-2916](https://intel.threadlinqs.com/threat/TL-2026-2916) — HIGH — Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style) (update)
- [TL-2026-2891](https://intel.threadlinqs.com/threat/TL-2026-2891) — MEDIUM — Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC
- [TL-2026-2915](https://intel.threadlinqs.com/threat/TL-2026-2915) — MEDIUM — Coordinated model-distillation campaign against OpenAI: 15,000+ accounts attempt to extract protected model reasoning, linked to Moonshot AI-associated individuals

## Techniques observed

AML.T0005, AML.T0024, AML.T0024.002, AML.T0040, [AML.T0051](https://intel.threadlinqs.com/technique/AML.T0051), [T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.001](https://intel.threadlinqs.com/technique/T1003.001), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1027.004](https://intel.threadlinqs.com/technique/T1027.004), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.008](https://intel.threadlinqs.com/technique/T1036.008), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.003](https://intel.threadlinqs.com/technique/T1053.003), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1056.002](https://intel.threadlinqs.com/technique/T1056.002), [T1056.003](https://intel.threadlinqs.com/technique/T1056.003), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.002](https://intel.threadlinqs.com/technique/T1059.002), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1074](https://intel.threadlinqs.com/technique/T1074), T1074.002, [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.001](https://intel.threadlinqs.com/technique/T1078.001), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1098](https://intel.threadlinqs.com/technique/T1098), T1098.007, [T1102](https://intel.threadlinqs.com/technique/T1102), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.001](https://intel.threadlinqs.com/technique/T1110.001), [T1110.003](https://intel.threadlinqs.com/technique/T1110.003), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1114.003](https://intel.threadlinqs.com/technique/T1114.003), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.004](https://intel.threadlinqs.com/technique/T1204.004), [T1205](https://intel.threadlinqs.com/technique/T1205), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), T1213.006, [T1218.007](https://intel.threadlinqs.com/technique/T1218.007), [T1219](https://intel.threadlinqs.com/technique/T1219), T1219.001, [T1480](https://intel.threadlinqs.com/technique/T1480), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1484.001](https://intel.threadlinqs.com/technique/T1484.001), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546](https://intel.threadlinqs.com/technique/T1546), T1546.013, [T1548](https://intel.threadlinqs.com/technique/T1548), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1553.001](https://intel.threadlinqs.com/technique/T1553.001), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.001](https://intel.threadlinqs.com/technique/T1555.001), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.003](https://intel.threadlinqs.com/technique/T1564.003), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.003](https://intel.threadlinqs.com/technique/T1566.003), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.001](https://intel.threadlinqs.com/technique/T1567.001), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), T1574.002, [T1574.006](https://intel.threadlinqs.com/technique/T1574.006), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.008](https://intel.threadlinqs.com/technique/T1583.008), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1585.002](https://intel.threadlinqs.com/technique/T1585.002), [T1585.003](https://intel.threadlinqs.com/technique/T1585.003), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.001](https://intel.threadlinqs.com/technique/T1589.001), [T1591.004](https://intel.threadlinqs.com/technique/T1591.004), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1598.003](https://intel.threadlinqs.com/technique/T1598.003), [T1606](https://intel.threadlinqs.com/technique/T1606), T1606.001, [T1608](https://intel.threadlinqs.com/technique/T1608), [T1609](https://intel.threadlinqs.com/technique/T1609), [T1610](https://intel.threadlinqs.com/technique/T1610), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1636](https://intel.threadlinqs.com/technique/T1636), [T1650](https://intel.threadlinqs.com/technique/T1650), [T1657](https://intel.threadlinqs.com/technique/T1657), [T1684.001](https://intel.threadlinqs.com/technique/T1684.001), T1684.002, [T1685](https://intel.threadlinqs.com/technique/T1685)

## Threat actors

[Individuals associated with Moonshot AI](https://intel.threadlinqs.com/actor/Individuals%20associated%20with%20Moonshot%20AI), [TA419](https://intel.threadlinqs.com/actor/TA419), [Kairos](https://intel.threadlinqs.com/actor/Kairos), [Milk Dragon](https://intel.threadlinqs.com/actor/Milk%20Dragon), [UNC5537](https://intel.threadlinqs.com/actor/UNC5537), JADEPUFFER (Storm-3168), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP), [Longlegs](https://intel.threadlinqs.com/actor/Longlegs)

Nation-state attribution: China

Threat categories: VULNERABILITY, THREAT_INTEL, ZERO_DAY, PHISHING, MALWARE, RANSOMWARE, DATA_BREACH, SUPPLY_CHAIN

## Severity breakdown

- critical: 8
- high: 13
- medium: 2
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 457 (file 133, network 116, behavioral 49, entity 45, infrastructure 43, package 30, malware 22, tool 15, technique 4)
- New detection rules: 207 (100% of the day’s threats covered)

## More editions

- Previous: [2026-10-03](https://intel.threadlinqs.com/debrief/2026-10-03)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-10-04
