Late September reinforced how quickly threats are converging around trusted access. The Gentlemen and Qilin led ransomware activity, INC Ransom gained ground, and espionage groups leaned on identities, supply chains, and exposed services. AI-assisted cloud attacks added a new wrinkle, while exploited SharePoint, NetScaler, Check Point, Cisco, and F5 flaws made rapid patching, identity security, and post-compromise hunting key priorities.

Report Links

Download Threat Brief For September 16-30 2026

Byer-Nichols Threat Brief Podcast September 16-30 2026

Top Ransomware

Ransomware Percentage
The Gentlemen 10.68%
Qilin 8.50%
INC Ransom 6.32%
STORM 4.58%
Akira 3.92%

The Gentlemen held first place at 10.68%, with Qilin close behind. Both continued their sustained dominance of victim disclosures. INC Ransom was the biggest mover, jumping from ninth to third, while STORM rose to fourth and Akira held fifth. Newer crews are gaining ground, but Akira continues to pose a concern through double extortion and VPN-driven access.

Victim Sector

Sector Percentage
Technology 17.21%
Financial Services 12.85%
Retail 12.20%
Manufacturing 11.98%
Construction 11.76%

Victim Location

Location Percentage
USA 40.09%
Brazil 3.05%
France 3.70%
Germany 3.49%
Canada 2.83%

Victim Organization Size

Organization size Percentage
Small Business (500 or less) 74.44%
Mid-Market (501-5000) 18.39%
Large Enterprise (5000+) 7.17%

Trending Adversaries

  • FamousSparrow
  • JadePuffer
  • NightEagle
  • Star Blizzard
  • Storm-3069
  • WaterPlum

FamousSparrow expanded Latin American government espionage with SparroWocky, NightEagle broadened into Russian targets, and Star Blizzard streamlined phishing through RedFlick. JadePuffer pushed automation furthest with agentic ransomware, while Storm-3069 used NeedyMantis for persistent access. WaterPlum's fake-interview campaign reached at least 30,000 devices. The common thread is faster, more durable compromise through automation and trusted workflows.

Trending & Actively Exploited Vulnerabilities

CVE Vendor Product
CVE-2026-65660 Microsoft SharePoint
CVE-2026-71362 Adobe Commerce and Magento
CVE-2026-76460 Cisco Identity Services Engine
CVE-2026-76504 Cisco Catalyst SD-WAN Manager
CVE-2026-85102 Check Point Multiple Products
CVE-2026-86950 Apple Multiple Products
CVE-2026-88771 Citrix NetScaler
CVE-2026-88772 Citrix NetScaler
CVE-2026-93616 Check Point Multiple Products
CVE-2026-94127 F5 BIG-IP APM

This period's selected vulnerabilities concentrate on enterprise collaboration, commerce, identity, network management, and edge infrastructure. Internet-facing management planes should lead the patch queue, especially where authentication bypass or active exploitation can turn one exposed appliance into broader network access.

Trending Malware

Malware Details
Carbonato Compromises exposed Docker hosts and combines worm-like propagation with a Telegram-controlled AI agent that prioritizes credential theft.
NeedyMantis Modular post-compromise malware framework built to maintain long-term, covert access to selected Windows environments.
PAYLOAD Abuses Active Directory Group Policy to cause domain-wide disruption and support extortion, potentially without deploying Windows ransomware binaries.
Rapuncel Windows infostealer using fake software downloads and a signed kernel driver to disable security products before stealing credentials and data.
RatHat Android banking trojan combining Accessibility and ADB abuse with AI-assisted automation to steal credentials and remotely control compromised devices.
SparroWocky Stealthy modular Windows backdoor giving cyberespionage operators extensive remote control, surveillance, and data theft.

Top News

  • Brevo supply-chain attack injected ClickFix scripts on customer sites.
  • Gyazo server flaw was exploited to steal 23.6 million user records.
  • Microsoft disrupted the EvilTokens phishing service targeting device-code authentication.
  • Nightmare Eclipse defender zero-day blocked Microsoft antivirus updates.
  • A new Settra ransomware variant deployed MeshAgent RMM.
  • Russian state hackers used the RedFlick technique to push malware.
  • Salesbleed abused Salesforce agents for Slack phishing.
  • ShinyHunters hacked the Clop leak site and threatened to extort The Gang.

Contributors

Written by Jeremy Nichols, Director, Security Programs & Strategy at SecureSky
Executive Summaries & Adversary Bios by Geoff Rehmet, Cybersecurity Expert
Produced & Distributed By Byer Co Cybersecurity Marketing Division (aka Phish Tank Digital)