Threadlinqs Intelligence — Real-Time Threat Detection Platform

Threadlinqs Intelligence is a free, public cyber-threat-intelligence platform for security operations, detection engineering and threat-hunting teams. Every entry is a profiled real-world threat: what the adversary did, which MITRE ATT&CK techniques it maps to, which CVEs it exploited, which indicators it left behind, and the detection rules that catch it. It currently profiles 2,568 threats, each carrying deployable detection logic — 23,551 rules in Splunk SPL, Microsoft KQL and Sigma — alongside 64,585 extracted indicators of compromise, 734 attributed threat actors and 849 distinct MITRE ATT&CK and ATLAS techniques. The corpus is updated daily. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Data as of .

Explore

Recent threat intelligence

  1. Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions (HideExclusionsFromLocalAdmins) to Evade MDAV — MEDIUM, added
  2. ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing — MEDIUM, added
  3. Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scans — HIGH, added
  4. Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor) — CRITICAL, added
  5. Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic Redirection — MEDIUM, added
  6. Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild — CRITICAL, added
  7. 2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm — HIGH, added
  8. GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027 — CRITICAL, added
  9. CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust) — CRITICAL, added
  10. WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131) — CRITICAL, added
  11. Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files — HIGH, added
  12. Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP) — HIGH, added
  13. Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote Code Execution — CRITICAL, added
  14. Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331) — CRITICAL, added
  15. CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations — HIGH, added
  16. MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer — HIGH, added
  17. AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors — HIGH, added
  18. Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles — MEDIUM, added
  19. Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses (CVE-2026-64507, CVE-2026-64508) — HIGH, added
  20. Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine — HIGH, added
  21. Agentic AI used for post-exploitation in breach of the Dutch Institute for Vulnerability Disclosure (DIVD) — HIGH, added
  22. Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations — MEDIUM, added
  23. Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access — HIGH, added
  24. Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse) — HIGH, added
  25. CVE-2026-50610: Acer System Monitor (NitroSense/PredatorSense) local privilege escalation from standard user to SYSTEM via unauthenticated named pipe registry write — HIGH, added
  26. PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled Groups/Channels — MEDIUM, added
  27. North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling — HIGH, added
  28. AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification — HIGH, added
  29. SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses — HIGH, added
  30. Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials (Wiz Blue Agent Investigation) — CRITICAL, added

From the blog

Browse every threat, CVE and actor page. Machine-readable overview: /llms.txt.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats