Executive Summary -
Highlights of Cyber Threat Intelligence Digest
Vulnerabilities
VLC Media Player CVE-2026-56711 and CVE-2026-73324 Enable Code Execution and Data Disclosure -On 9 September 2026, Red Hat reported CVE-2026-56711 and CVE-2026-73324, which affect VLC Media Player (versions 3.0.0 through 3.0.23). A vendor patch was not available at the time of disclosure, and neither report identified active exploitation.
CVE-2026-56711 is an integer overflow vulnerability in VLC Media Player's AllocatePicture function, requiring a target to open a crafted Portable Network Graphics (PNG) file; successful exploitation allows threat actors to crash VLC Media Player or execute arbitrary code. CVE-2026-73324 is a heap out-of-bounds read vulnerability in VLC Media Player's Real-Time Streaming Protocol (RTSP) module, requiring a target to access a malicious RTSP link or playlist entry; successful exploitation allows threat actors to obtain sensitive data from VLC Media Player's process memory.
Wordfence Reports Active Exploitation of CVE-2026-27540 Vulnerability in WooCommerce Wholesale Lead Capture Plugin - On 16 September 2026, Wordfence disclosed an actively exploited unauthenticated arbitrary file upload vulnerability tracked as CVE-2026-27540, affecting the Wholesale Lead Capture Plugin for WooCommerce, versions 2.0.3.1 and earlier.
Successful exploitation allows unauthenticated threat actors to upload executable PHP files and potentially achieve remote code execution (RCE). At the time of writing, Wordfence has not disclosed the identity of the threat actor behind this exploitation.
Acronis Discloses Actively Exploited Vulnerability CVE-2026-87886, Allowing Local Privilege Escalation in cPanel and WHM Backup Plugin - On 16 September 2026, Acronis disclosed an actively exploited privilege escalation vulnerability tracked as CVE-2026-87886. The vulnerability affects the Acronis Backup plugin for cPanel & WHM, versions prior to 1.9.3.1021, and the Acronis Backup extension for Plesk, versions prior to 1.8.11.638.
Successful exploitation allows threat actors to escalate privileges. At the time of writing, Acronis has not disclosed the identity of the threat actors behind this exploitation.
Potential Threats
UK, US, and Dutch Authorities Warn of Iranian Threat Actors Targeting Dissidents, Activists, and Journalists with CHOSEN BRICK Malware - On 15 September 2026, the UK National Cyber Security Centre (NCSC), the US Federal Bureau of Investigation (FBI), and the Dutch General Intelligence and Security Service (AIVD) issued a joint advisory on the "CHOSEN BRICK" malware (also known as "HEAVYGRAM"). Authorities assessed that Iranian threat actors have used CHOSEN BRICK since at least 2025 to conduct cyber espionage against dissidents, activists, journalists, and other individuals perceived as threats to the regime. Actors research targets and establish contact via platforms such as WhatsApp and Telegram, impersonating trusted individuals or platform support staff to persuade victims to open malicious files disguised as legitimate applications, including Pictory, RunwayML, NortonLite, Telegram, Flash Player, KeePass, or MRI scan results. When opened, the lure displays a convincing decoy while installing CHOSEN BRICK in the background.
Upon execution, the malware persists via the Windows Registry Run key and evades detection by adding Microsoft Defender exclusions. It connects to a victim-specific Telegram bot for command-and-control, enabling process enumeration, reconnaissance, screen and audio capture, Telegram and WhatsApp session collection, email extraction, further malware deployment, file deletion, and system wiping. Data is exfiltrated via Telegram and cloud storage services such as VultrObjects and StorjShare, with newer variants using HTTPS or SOCKS5 proxies to obscure C2 traffic.
Threat Actors Use AI-Assisted Templates in Executive Impersonation and Invoice Fraud Campaign - On 10 September 2026, Microsoft Threat Intelligence published an analysis of an AI-assisted executive impersonation and invoice fraud campaign that sent over one million emails to enterprise users. Assessed against Recorded Future's AI Malware Maturity Model (AIM3), the activity falls at Level 2 (Adopting), with Microsoft citing verbose HTML comments, structured section labels, uniform construction, and repeated narrative patterns as possible indicators of generative AI involvement, though not confirmation of it. Threat actors first gathered public information on targeted organisations, executives, finance staff, vendors, and business relationships to tailor their lures. On 31 July 2026, they registered service-nowinc[.]com, a ServiceNow lookalike domain used for the spoofed ServiceNow President address, and domainlify[.]net for Reply-To addresses. Between 3 and 5 August 2026, actors used multiple third-party email services to send over one million emails, 87.7% targeting US users across IT services, business advisory, consumer goods, and other sectors. Microsoft found no evidence of compromise among the legitimate organisations referenced, including ServiceNow.
The emails spoofed executives (CEOs, CFOs, presidents) in the sender name, Reply-To, and signature, with a brief invoice approval note urging recipients to request a PDF if needed. Beneath sat a fabricated "ServiceNow Platform - Annual Subscription" invoice with branding, invoice number, dates, amount due, and line items, directing recipients to pay nearly $50,000 via ACH to threat actor-controlled accounts that varied by target. The actors also embedded two fake forwarded emails simulating the executive and ServiceNow president discussing the purchase and payment approval; these lacked standard forwarding headers, showed left-aligned rather than indented messages, mismatched display names and addresses, and subject lines using terms like "due bill" and the misspelled "ACH Parment". The fake CEO requested direct invoice delivery without copying the sender, and the final message claimed approval from that same spoofed address.
Malicious Twitch Browser Extension Forwards OAuth Tokens to Russian Bot Service - On 11 September 2026, Socket reported a cross-browser extension campaign involving Twitch Enhanced Viewer | JeetBot, a Chrome and Firefox extension forwarding live Twitch OAuth session tokens to proxy infrastructure tied to JeetBot, a commercial Russian-language bot service for Twitch, Kick, and VK Live. Socket found 30,000 Chrome Web Store users and 552 Firefox Add-ons users. Current v85.x builds forward account-scoped OAuth tokens via URL query parameters for every watched channel outside a hard-coded allowlist of ten Russian-language streamer channels, whereas earlier v4.x builds posted tokens directly to collection endpoints. After installation, the extension presents benign viewer features (ad blocking, forced 1080p, region unlocking, channel points) while obtaining broad host permissions for Twitch's domains, letting a content script read the Authorization header and device ID and relay them to the background worker via an internal bridge, tev-proxy-session. Socket assessed the token as account-scoped rather than a narrow playback token, granting access to chat, whispers, account settings, and channel point spending.
Current builds redirect Twitch playback requests through enhanced[.]jeetbot[.]cc (or proxy[.]morphilina[.]me for forced stripping), appending the token and device ID as query parameters and exposing the bearer token in clear text in proxy logs; both domains now return errors. Firefox performs the redirect via a webRequest listener, Chrome via a declarativeNetRequest rule, and proxy destinations are fetched from ext-styles[.]jeetbot[.]cc endpoints that remain active. Earlier v4.x builds (e.g. version 4.8, January 2026) used separate collection endpoints, now also erroring, with Russian-language comments describing silent failure handling and a five-second send cooldown. Firefox Add-ons versioning jumped from 7.2.6 to 85.2.2 in April–May 2026, after which direct token posting was replaced by network-layer forwarding. Socket linked the infrastructure to JeetBot and to Popov Aleksandr Alekseevich, a jeetbot[.]cc email address, and the still-active domain alexue4[.]dev, with the store developer listed as HISHIMIRO.
General News
Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI - The National Security Agency is undertaking a fast, far-reaching reorganisation aimed at getting its intelligence to real-world battlefields more quickly, according to sources familiar with the matter. Existing directorates will be recast into five "mission centres" covering China, cybersecurity, artificial intelligence, combat support, and global intelligence, per sources who spoke to Recorded Future News; the Washington Post first reported the rearrangement. Army Gen. Joshua Rudd, who heads both the NSA and US Cyber Command, shared the changes with staff earlier this month, starting a 30-day implementation clock. Some details remain unresolved: the hacking group Tailored Access Operations is expected to sit under global intelligence, but the fate of newer bodies like the Cybersecurity Collaboration Center, and the reorganisation's effect on the NSA's relationship with Cyber Command (the two share resources and a campus at Fort Meade), is unclear. Sources said Rudd and Deputy Director Tim Kosiba know the rapid realignment will "break things" within the bureaucracy and will adjust as they go. Each centre will have its own chief, with some appointments, including the new AI head, reportedly ready for internal announcement as soon as Monday. The centres are expected to reach "full operational capability" by January.
The agency last restructured at this scale roughly a decade ago under "NSA21," which merged its offensive and defensive organisations but is now widely viewed as a failure that added bureaucratic confusion. A separate effort, "EVO25," begun early in the second Trump administration, would have consolidated agency offices but was seen as a bid to pre-empt a scheme imposed by the US DOGE Service, and was abandoned. At his January confirmation hearing, Rudd said his priorities were speed, then scale, innovation, and integration, stressing the need to move quickly on the right technologies and capabilities; he was confirmed in March, with his push for faster intelligence delivery reportedly shared by Kosiba and Executive Director Darren Turner. An NSA spokesperson said the agency's core missions "remain unchanged," and that the restructuring aims to enhance its ability to fulfil national security missions at speed and scale.
Revolut handed customer data to fraudsters using government email account - British fintech company Revolut confirmed disclosing sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government email account, apparently targeting high-net-worth individuals, many involved in crypto asset businesses. Revolut said it had "recently identified a sophisticated external impersonation scam where an unauthorised third party utilised a legitimate government agency domain email to submit fraudulent requests for information," though it did not publicly identify the domain used. Alleged extortion images circulated on Telegram by an account claiming responsibility suggested the email originated from an Italian domain, though Italian authorities did not respond to requests for comment and the Telegram account has since been suspended, with not all details in its posts confirmed. Revolut said only a limited number of customers were affected and had been notified directly, adding that upon detection it "immediately blocked the address and alerted the relevant government agency as well as enforcement agencies, data protection, and financial regulators." It is not known whether the same compromised domain targeted other financial organisations. The perpetrators reportedly called for Revolut to make an extortion payment to avoid the data being released, though Revolut declined to comment on the existence of any extortion attempt.
Affected customers described the exposed data as including birth dates, postal and email addresses, phone numbers, passport and driving licence copies, verification selfies, bank statements, international bank account numbers (IBAN), withdrawal records, and transaction histories including Bitcoin activity; individuals identifying themselves as impacted included a cryptocurrency entrepreneur and the former CEO of the Mt. Gox bitcoin exchange. The incident echoes a series of breaches in 2021 and 2022, in which hackers linked to the Lapsus$ group used compromised law enforcement accounts and forged emergency data requests to obtain user information from technology companies including Apple, Meta, and Discord; the FBI has previously issued an alert about fraudulent emergency data requests, noting an increase in criminal-forum postings offering access to compromised email accounts for this purpose. Revolut says it has more than 80 million customers globally and is considering a public listing that could value it at up to $200 billion.
UK appoints new commander of National Cyber Force - The new commander of the UK's National Cyber Force (NCF) stepped into the role this week, according to sources with knowledge of the appointment. The individual has not yet been avowed - the formal process by which an intelligence or security figure's identity is publicly acknowledged in Britain - as routine security considerations are still being worked through. They will be the third commander to lead the NCF since its 2020 establishment to consolidate Britain's offensive cyber capabilities under a unified command, a partnership between the defence and intelligence communities. The two previous commanders were drawn from either side of that partnership: inaugural commander James Babbage came from GCHQ, where he served for nearly 30 years before being avowed in early 2023 as the force published its first public doctrine paper; he led the NCF until later that year, moving to the National Crime Agency, where he is now director general for threats. His successor, Air Vice-Marshal Tim Neal-Hopes, joined in October 2023 from the armed forces, having served as director for cyber, intelligence and information integration at Strategic Command. The NCF's other partners, MI6 and the Defence Science and Technology Laboratory, have yet to contribute a commander.
The force conducts daily operations to counter state threats, support military operations, and disrupt terrorists and serious criminals. Its 2023 paper described the country as a "responsible and democratic cyber power," arguing its offensive operations are "accountable," "precise", and "calibrated," unlike attacks attributed to states such as Russia and China, though it offered little detail on how ethical standards apply in practice, with many operations regarded as necessarily covert. Plans for the force's permanent headquarters at Samlesbury, Lancashire, were "progressing as scheduled" earlier this year, with funding committed to 2030. A GCHQ spokesperson confirmed Neal-Hopes had "completed his full tenure as Commander National Cyber Force, and a new Commander has now taken up the post."
Threat Actor Weekly Graph
Over the past 7 days, we have been tracking the following intent and opportunity changes within our Threat Actor Landscape.
Intent represents the potential targets of a group. When a group is observed attacking a different organisation or entity, their intent will increase.
Opportunity represents the various methods and technologies these groups may use. For example, if a group started using a new attack vector, such as a new kind of ransomware, their opportunity would increase.
Both intent and opportunity are scored out of 100 and are responsible for scoring the group's severity. These updates can be seen below.

| ● Limited Severity | ● Basic Severity | ● Moderate Severity | ● High Severity |
| Threat Actor | Severity Increase | Opportunity | Intent | ||||||
|---|---|---|---|---|---|---|---|---|---|
| UNC6395 | ● Moderate | → | ● Moderate | ● 49 | → | ● 46 | ● 50 | → | ● 50 |
| Red Heron | NEW | → | ● Basic | NEW | → | ● 49 | NEW | → | ● 35 |
| alina20 | NEW | → | ● Basic | NEW | → | ● 32 | NEW | → | ● 30 |
| Spaniard | NEW | → | ● Basic |
NEW |
→ | ● 27 | NEW | → | ● 30 |
| zfo | NEW | → | ● Basic | NEW | → | ● 20 | NEW | → | ● 30 |
Global Trends Powered by Recorded Future
Within each category, we have provided the current top five globally trending items. Each item is linked to how actively trending it is and is marked with a small symbol.
The spikes in references are calculated over 60 days and are normalised to ensure they aren't disproportionate when compared to bigger entities that will naturally have more baseline mentions.
▲- Spike – This indicates a large increase in reporting volume and a high diversity in the event descriptions.
▲- Rise – This indicates a small increase in reporting volume with little diversity in the descriptions.
| Attackers | Methods | Vulnerabilities | Targets | |||||
|---|---|---|---|---|---|---|---|---|
| PalachPro | ▲ | Anubis Ransomware | ▲ | CVE-2026-87886 | ▲ | Revolut | ▲ | |
| North Korean APT | ▲ | Stealware | ▲ | CVE-2026-76461 | ▲ | Italian Government | ▲ | |
| Red Heron | ▲ | CHOSEN BRICK | ▲ | CVE-2026-85706 | ▲ | CenterPoint Energy | ▲ | |
| SERVER KILLERS | ▲ | Kremlin | ▲ | CVE-2026-60004 | ▲ | Pipelines | ▲ | |
| Shadowbyt3 | ▲ | REMCOS RAT | ▲ | CVE-2026-58704 | ▲ | HBO Max | ▲ | |
Prominent Information Security Events
Threat Actors Use AI -Assisted Templates in Executive Impersonation and Invoice Fraud Campaign
Source: Insikt Group | Validated Intelligence Event
IOC: Domain - domainlify[.]net
On 10 September 2026, Microsoft Threat Intelligence published an analysis of an AI-assisted executive impersonation and invoice fraud campaign that sent over one million emails to enterprise users. Assessed against Recorded Future's AI Malware Maturity Model (AIM3), the activity falls at Level 2 (Adopting), with Microsoft citing verbose HTML comments, structured section labels, uniform construction, and repeated narrative patterns as possible indicators of generative AI involvement, though not confirmation of it. Threat actors first gathered public information on targeted organisations, executives, finance staff, vendors, and business relationships to tailor their lures. On 31 July 2026, they registered service-nowinc[.]com, a ServiceNow lookalike domain used for the spoofed ServiceNow President address, alongside domainlify[.]net, used in Reply-To addresses.
Between 3 and 5 August 2026, actors used multiple third-party email services to send over one million emails, 87.7% targeting US users across IT services, business advisory, consumer goods, and other sectors. Microsoft found no evidence of compromise among the legitimate organisations referenced, including ServiceNow. The emails spoofed executives (CEOs, CFOs, presidents) in the sender name, Reply-To, and signature, with a brief invoice approval note urging recipients to request a PDF if needed. Beneath sat a fabricated "ServiceNow Platform – Annual Subscription" invoice with branding, invoice number, dates, amount due, and line items, directing recipients to pay nearly $50,000 via ACH to threat actor-controlled accounts that varied by target.
The actors also embedded two fake forwarded emails simulating the executive and ServiceNow president discussing the purchase and payment approval; these lacked standard forwarding headers, showed left-aligned rather than indented messages, mismatched display names and addresses, and subject lines using terms like "due bill" and the misspelled "ACH Parment". The fake CEO requested direct invoice delivery without copying the sender, and the final message claimed approval from that same spoofed address.
UK, US and Dutch Authorities Warn of Iranian Threat Actors Targeting Dissidents, Activists and Journalists with CHOSEN BRICK Malware
Source: Insikt Group | Validated Intelligence Event
IOC: Hash - 7e23ffadb664b0e53d821478a249d84c
On 15 September 2026, the UK National Cyber Security Centre (NCSC), the US Federal Bureau of Investigation (FBI), and the Dutch General Intelligence and Security Service (AIVD) issued a joint advisory on the "CHOSEN BRICK" malware (also known as "HEAVYGRAM"). Authorities assessed that Iranian threat actors have used CHOSEN BRICK since at least 2025 to conduct cyber espionage against dissidents, activists, journalists, and other individuals perceived as threats to the regime.
According to the advisory, Iranian threat actors initiate the attack chain by conducting research on targets and establishing contact via messaging platforms such as WhatsApp and Telegram. The threat actors reportedly impersonate trusted individuals or platform support personnel to build rapport and persuade targets to open malicious files disguised as legitimate applications, including Pictory, RunwayML, NortonLite, Telegram, Flash Player, KeePass, or MRI scan results. When opened, the lure displays a legitimate-looking decoy while installing CHOSEN BRICK in the background.
Upon execution, CHOSEN BRICK establishes persistence through the Windows Registry Run key and evades detection by adding Microsoft Defender exclusions. The malware then connects to a victim-specific Telegram bot for command-and-control (C2) communications, enabling process enumeration, system reconnaissance, screen capture, audio recording, Telegram and WhatsApp session collection, email extraction, additional malware deployment, file deletion, and system wiping. CHOSEN BRICK reportedly exfiltrates stolen data through Telegram and cloud storage services, including VultrObjects and StorjShare, with newer variants also using HTTPS or SOCKS5 proxies to obscure Telegram bot activity.
Remediation Actions
Following the information provided above, we recommend that the technologies mentioned be fully patched and updated. We also want to highlight and recommend applying the following patches where applicable:
-
CVE-2026-56711, CVE-2026-73324 (VLC) - This vulnerability affects versions 3.0.0 to 3.0.23, no patch has yet been released.
- CVE-2026-85046 (Wordfence) - This vulnerability can be remediated by patching to version 2.0.3.2 or later.
-
CVE-2026-80256 (Acronis) - Updating to version 1.9.3.1021 for Acronis Backup plugin, or version 1.8.11.638 for Acronis Backup extension for Plesk will prevent this vulnerability from being exploited.
If you are currently an Acumen Cyber Vulnerability Management customer, we will be proactively performing related searching and hunting activities within your environment.