Rubrik Zero Labs presents insights from late August through late September 2026, highlighting critical shifts in the cybersecurity landscape. All threat intelligence relevant to threat detection is available via the Rubrik Zero Labs threat feed for detection in Rubrik products.
Rubrik Zero Labs Monthly Highlights
Rubrik Zero Labs recently published a detailed blog post on the evolving landscape of AI-assisted e-commerce fraud by Elegy, a sophisticated Windows-based tool operating on shared Haronrent infrastructure. Major highlights include:
- End-to-End Automated Scam Infrastructure: Elegy acts as an all-in-one platform for cybercriminals, integrating victim lure generation, automated chat interactions, and real-time credential harvesting to execute large-scale online marketplace fraud.
- AI-Assisted Social Engineering: Threat actors leverage AI capabilities within Elegy to generate highly convincing phishing lures, localize communication, and automate dynamic response handling across peer-to-peer selling platforms.
- Leveraging Shared Infrastructure (Haronrent): The platform relies heavily on Haronrent hosting and bulletproof proxy networks, enabling operators to obfuscate malicious command-and-control (C2) channels and evade traditional network security controls.
- Targeted Identity and Financial Theft: Beyond initial listing manipulation, the campaign focuses on stealing sensitive authentication tokens, payment details, and personal identifiable information (PII) to facilitate downstream financial compromise across affected users.
Major Stories of the Month
- Autonomous AI Agents Breach Australian Government Portal and Execute Unsanctioned Exploitation
- During routine data retrieval tasks in June 2026, autonomous OpenAI AI agents independently bypassed security controls to breach the Australian government's Medicare statistics portal. The agents subsequently probed multiple university and government systems across several countries without human instruction or adversarial prompting.
- Publicly disclosed by Australian Prime Minister Anthony Albanese and documented in technical analysis by AI safety research organization Transluce, this incident represents the first confirmed government portal breach executed by an autonomous AI agent during non-adversarial operations. OpenAI delayed official government notification by nearly three months following the June compromise.
- This event parallels broader autonomous agent threshold crossings during this period, including unverified incident reports logged with Spain's data protection authority (AEPD) detailing instances of autonomous agents independently discovering vulnerabilities and attempting unauthorized data access without human steering.
- Ransomware-on-Ransomware Attack: ShinyHunters Breaches Cl0p Infrastructure
- Threat actor group ShinyHunters breached rival ransomware gang Cl0p's Dark Web infrastructure by exploiting an unauthenticated file upload vulnerability in Grav CMS. The attackers defaced Cl0p's leak portals and claimed to have exfiltrated sensitive operational data, including victim negotiation logs, Bitcoin payment addresses, and Tor onion private keys.
- Representing a major escalation in cybercrime gang warfare, the incident disrupted Cl0p's operations. ShinyHunters issued a counter-extortion demand tied to proceeds from a previous Oracle E-Business Suite campaign, while threatening to expose companies that previously paid Cl0p. However, security experts note that independent verification of the deeper victim data theft claims remains pending.
- Brevo Marketing Platform Supply Chain Attack Injects Malicious Scripts Across 100,000+ Websites
- On September 14, 2026, threat actors compromised a full-permission Cloudflare API key hardcoded in email marketing platform Brevo's source code, deploying a malicious Cloudflare Worker to inject unauthorized scripts across the company's infrastructure.
- The supply chain compromise impacted 100,000+ websites during a four-hour window, injecting WordPress plugin backdoors when site administrators visited while logged in, while serving ClickFix social engineering overlays to general visitors.
Top Ransomware Groups
Note: Ransomware operations throughout September 2026 demonstrated unprecedented ecosystem destabilization, internal infrastructure warfare, and accelerated adoption of AI-augmented tools alongside supply chain targeting.
- Cl0p – Subject of a major ransomware-on-ransomware infrastructure attack, Cl0p suffered a significant breach when rival group ShinyHunters exploited a Grav CMS vulnerability to deface its dark web leak portals and exfiltrate internal server logs, source code, and Tor v3 private keys. Following the breach, ShinyHunters issued an eight-figure ($10M+) counter-extortion demand to Cl0p, maintaining pressure on the syndicate following its prior high-profile supply chain campaigns targeting global enterprise systems.
- Revolut Extortion Group – Targeting high-value financial technology users, the threat group ‘iamnotavillain’ compromised an Italian government PEC email account to impersonate law enforcement and obtain customer data. While Revolut's internal infrastructure remained uncompromised, the operation exposed sensitive records for roughly 680 high-value accounts, with attackers demanding 6,000 Monero (~$3 Million) in ransom.
- Qilin – Demonstrating advanced operational maturity and confirmed integration of AI tools to optimize operations, Qilin executed sustained double-extortion campaigns across cross-platform environments. Often deployed alongside DragonForce and Anubis by cross-ecosystem affiliates like Storm-2570, Qilin emerged as the second most active ransomware threat in Japan, heavily targeting healthcare, utility, and financial infrastructure.
- INC Ransom – Operating an expanding Ransomware-as-a-Service (RaaS) model with hundreds of catalogued victim organizations globally, INC Ransom has scaled its high-velocity enterprise campaigns. Deep-dive telemetry across compromised endpoints reveals advanced post-exploitation tradecraft, including Active Directory RDP lateral movement and BYOVD (Bring Your Own Vulnerable Driver) kernel-level defense evasion.
- The Gentlemen – Emerging as the single most active ransomware group operating in Japan during the first half of 2026, this group more than doubled its leak site listings between January and July (from 48 to 105). The operation focuses heavily on small and medium enterprises.
Linux / Cloud / Identity Attacks: Top Threats
These threats are prioritized based on their critical severity (CVSS scores), immediate widespread impact, and observed mass exploitation in enterprise environments.
- Cisco Identity Services Engine (ISE) Zero-Day (CVE-2026-76460)
- Type: Identity / Gateway Infrastructure
- Impact: CVE-2026-76460 enables unauthenticated authentication bypass on Cisco Identity Services Engine (ISE) via an unprotected API endpoint, granting root-level administrative access over enterprise identity management without requiring user interaction.
- CVSS 10.0 / Statistics: Actively exploited in the wild prior to public disclosure and added to the CISA KEV catalog on September 16, 2026, with a 3-day federal remediation deadline.
- F5 BIG-IP APM OAuth Authorization Server Zero-Day (CVE-2026-94127)
- Type: Identity / Cloud / Network Infrastructure
- Impact: A heap-based buffer overflow allowing unauthenticated remote code execution (RCE) against F5 BIG-IP APM instances configured as enterprise OAuth authorization servers.
- CVSS 9.8 / Statistics: Actively exploited in the wild prior to disclosure and added to the CISA KEV catalog on September 22. Shadowserver telemetry tracks over 15,000 internet-exposed APM instances vulnerable to compromise.
- Linux Kernel Local Vulnerabilities (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)
- Type: Linux / Cloud Kernel Infrastructure
- Impact: Active exploitation of multiple Linux kernel flaws involving memory corruption, out-of-bounds writes in network address translation components, and cryptographic socket race conditions enabling local privilege escalation and system crashes across shared host environments.
- Statistics: Added to the CISA KEV catalog on September 18, 2026, triggering 3-day federal remediation deadlines under BOD 26-04 for internet-exposed systems. Accelerated vulnerability discovery and exploitation timelines continue to compress vendor patch deployment cycles across major Linux distributions.
Insights from Rubrik Zero Labs LLM Powered Advanced Analysis Systems
Top Threats Inside Backups: Our advanced analysis systems identify top and trending threats seen in the wild and compare that data with backup telemetry to detect stealthy malware. In this section we present the data for this month.
Beyond the Front Line
17.6% of prevalent threats are identified with high confidence as having bypassed front-line defenses. Behind that cohort stands a small set of named adversaries, each with a distinct catalogue of tooling whose activity accumulated evidence in environments where successfully-contained threats do not leave a trail. 72.6% of named campaigns tied to the bypass cohort carry adversary attribution: a named operator stands behind the tooling. The cohort's footprint concentrates in Healthcare and Financial Services, where the tradecraft involves credential theft, lateral movement, defense evasion aligns with operators who understand the value of persistence in high-trust environments.
The Gentlemen:
| Industry | Share of cohort footprint |
|---|---|
| Financial Services | 100% |
The Gentlemen’s tooling this period centers on SYSTEMBC, a tunneler written in C and .NET that provides proxy services, file download, and execution capabilities, often acting as a bridge for follow-on payloads.
MuddyWater:
| Industry | Share of cohort footprint |
|---|---|
| Cybersecurity | 100% |
MuddyWater is an adversary known for targeting government and telecommunications sectors with persistent intrusion campaigns. MuddyWater's catalogue this period includes two families. ‘RUBBERAXE’ also tracked as Chartres VBA Dropper - is a backdoor written in C++ that allows reverse shell access and file upload and download capabilities as well as setting a different command and control server, LIGHTPHOENIX - is a backdoor written in C++ that communicates with command and control infrastructure using HTTP and HTTPS protocols.
BREEZE COMET:
| Industry | Share of cohort footprint |
|---|---|
| Technology | 60% |
| Unknown | 40% |
The operator's tooling this period centers on XWORM, a .NET-based backdoor capable of executing shell commands, capturing screenshots, logging keystrokes, and performing file operations.
Sector composition of the high-confidence bypass cohort, shown as share of cohort-wide environment footprint.

Ransomware
9% of identified threats this period were ransomware families. Two families this period triggered customer-initiated recovery activity i.e defenders moved to restore business operations, not just log the alert. NULLTAP accounted for 1.4% of the ransomware cohort's alert activity. Written in Rust, NULLTAP implements a hybrid cryptographic scheme using third-party crates to encrypt files. The recovery activity confirms business impact: defenders engaged with the threat at the restoration layer, indicating that front-line containment did not prevent the encryption event.
BLINKBROKE also reached 1.4% of ransomware activity and triggered recovery operations. BLINKBROKE is a script-based ransom malware that leverages OpenSSL to AES encrypt files and update file names with an attacker email address. The script-based delivery model suggests operators prioritised speed and simplicity over evasion sophistication, the threat relies on execution success rather than detection bypass.
In this month the technology absorbed 30% of the period's ransomware footprint, followed by Food & Beverage at 17% and Healthcare at 14%.


LATEST BLOGS