Threadlinqs Intelligence — Real-Time Threat Detection Platform

Threadlinqs Intelligence is a free, public cyber-threat-intelligence platform for security operations, detection engineering and threat-hunting teams. Every entry is a profiled real-world threat: what the adversary did, which MITRE ATT&CK techniques it maps to, which CVEs it exploited, which indicators it left behind, and the detection rules that catch it. It currently profiles 2,741 threats, each carrying deployable detection logic — 25,108 rules in Splunk SPL, Microsoft KQL and Sigma — alongside 68,432 extracted indicators of compromise, 661 attributed threat actors and 856 distinct MITRE ATT&CK and ATLAS techniques. The corpus is updated daily. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Data as of .

Explore

Recent threat intelligence

  1. Android October 2026 Security Bulletin - 25 Vulnerabilities Patched in Framework and System (Patch Level 2026-10-01) — HIGH, added
  2. Chrome 155 Update Patches 247 Vulnerabilities Including 4 Critical Use-After-Free Flaws (CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, CVE-2026-106347) — CRITICAL, added
  3. Rockstar Games Breaches: Lapsus$ Source Code Theft, ShinyHunters Anodot/Snowflake OAuth Data Theft (78.6M Records), and Cyberleek Fake GTA VI Build Malware — HIGH, added
  4. Anthropic Disables Live Internet Access for Internal AI Evaluations After Claude Models Exploit Injection Flaws and Submit Unauthorized Forms — MEDIUM, added
  5. DeKalb County, Indiana Vendor Impersonation Email Payment Fraud (Oct 2026) — MEDIUM, added
  6. Advantest Discloses Data Breach Months After February 2026 Ransomware Attack — MEDIUM, added
  7. Progress DataDirect GenAI Command Injection via OpenAPI/Swagger Filename (CVE-2026-91140) — CRITICAL, added
  8. DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2 to Deploy RuntimeBroker Backdoor Against Government Targets — HIGH, added
  9. AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch Endpoint to GodPotato/PrintSpoofer SYSTEM Escalation on Windows — HIGH, added
  10. Attackers Hide AI Prompt Injections Inside Phishing Emails to Manipulate AI Email Assistants — MEDIUM, added
  11. Deepfake scam operating inside a larger multi-stage fraud campaign (Bolster AI analysis) — MEDIUM, added
  12. Sonatype Q3 2026 Open Source Malware Index: Compounding Supply-Chain Compromise (Mini Shai-Hulud npm wave, mlflow-ui PyPI AI-agent-uploaded malware) — HIGH, added
  13. ChainDrop npm Worm and PolinRider DPRK-Linked Operation Use Blockchain C2 to Steal Cloud and CI/CD Credentials — HIGH, added
  14. Critical Cisco Nexus 3000/9000 NX-OS NGOAM Stack Buffer Overflows Allow Unauthenticated Root Code Execution (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501) — CRITICAL, added
  15. Malware Embedding Prompt-Injection Text to Evade AI-Based Analysis (FRUITSHELL, PLOTSAFE, HOLLOWCLAD, MANTLEMAZE, ROZESHELL) — MEDIUM, added
  16. UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing — HIGH, added
  17. IBM and Red Hat fix 400+ previously unknown Java library vulnerabilities via Lightwell — MEDIUM, added
  18. CVE-2025-64393: Critical Veeam Backup & Replication RCE via Mount Service Insecure Deserialization — CRITICAL, added
  19. Active Exploitation of Citrix NetScaler ADC and Gateway Zero-Days (CVE-2026-88771, CVE-2026-88772) with WHIPSHOT/SLAPSHOT Post-Exploitation — CRITICAL, added
  20. BlossCraft Launcher: Electron-Based Information Stealer Masquerading as Game Launcher — MEDIUM, added
  21. Akira Ransomware Attack Mapped by Huntress: RDP Initial Access, GOST Tunneling, Rclone Exfiltration — HIGH, added
  22. BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046 and CVE-2026-87491 with Windows Kernel LPE CVE-2026-85880 — CRITICAL, added
  23. GuidePoint GRIT Q3 2026 Ransomware Report: Record 2,760 Victims, New Top Group Edges Out Qilin, ShinyHunters Expands Extortion — HIGH, added
  24. FBI Arrests Founder of Ransomware Negotiation Firm (Edward Dubrovsky, Cypfer/CyberSteward) on Cyber Extortion and Conspiracy Charges Amid ShinyHunters Crackdown — MEDIUM, added
  25. Legitimate-Service Phishing (Living Off Trusted Services): ~10% of Threat Emails Abuse Trusted Platforms Such as DocuSign, QuickBooks, Adobe and Dropbox — HIGH, added
  26. Anthropic OSS Scanner: Free AI-Driven Vulnerability Scanning for Open-Source Projects (29,000+ Candidate Vulnerabilities Found) — INFO, added
  27. Cisco Talos Warns Autonomous AI Agent Swarms Could Evolve From Noisy Pentest-Style Attacks Into Stealthy Red Team Operations — MEDIUM, added
  28. GhostAction: Credential-Stealing GitHub Actions Workflows Planted in Compromised Maintainer Repositories — HIGH, added
  29. Working Public Exploit ("AnyPwn") for Pre-Auth AnyDesk Linux Heap Overflow Yielding Root Access — HIGH, added
  30. Multiple Vulnerabilities in Google Chrome prior to 155.0.8059.39 (incl. CVE-2026-102322 SiteIsolation RCE and CVE-2026-106386 WebAudio, public PoC reported) — CRITICAL, added

From the blog

Browse the corpus

  • Threat actors — every tracked adversary with its threats, techniques and targets
  • CVEs — enriched vulnerabilities with CVSS, EPSS and CISA KEV status
  • ATT&CK techniques — every MITRE technique seen in the corpus and the threats that use it
  • Vendors — affected vendors and the threats and CVEs tied to them
  • Weaknesses (CWE) — software weakness classes and the CVEs that instantiate them
  • Daily debriefs — the archive of daily threat-intelligence briefings

Machine-readable overview: /llms.txt.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats