Late September reinforced how quickly threats are converging around trusted access. The Gentlemen and Qilin led ransomware activity, INC Ransom gained ground, and espionage groups leaned on identities, supply chains, and exposed services. AI-assisted cloud attacks added a new wrinkle, while exploited SharePoint, NetScaler, Check Point, Cisco, and F5 flaws made rapid patching, identity security, and post-compromise hunting key priorities.
Report Links
Download Threat Brief For September 16-30 2026
Byer-Nichols Threat Brief Podcast September 16-30 2026
Top Ransomware
| Ransomware | Percentage |
|---|---|
| The Gentlemen | 10.68% |
| Qilin | 8.50% |
| INC Ransom | 6.32% |
| STORM | 4.58% |
| Akira | 3.92% |
The Gentlemen held first place at 10.68%, with Qilin close behind. Both continued their sustained dominance of victim disclosures. INC Ransom was the biggest mover, jumping from ninth to third, while STORM rose to fourth and Akira held fifth. Newer crews are gaining ground, but Akira continues to pose a concern through double extortion and VPN-driven access.
Victim Sector
| Sector | Percentage |
|---|---|
| Technology | 17.21% |
| Financial Services | 12.85% |
| Retail | 12.20% |
| Manufacturing | 11.98% |
| Construction | 11.76% |
Victim Location
| Location | Percentage |
|---|---|
| USA | 40.09% |
| Brazil | 3.05% |
| France | 3.70% |
| Germany | 3.49% |
| Canada | 2.83% |
Victim Organization Size
| Organization size | Percentage |
|---|---|
| Small Business (500 or less) | 74.44% |
| Mid-Market (501-5000) | 18.39% |
| Large Enterprise (5000+) | 7.17% |
Trending Adversaries
- FamousSparrow
- JadePuffer
- NightEagle
- Star Blizzard
- Storm-3069
- WaterPlum
FamousSparrow expanded Latin American government espionage with SparroWocky, NightEagle broadened into Russian targets, and Star Blizzard streamlined phishing through RedFlick. JadePuffer pushed automation furthest with agentic ransomware, while Storm-3069 used NeedyMantis for persistent access. WaterPlum's fake-interview campaign reached at least 30,000 devices. The common thread is faster, more durable compromise through automation and trusted workflows.
Trending & Actively Exploited Vulnerabilities
| CVE | Vendor | Product |
|---|---|---|
| CVE-2026-65660 | Microsoft | SharePoint |
| CVE-2026-71362 | Adobe | Commerce and Magento |
| CVE-2026-76460 | Cisco | Identity Services Engine |
| CVE-2026-76504 | Cisco | Catalyst SD-WAN Manager |
| CVE-2026-85102 | Check Point | Multiple Products |
| CVE-2026-86950 | Apple | Multiple Products |
| CVE-2026-88771 | Citrix | NetScaler |
| CVE-2026-88772 | Citrix | NetScaler |
| CVE-2026-93616 | Check Point | Multiple Products |
| CVE-2026-94127 | F5 | BIG-IP APM |
This period's selected vulnerabilities concentrate on enterprise collaboration, commerce, identity, network management, and edge infrastructure. Internet-facing management planes should lead the patch queue, especially where authentication bypass or active exploitation can turn one exposed appliance into broader network access.
Trending Malware
| Malware | Details |
|---|---|
| Carbonato | Compromises exposed Docker hosts and combines worm-like propagation with a Telegram-controlled AI agent that prioritizes credential theft. |
| NeedyMantis | Modular post-compromise malware framework built to maintain long-term, covert access to selected Windows environments. |
| PAYLOAD | Abuses Active Directory Group Policy to cause domain-wide disruption and support extortion, potentially without deploying Windows ransomware binaries. |
| Rapuncel | Windows infostealer using fake software downloads and a signed kernel driver to disable security products before stealing credentials and data. |
| RatHat | Android banking trojan combining Accessibility and ADB abuse with AI-assisted automation to steal credentials and remotely control compromised devices. |
| SparroWocky | Stealthy modular Windows backdoor giving cyberespionage operators extensive remote control, surveillance, and data theft. |
Top News
- Brevo supply-chain attack injected ClickFix scripts on customer sites.
- Gyazo server flaw was exploited to steal 23.6 million user records.
- Microsoft disrupted the EvilTokens phishing service targeting device-code authentication.
- Nightmare Eclipse defender zero-day blocked Microsoft antivirus updates.
- A new Settra ransomware variant deployed MeshAgent RMM.
- Russian state hackers used the RedFlick technique to push malware.
- Salesbleed abused Salesforce agents for Slack phishing.
- ShinyHunters hacked the Clop leak site and threatened to extort The Gang.
Contributors
Written by Jeremy Nichols, Director, Security Programs & Strategy at SecureSky
Executive Summaries & Adversary Bios by Geoff Rehmet, Cybersecurity Expert
Produced & Distributed By Byer Co Cybersecurity Marketing Division (aka Phish Tank Digital)