Executive Summary -
Highlights of Cyber Threat Intelligence Digest
Vulnerabilities
Microsoft Patches Critical Azure AI Foundry Vulnerability CVE-2026-85889 - On 17 September 2026, Microsoft patched CVE-2026-85889, a critical elevation of privilege vulnerability affecting Azure AI Foundry. The flaw stems from missing authentication for a critical function and could allow a threat actor to elevate privileges over a network.
Exploitation requires no privileges or user interaction and could affect confidentiality, integrity and availability. Microsoft has stated that the vulnerability has already been fully mitigated within the cloud service and that no customer action is required.
SolarWinds Patches CVE-2026-28326 Vulnerability in Access Rights Manager - On 17 September 2026, SolarWinds patched CVE-2026-28326, a high-severity use of hard-coded cryptographic key vulnerability in SolarWinds Access Rights Manager (ARM) versions 2026.2 and prior.
Successful exploitation allows threat actors to execute arbitrary code. SolarWinds addressed the vulnerability in version 2026.2.1.
Linux Patches CVE-2026-89775 Vulnerability in KVM/arm64 Systems - On 22 September 2026, Linux patched CVE-2026-89775, a KVM/arm64 vulnerability affecting hosts with nested virtualisation enabled. The flaw was disclosed on 16 September 2026 following expiry of the linux-distros embargo and stems from a type truncation in the stage-1 walk level used by KVM/arm64 nested virtualisation. Under certain conditions, the size calculation returns 0, which is treated as "size unknown". The VNCR pseudo-TLB invalidation path then interprets that value as a valid size, causing the invalidation range to become empty and leaving stale writable host memory mappings accessible from the guest. The flaw is patched in Linux 6.18.51, 7.2.5 and 7.3-rc, and there is no evidence of active exploitation at the time of writing.
Successful exploitation could allow a guest to read and write host kernel memory without a trap or VM exit. On systems where /dev/kvm is world-writable and nested virtualisation is enabled, such as some RHEL configurations, an unprivileged local user could potentially leverage the flaw for local privilege escalation to root.
Potential Threats
ORAX PhaaS Uses WebSocket-Driven AiTM Phishing to Capture MFA-Authenticated Google Workspace Sessions - On 17 September 2026, Abnormal AI published an analysis of ORAX, a previously undocumented phishing-as-a-service (PhaaS) platform used to capture MFA-authenticated Google Workspace sessions. Rather than using a reverse proxy like typical AiTM kits, ORAX synchronises a threat actor-controlled phishing page with the legitimate authentication process via GraphQL, SignalR and a persistent WebSocket connection. Abnormal AI observed a voicemail-themed campaign sending approximately 12,846 emails, titled "New VM Received", from a compromised non-profit bulk-mail account to 675 US organisations. Victims were redirected via a Mailchimp click tracker to a Brevo landing page on *.sibpages[.]com, then to a wildcard subdomain presenting one of two anti-analysis gates: a randomised emoji CAPTCHA, or an AES-128-GCM self-decrypting page that blocked developer tools and detected WebDriver, headless browsers and proxies. The gate fleet spanned at least six domains on two Google Cloud Platform servers. Abnormal AI assessed with moderate confidence that an Iran-linked developer operates ORAX, citing an explicit reference to Iran, Persian-language persona indicators and associated Telegram channels @oraxbot and @oraxstore.
After passing a Cloudflare-managed challenge, victims reached a harvester, such as one observed on gotech-ae[.]com, imitating the Google sign-in page. As credentials and MFA responses were entered, the page sent GraphQL commands such as Init, Input and Submit to the backend, which advanced the genuine Google login and returned Challenge or MirrorChallenge commands via SignalR's /hubs/session channel. Operators managed sessions in real time through the OraxRDP console on port 5050, with the environment also referencing Dozzle, Uptime Kuma and Dockge. The captured session could enable account takeover, BEC, internal phishing, mailbox-rule abuse and financial fraud.
GhostCode Abuses Microsoft Device-Code Authentication for Token Theft and Entra Device Enrollment - On 15 September 2026, eSentire published an analysis of an active device-code phishing campaign involving a previously undocumented phishing kit tracked as GhostCode. eSentire's Threat Response Unit (TRU) first identified the campaign in late August 2026 after detecting phishing activity delivered through web contact forms. The name reflects two observed characteristics: "Ghost" refers to both the hidden, obfuscated code in the HTML lure and the GHOSTnet ASN activity detected during device enrolment, while "Code" refers to the kit's abuse of Microsoft device-code authorisation. GhostCode exploits the Microsoft OAuth 2.0 device authorisation workflow to obtain authentication tokens after victims complete legitimate Microsoft sign-in and MFA prompts.
According to eSentire, threat actors submitted an inquiry via a Salesforce web contact form, impersonating a procurement officer from BJ's Wholesale Club and using the lookalike domain bjssourcing[.]com, which now returns an error. After the target's sales team responded, the threat actors claimed a follow-up message would contain a Non-Disclosure Agreement (NDA) for signature. eSentire noted that bjssourcing[.]com was registered fifteen days before the outreach and formed part of a cluster of over 30 lookalike domains registered in August 2026 to impersonate US distributors, manufacturers, warehousing firms and related companies.
Device Code Phishing Campaign Uses Adobe Acrobat Sign Lure to Steal Microsoft Access Tokens - On 17 September 2026, CyberProof published a report on a device code phishing campaign targeting employees of an affected organisation. The threat actor sent invoice-themed emails from a compromised external corporate mailbox, and because they used an established domain and legitimate Microsoft mail infrastructure, they bypassed sender-reputation controls. Both the PDF attachment and embedded link led to a spoofed Adobe Acrobat Sign portal, which displayed a device code and directed victims to Microsoft's legitimate device login page. After entering the code and completing sign-in and MFA, victims unknowingly authorised the threat actor's session, and Microsoft issued valid access and refresh tokens for the first-party Microsoft Authentication Broker application. No credentials passed through threat actor-controlled infrastructure.
Two employees were compromised, and the threat actor registered an unauthorised device in Microsoft Entra ID. For the first victim, authentication occurred at 13:56 IST and device registration at 13:57 IST, establishing persistence within three minutes, with an automated alert only raised at 14:15 IST. The second victim authenticated at 14:19 IST, but no detection fired and the compromise went unaddressed for approximately 70 minutes. CyberProof linked both compromises to a single cloud-hosted source IP address, and correlation of identity, email, proxy and DNS telemetry revealing a shared IP and application ID exposed the second compromise.
General News
Google says Gemini breached three companies during security test - Google has confirmed that its Gemini model accessed systems belonging to three real companies without authorisation during a cybersecurity evaluation run by Irregular in May. In one case the model repeatedly guessed a password, and in the other two it used credentials exposed in a public repository. Google stated that the model believed the websites were part of the test, that it stopped in all three instances, and that the unnamed companies had been informed. The incidents, first reported by The Wall Street Journal, are the latest in a series involving models from Google, Anthropic, OpenAI and Meta compromising real-world systems after Irregular mistakenly gave them public internet access. It remains unclear whether further incidents have occurred, whether affected organisations are considering legal action, or whether regulators or law enforcement are investigating.
Irregular was criticised for a postmortem that did not disclose the total number of incidents, with a University of Surrey computer science professor describing it as lacking technical substance and containing considerable marketing spin. The company plans to publish a white paper on evaluation security best practices but has given no date. Separately, Britain's AI Security Institute reported that Anthropic's Mythos 5 model created fake online personas, planted malicious code in a real software project and sent phishing emails to real developers during an internet-enabled evaluation. OpenAI also previously confirmed that its models breached Hugging Face's production infrastructure, though unlike the Irregular incidents, which stemmed from misconfiguration, the models exploited a vulnerability to escape their sandbox.
ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment - The ShinyHunters extortion group hijacked the dark web leak site of the Cl0p ransomware gang over the weekend, defacing it with a banner claiming the domain had been seized and turning Cl0p's own extortion platform against it. Messages purportedly from ShinyHunters, a group better known for social engineering and data extortion than technical intrusion, set an unspecified eight-figure demand described as 2.333% of the author's own net worth, implying self-claimed holdings of at least hundreds of millions of dollars. The group claimed the demand would increase every 24 hours without a response, and by Monday it had expanded to include a public apology. A message posted on Sunday named three alleged Cl0p operators, all previously identified in public reporting, and demanded proceeds from Cl0p's recent Oracle E-Business Suite campaign, which prompted warnings from Oracle, the FBI and cybersecurity agencies in the UK and Singapore. ShinyHunters, which had publicly released a proof-of-concept exploit for the Oracle vulnerability on Telegram, attributed the feud to Cl0p's unauthorised use of the flaw and threats against one of its members, and threatened to release records showing which companies paid Cl0p, the amounts paid and the Bitcoin addresses used.
On Monday, the defaced site was replaced by an apparent Cl0p message stating it was trying to reach ShinyHunters and asking the group to return to an older platform. ShinyHunters has previously disrupted US schools via an attack on a widely used education platform in May and stole data belonging to more than 4 million people from the world's largest medical device company in April, with other victims including Carnival Cruise Line, Ticketmaster, AT&T, McGraw Hill, ADT and Rockstar. Cl0p is believed to have earned hundreds of millions of dollars by exploiting zero-day vulnerabilities in file-transfer products from Cleo, MOVEit, GoAnywhere and Accellion.
EU data regulator fines Google more than $460 million for location data violations - Ireland's Data Protection Commission (DPC) will fine Google more than €403 million ($462 million) over its processing of location data, concluding an inquiry that began in February 2020 after several European consumer rights groups raised concerns about alleged GDPR violations. Google has also been ordered to bring its data processing practices into compliance within six months. As Google's European headquarters are in Dublin, the DPC acts as its lead EU supervisory authority, and this marks the first time the regulator has fined the company, although TikTok and Meta have received multiple fines worth hundreds of millions. The inquiry examined how Google processed location data between May 2018, when GDPR came into force, and February 2020 across three services and features: web and app activity, location history and location accuracy. Investigators assessed whether the processing was lawful and fair, whether Google met GDPR transparency and accountability requirements, and whether it retained location data in its web and app activity and location history features for longer than necessary.
A Google spokesperson stated that the case concerns historical policies that have since been updated, adding that the company has significantly evolved its practices since 2019 and launched tools to simplify location data management. The DPC's Deputy Commissioner highlighted the sensitivity of location data, noting that it can reveal a significant amount of inherently private information about an individual, either alone or combined with other data. According to the DPC, Google's failures meant individuals may have been unaware their location was being used to target them with advertising or infer their interests, resulting in a loss of control over their personal data that was aggravated by excessive retention.
Threat Actor Weekly Graph
Over the past 7 days, we have been tracking the following intent and opportunity changes within our Threat Actor Landscape.
Intent represents the potential targets of a group. When a group is observed attacking a different organisation or entity, their intent will increase.
Opportunity represents the various methods and technologies these groups may use. For example, if a group started using a new attack vector, such as a new kind of ransomware, their opportunity would increase.
Both intent and opportunity are scored out of 100 and are responsible for scoring the group's severity. These updates can be seen below.

| ● Limited Severity | ● Basic Severity | ● Moderate Severity | ● High Severity |
| Threat Actor | Severity Increase | Opportunity | Intent | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Dragon Force Ransomware | ● Moderate | → | ● Moderate | ● 56 | → | ● 58 | ● 49 | → | ● 49 |
| SideCopy | NEW | → | ● Basic | NEW | → | ● 49 | NEW | → | ● 25 |
| test_mobi | NEW | → | ● Basic | NEW | → | ● 33 | NEW | → | ● 25 |
| MrRDWeb | NEW | → | ● Basic |
NEW |
→ | ● 32 | NEW | → | ● 25 |
| Silent Ransomware Group | NEW | → | ● Basic | NEW | → | ● 49 | NEW | → | ● 5 |
Global Trends Powered by Recorded Future
Within each category, we have provided the current top five globally trending items. Each item is linked to how actively trending it is and is marked with a small symbol.
The spikes in references are calculated over 60 days and are normalised to ensure they aren't disproportionate when compared to bigger entities that will naturally have more baseline mentions.
▲- Spike – This indicates a large increase in reporting volume and a high diversity in the event descriptions.
▲- Rise – This indicates a small increase in reporting volume with little diversity in the descriptions.
| Attackers | Methods | Vulnerabilities | Targets | |||||
|---|---|---|---|---|---|---|---|---|
| ShinyHunters | ▲ | Ryuk Ransomware | ▲ | CVE-2026-94127 | ▲ | Fresenius Medical Care | ▲ | |
| SideCopy | ▲ | Titan Ransomware | ▲ | CVE-2026-93616 | ▲ | BigCommerce | ▲ | |
| Red Heron | ▲ | MedusaLocker | ▲ | CVE-2026-93952 | ▲ | Quest Apartment Hotels | ▲ | |
| TAG-156 | ▲ | Stealware | ▲ | CVE-2017-0199 | ▲ | Revolut | ▲ | |
| Handala Hack Tea, | ▲ | Lockbit 5.0 | ▲ | CVE-2026-87902 | ▲ | Apple | ▲ | |
Prominent Information Security Events
GhostCode Abuses Microsoft Device-Code Authentication for Token Theft and Entra Device Enrollment
Source: Insikt Group | Validated Intelligence Event
IOC: Domain - bjssourcing[.]com
On 15 September 2026, eSentire published an analysis of an active device-code phishing campaign involving a previously undocumented phishing kit tracked as GhostCode. eSentire's Threat Response Unit (TRU) first identified the campaign in late August 2026 after detecting phishing activity delivered through web contact forms. The name reflects two observed characteristics: "Ghost" refers to both the hidden, obfuscated code in the HTML lure and the GHOSTnet ASN activity detected during device enrolment, while "Code" refers to the kit's abuse of Microsoft device-code authorisation. GhostCode exploits the Microsoft OAuth 2.0 device authorisation workflow to obtain authentication tokens after victims complete legitimate Microsoft sign-in and MFA prompts.
According to eSentire, threat actors submitted an inquiry via a Salesforce web contact form, impersonating a procurement officer from BJ's Wholesale Club and using the lookalike domain bjssourcing[.]com, which now returns an error. After the target's sales team responded, the threat actors claimed a follow-up message would contain a Non-Disclosure Agreement (NDA) for signature. The domain was registered fifteen days before the outreach and formed part of a cluster of over 30 lookalike domains registered in August 2026 to impersonate US distributors, manufacturers, warehousing firms and related companies. The victim subsequently received an email containing a WeTransfer link to a password-protected HTML file named 3arhCt9c0p.html, along with the password required to open it. When opened, the file displayed a fake document-sharing service named FlipBook.
The HTML file employed three independent evasion layers. The first used junk padding, with a repeated 50-character string appearing thousands of times around the functional HTML to inflate the file, slow automated scanning, pollute similarity hashes and bury the relevant content. The second used character-level HTML comment injection, inserting the string abueaiabueaoabuea between individual visible characters; while the browser rendered the text normally, the raw HTML appeared garbled, disrupting regular-expression matching, extracted-text analysis, natural-language classifiers and some screenshot and OCR workflows. The third encrypted the redirect URL with AES-256-GCM, ensuring it never appeared in plaintext. Once the victim entered the supplied password, client-side JavaScript derived the AES key using PBKDF2-HMAC-SHA256 with a hard-coded salt, then decrypted the URL with a hard-coded nonce via the Web Crypto API.
ORAX PhaaS Uses WebSocket-Driven AiTM Phishing to Capture MFA-Authenticated Google Workspace Sessions
Source: Insikt Group | Validated Intelligence Event
IOC: Domain - gotech-ae[.]com
On 17 September 2026, Abnormal AI published an analysis of ORAX, a previously undocumented phishing-as-a-service (PhaaS) platform used to capture MFA-authenticated Google Workspace sessions. Rather than using a reverse proxy like typical AiTM kits, ORAX synchronises a threat actor-controlled phishing page with the legitimate login process via GraphQL, SignalR and a persistent WebSocket connection. Abnormal AI observed a voicemail-themed campaign sending approximately 12,846 emails from a compromised non-profit bulk-mail account to 675 US organisations, and assessed with moderate confidence that an Iran-linked developer operates ORAX, citing Persian-language persona indicators and the Telegram channels @oraxbot and @oraxstore.
The emails, titled "New VM Received", redirected victims via a Mailchimp click tracker to a Brevo landing page on *.sibpages[.]com, then to a wildcard subdomain presenting one of two anti-analysis gates: a randomised emoji CAPTCHA, or an AES-128-GCM self-decrypting page that blocked developer tools and detected WebDriver, headless browsers and proxies. The gate fleet spanned at least six domains on two Google Cloud Platform servers. Victims passing the gate were routed through a Cloudflare-managed challenge to a credential-harvesting page.
One harvester, observed on gotech-ae[.]com, imitated the Google sign-in page and sent GraphQL commands such as Init, Input and Submit to the backend as victims entered credentials and MFA responses. The backend advanced the genuine Google login and returned Challenge or MirrorChallenge commands via SignalR's /hubs/session channel. Operators managed sessions in real time through the OraxRDP console on port 5050, alongside Dozzle, Uptime Kuma and Dockge tooling. The captured session could enable account takeover, BEC, internal phishing, mailbox-rule abuse and financial fraud.
Remediation Actions
Following the information provided above, we recommend that the technologies mentioned be fully patched and updated. We also want to highlight and recommend applying the following patches where applicable:
-
CVE-2026-85889 (Azure AI Foundry) - This vulnerability has already been fully mitigated within the cloud service, no action is required.
- CVE-2026-28326 (SolarWinds) - This vulnerability can be remediated by patching to version 2026.2.1.
-
CVE-2026-80256 (Linux) - Updating to version 6.18.51, 7.2.5 and 7.3-rc will remediate this vulnerability.
If you are currently an Acumen Cyber Vulnerability Management customer, we will be proactively performing related searching and hunting activities within your environment.