Daily Digest

New Android Malware, APT Expansions, and Supply Chain Attacks Dominate Cybersecurity News

September 22, 2026
8 articles (8 new)
24 min read

Summary

Daily Cybersecurity Briefing - September 22, 2026

Emerging Threats and Sophisticated Attacks:

  • RatHat Android Malware: Security researchers have identified a new Android remote access trojan (RAT) named 'RatHat,' attributed to Chinese threat actors. This malware leverages generative AI to evade detection and steals financial data by tricking users into granting extensive accessibility permissions, enabling it to activate wireless debugging and deploy overlays for credential theft.
  • SideCopy APT Targets Academia: The Pakistan-nexus threat group SideCopy has expanded its operations to include Indian academic institutions, in addition to its previous targeting of government and military entities. A recent campaign utilizes spear-phishing emails with malicious LNK files to deliver the ReverseRAT trojan, employing techniques like reflective DLL loading and .NET deserialization for stealth.
  • 'Rapuncel' Infostealer with EDR Bypass: A new information stealer, 'Rapuncel,' is being distributed through fake GitHub repositories. Its primary threat lies in a kernel driver, 'Alinubx.sys,' signed with a valid Microsoft certificate, which disables 145 different security products, allowing it to steal credentials from browsers, cryptocurrency wallets, and applications.

Supply Chain and Infrastructure Incidents:

  • BigCommerce Data Breach: E-commerce platform BigCommerce experienced a data breach due to a compromised third-party application, 'Ribon' and 'Ribon 1.5.' Attackers used a stolen application key to access customer names, emails, phone numbers, and shipping addresses between September 13 and 17, 2026. Financial data was not affected.
  • Crypto Firm Haruko Breached: London-based crypto infrastructure provider Haruko was breached after an attacker stole an access token from memory. This allowed the attacker to capture read-only API keys and trading data for institutional clients, leading to reported fund losses for some smaller clients.
  • Elsevier Domains Hijacked: Three domains belonging to academic publisher Elsevier were temporarily hijacked on September 21, 2026, redirecting visitors to a page branded with the LAPSUS$ extortion group's name. The incident, lasting approximately 78 minutes, was likely caused by a compromised DNS or CDN configuration.

National Preparedness and Cybercrime Dynamics:

  • CISA Cyber Storm X Exercise: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) concluded Cyber Storm X, its tenth national cyber exercise. The event simulated a nation-state attack on U.S. critical infrastructure, focusing on transportation and water/wastewater sectors, to test incident response and improve coordination.
  • ShinyHunters Hijacks Clop Site: In an apparent inter-gang feud, the ShinyHunters extortion group has defaced the dark web data leak site of the Clop ransomware gang. ShinyHunters claims this action is retaliation for alleged theft of an Oracle zero-day exploit and has threatened to release Clop's victim data.

Filter by Category

New Articles (8)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.