Threadlinqs Intelligence — Real-Time Threat Detection Platform
Threadlinqs Intelligence is a free, public cyber-threat-intelligence platform for security operations, detection engineering and threat-hunting teams. Every entry is a profiled real-world threat: what the adversary did, which MITRE ATT&CK techniques it maps to, which CVEs it exploited, which indicators it left behind, and the detection rules that catch it. It currently profiles 2,568 threats, each carrying deployable detection logic — 23,551 rules in Splunk SPL, Microsoft KQL and Sigma — alongside 64,585 extracted indicators of compromise, 734 attributed threat actors and 849 distinct MITRE ATT&CK and ATLAS techniques. The corpus is updated daily. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Data as of .
Explore
- Daily threat intelligence debrief — every threat added or updated in the last 24 hours, with detection and ATT&CK coverage.
- Platform statistics — corpus size, severity and category composition, technique and actor coverage.
- MITRE ATT&CK coverage map — techniques and threats per tactic across the Enterprise, ICS and ATLAS matrices.
- Live CVE intelligence feed — enriched CVEs ranked by CVSS, EPSS exploitation probability, CISA KEV status and public exploit availability.
- MCP server for AI agents — Model Context Protocol access to the same corpus from Claude, Cursor or any MCP client.
Recent threat intelligence
- Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions (HideExclusionsFromLocalAdmins) to Evade MDAV — MEDIUM, added
- ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing — MEDIUM, added
- Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scans — HIGH, added
- Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor) — CRITICAL, added
- Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic Redirection — MEDIUM, added
- Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild — CRITICAL, added
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm — HIGH, added
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027 — CRITICAL, added
- CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust) — CRITICAL, added
- WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131) — CRITICAL, added
- Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files — HIGH, added
- Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP) — HIGH, added
- Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote Code Execution — CRITICAL, added
- Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331) — CRITICAL, added
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations — HIGH, added
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer — HIGH, added
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors — HIGH, added
- Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles — MEDIUM, added
- Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses (CVE-2026-64507, CVE-2026-64508) — HIGH, added
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine — HIGH, added
- Agentic AI used for post-exploitation in breach of the Dutch Institute for Vulnerability Disclosure (DIVD) — HIGH, added
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations — MEDIUM, added
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access — HIGH, added
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse) — HIGH, added
- CVE-2026-50610: Acer System Monitor (NitroSense/PredatorSense) local privilege escalation from standard user to SYSTEM via unauthenticated named pipe registry write — HIGH, added
- PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled Groups/Channels — MEDIUM, added
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling — HIGH, added
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification — HIGH, added
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses — HIGH, added
- Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials (Wiz Blue Agent Investigation) — CRITICAL, added
From the blog
- Anthropic AI Misuse Report (Sept 2026) Mapped
- Signal Hijacking: QR Phishing, APT44 WAVESIGN
- TLQL: Threadlinqs Query Language Reference
- TeamPCP: From LiteLLM to Vect Ransomware
- OS.ai: The Agentic OS Manager for Threat Intel
Browse every threat, CVE and actor page. Machine-readable overview: /llms.txt.
Threadlinqs Intelligence — Real-Time Threat Detection Platform
Live intelligence console
Threat weather, live.
Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.
Every threat in the corpus, newest first.