The first half of September was defined less by ransomware disruption than by an unusually heavy vulnerability window and a fresh malware set. The Gentlemen retook the ransomware lead, mid-market victims expanded, and critical enterprise flaws—including exploited Microsoft Windows and Chromium V8 zero-days—raised patching pressure as actors paired identity-driven access with newer cross-platform and remote-control tooling.
Report Links
Download Threat Brief For September 1-15 2026
Ransomware Actors
| Ransomware | Percentage | Notes |
|---|---|---|
| The Gentlemen | 13.99% | Returned to first place |
| Qilin | 8.91% | Eased from 17.71% |
| Krybit | 7.12% | Returned to the top five |
| SAFEPAY | 5.09% | Rebounded from #46 |
| Akira | 4.58% | Returned to the top five |
The Gentlemen moved back into first as Qilin declined from 17.71% to 8.91%. Krybit and Akira returned to the top five, while SAFEPAY’s jump from #46 is better read as a rebound for a group that regularly circulates in the top 15. Overall, the movement looks like the usual rotation in ransomware activity rather than a structural shift.
Victim Sector
| Sector | Percentage |
|---|---|
| Manufacturing | 15.78% |
| Technology | 15.01% |
| Retail | 13.99% |
| Financial Services | 10.69% |
| Construction | 10.18% |
Victim Location
| Location | Percentage |
|---|---|
| USA | 41.22% |
| India | 5.34% |
| Canada | 4.83% |
| Brazil | 2.54% |
| Spain | 3.05% |
The United States remained the leading victim location, while India and Brazil underscore the broader geographic spread of observed activity.
Victim Organization Size
| Organization size | Percentage |
|---|---|
| Small Business (500 or less) | 71.50% |
| Mid-Market (501-5000) | 23.58% |
| Large Enterprise (5000+) | 4.92% |
Mid-market organizations expanded to nearly one quarter of observed victims, making them an increasingly important focus for defensive planning.
Trending Adversaries
- BREEZE COMET
- Cordial Spider
- Gambling Goblin
- Mirage Kitten
- Springs / Spring Ring
- UAC-0099
BREEZE COMET and Gambling Goblin reflect financially motivated operations, from manipulating Brazilian payment systems to hijacking government sites for gambling traffic. Cordial Spider and Springs lean on vishing and trusted SSO or collaboration workflows, while Mirage Kitten expands cross-platform espionage with NodeRabbit and PollCat. UAC-0099 has experimented with prompt injection to hinder AI-assisted analysis. The mix is evenly split between newer and established actors, but identity abuse and novel tooling are the strongest common threads.
Trending & Actively Exploited Vulnerabilities
The vulnerability window was unusually crowded, with CISA adding more than 20 flaws during the period. The selected exposures focus on enterprise systems across Citrix, Cisco, Adobe Commerce, Microsoft, JFrog, ConnectWise, Google Chromium, and GitLab.
| CVE | Vendor | Product |
|---|---|---|
| CVE-2026-19490 | Citrix | NetScaler |
| CVE-2026-20079 | Cisco | Secure Firewall Management Center and Security Cloud Control |
| CVE-2026-75650 | Adobe | Commerce and Magento |
| CVE-2026-81963 | Microsoft | Windows |
| CVE-2026-82329 | JFrog | Artifactory |
| CVE-2026-84869 | ConnectWise | ScreenConnect |
| CVE-2026-85046 | Chromium V8 | |
| CVE-2026-85706 | GitLab | Community Edition and Enterprise Edition |
| CVE-2026-85880 | Microsoft | Windows |
| CVE-2026-87491 | Chromium V8 |
Prioritize internet-facing management systems first, then accelerate browser and endpoint patching where exploitation can reach users quickly.
Trending Malware
| Malware | Details |
|---|---|
| BambooToken | Multi-platform espionage malware that uses MQTT and DLL sideloading to quietly control and profile Windows and Linux hosts. |
| PollCat | Cross-platform RAT paired with NodeRabbit, using obfuscated JavaScript and HTTP C2 to execute commands, move files, and maintain stealthy persistence. |
| Cyclops Blink | A modular botnet and backdoor upgraded for modern Linux appliances and used by Sandworm-linked actors for deep network visibility. |
| REVSTEALER | Feature-rich infostealer combining anti-analysis, wallet and credential theft, gaming-account targeting, and Polygon-based fallback C2. |
| NodeRabbit | Cross-platform JavaScript RAT delivered via trojanized coding challenges, giving attackers persistent remote control and file/system access. |
| VectraRAT | Malware-as-a-service remote access trojan offering turnkey control, data theft, and flexible modules to subscribing threat actors. |
Top News
- A ClickFix campaign compromised 31 organizations and abused the Polygon blockchain.
- Old, unpatched flaws gave attackers access to a Philippines nuclear agency.
- US authorities charged a Russian national with infecting 80,000 freelancers with malware.
- Two exploited zero-days and 113 critical vulnerabilities appeared among 972 September CVEs.
- Japan’s digital agency said a VPN flaw exposed 246,000 personnel records.
- Hackers abused Claude to extract secrets from 1.8 million Android apps.
- China-based AI companies targeted US models with industrial-scale knowledge distillation.
- A threat actor generated one million personalized fraud emails in three days.
Contributors
Written by Jeremy Nichols, Director, Security Programs & Strategy at SecureSky
Executive Summaries & Adversary Bios by Geoff Rehmet, Cybersecurity Expert
Produced & Distributed By Byer Co Cybersecurity Marketing Division (aka Phish Tank Digital)