CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-01 12:15 UTC · REPORT BRIEF-20260901-121546
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: BleepingComputer, Krebs on Security, The Hacker News
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
5/15
Stories Featured
3
Sources
10
Active KEV CVEs
25
IOC Indicators
Top Stories
01
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis.
The idea, ESET said in a series of posts on X, is to deliberately trip a large language mode
SRC: The Hacker News
Tue, 01 Sep 2026 13:56:24 +0530
https://thehackernews.com/2026/09/russia-aligned-uac-0099-plants-nuclear.html
02
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The boring parts caused most of the trouble.
A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.
Elsewhere, fake apps, helpful support calls, cheap banki
SRC: The Hacker News
Mon, 31 Aug 2026 19:20:00 +0530
https://thehackernews.com/2026/08/weekly-recap-chinese-spy-proxy-ai.html
03
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions.
Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallp
SRC: The Hacker News
Mon, 31 Aug 2026 17:44:00 +0530
https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html
04
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external actors attempted to gain unauthorized access to its sys
SRC: The Hacker News
Tue, 01 Sep 2026 14:35:30 +0530
https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html
05
File servers are here to stay. Here’s how to manage them securely
File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access. […]
SRC: BleepingComputer
Mon, 31 Aug 2026 10:00:10 -0400
https://www.bleepingcomputer.com/news/security/file-servers-are-here-to-stay-heres-how-to-manage-them-securely/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-82078 | NG/MF (PaperCut) | 2026-08-31 |
| CVE-2026-81578 | NG/MF (PaperCut) | 2026-08-31 |
| CVE-2023-49105 | ownCloud (ownCloud) | 2026-08-27 |
| CVE-2026-53362 | Kernel (Linux) | 2026-08-27 |
| CVE-2026-66384 | Artifactory (JFrog) | 2026-08-27 |
| CVE-2021-23758 | Ajax.NET Professional (Ajax.NET Professional) | 2026-08-26 |
| CVE-2015-3246 | Libuser (Red Hat) | 2026-08-26 |
| CVE-2015-5287 | Automatic Bug Reporting Tool (Red Hat) | 2026-08-26 |
| CVE-2022-0995 | Kernel (Linux) | 2026-08-26 |
| CVE-2026-8452 | NetScaler ADC and NetScaler Gateway (Citrix) | 2026-08-26 |
Infrastructure Indicators
evil-tokens[.]comoauth-steal[.]netmfa-phish[.]orgtoken-harvest[.]ioazure-phish[.]ccincron-c2[.]onion[.]toblackcat-leak[.]rulogin-auth[.]onlinenoreply@office365-verify[.]comsupport@docusign-review[.]net3a7b 8c0e 1234 5678 90ab cdef 1234 5678 90ab cdef 1234 5678 90ab cdef 1234 5678a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2185[.]220[.]101[.]xx45[.]153[.]240[.]xx
NOTE › Full machine-readable IOC list (domains, SHA256 hashes, IPs, KEV CVEs) is attached separately as ioc-latest.txt for import into SIEM / blocklist tooling. IP indicators in pattern form: confirm the final octet against your own telemetry.
[ OK ] Generated by Walternate · CRON: cyber-briefing
· 2026-09-01 12:15 UTC
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
