Threadlinqs Intelligence — Real-Time Threat Detection Platform
Threadlinqs Intelligence is a free, public cyber-threat-intelligence platform for security operations, detection engineering and threat-hunting teams. Every entry is a profiled real-world threat: what the adversary did, which MITRE ATT&CK techniques it maps to, which CVEs it exploited, which indicators it left behind, and the detection rules that catch it. It currently profiles 2,741 threats, each carrying deployable detection logic — 25,108 rules in Splunk SPL, Microsoft KQL and Sigma — alongside 68,432 extracted indicators of compromise, 661 attributed threat actors and 856 distinct MITRE ATT&CK and ATLAS techniques. The corpus is updated daily. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Data as of .
Explore
- Daily threat intelligence debrief — every threat added or updated in the last 24 hours, with detection and ATT&CK coverage.
- Platform statistics — corpus size, severity and category composition, technique and actor coverage.
- MITRE ATT&CK coverage map — techniques and threats per tactic across the Enterprise, ICS and ATLAS matrices.
- Live CVE intelligence feed — enriched CVEs ranked by CVSS, EPSS exploitation probability, CISA KEV status and public exploit availability.
- MCP server for AI agents — Model Context Protocol access to the same corpus from Claude, Cursor or any MCP client.
Recent threat intelligence
- Android October 2026 Security Bulletin - 25 Vulnerabilities Patched in Framework and System (Patch Level 2026-10-01) — HIGH, added
- Chrome 155 Update Patches 247 Vulnerabilities Including 4 Critical Use-After-Free Flaws (CVE-2026-106382, CVE-2026-106197, CVE-2026-106358, CVE-2026-106347) — CRITICAL, added
- Rockstar Games Breaches: Lapsus$ Source Code Theft, ShinyHunters Anodot/Snowflake OAuth Data Theft (78.6M Records), and Cyberleek Fake GTA VI Build Malware — HIGH, added
- Anthropic Disables Live Internet Access for Internal AI Evaluations After Claude Models Exploit Injection Flaws and Submit Unauthorized Forms — MEDIUM, added
- DeKalb County, Indiana Vendor Impersonation Email Payment Fraud (Oct 2026) — MEDIUM, added
- Advantest Discloses Data Breach Months After February 2026 Ransomware Attack — MEDIUM, added
- Progress DataDirect GenAI Command Injection via OpenAPI/Swagger Filename (CVE-2026-91140) — CRITICAL, added
- DarkBlinders Uses Fake StarkMeet Meeting App and GitHub C2 to Deploy RuntimeBroker Backdoor Against Government Targets — HIGH, added
- AI Agent-Driven Intrusion Chains Exposed Tomcat Spring Batch Endpoint to GodPotato/PrintSpoofer SYSTEM Escalation on Windows — HIGH, added
- Attackers Hide AI Prompt Injections Inside Phishing Emails to Manipulate AI Email Assistants — MEDIUM, added
- Deepfake scam operating inside a larger multi-stage fraud campaign (Bolster AI analysis) — MEDIUM, added
- Sonatype Q3 2026 Open Source Malware Index: Compounding Supply-Chain Compromise (Mini Shai-Hulud npm wave, mlflow-ui PyPI AI-agent-uploaded malware) — HIGH, added
- ChainDrop npm Worm and PolinRider DPRK-Linked Operation Use Blockchain C2 to Steal Cloud and CI/CD Credentials — HIGH, added
- Critical Cisco Nexus 3000/9000 NX-OS NGOAM Stack Buffer Overflows Allow Unauthenticated Root Code Execution (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501) — CRITICAL, added
- Malware Embedding Prompt-Injection Text to Evade AI-Based Analysis (FRUITSHELL, PLOTSAFE, HOLLOWCLAD, MANTLEMAZE, ROZESHELL) — MEDIUM, added
- UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing — HIGH, added
- IBM and Red Hat fix 400+ previously unknown Java library vulnerabilities via Lightwell — MEDIUM, added
- CVE-2025-64393: Critical Veeam Backup & Replication RCE via Mount Service Insecure Deserialization — CRITICAL, added
- Active Exploitation of Citrix NetScaler ADC and Gateway Zero-Days (CVE-2026-88771, CVE-2026-88772) with WHIPSHOT/SLAPSHOT Post-Exploitation — CRITICAL, added
- BlossCraft Launcher: Electron-Based Information Stealer Masquerading as Game Launcher — MEDIUM, added
- Akira Ransomware Attack Mapped by Huntress: RDP Initial Access, GOST Tunneling, Rclone Exfiltration — HIGH, added
- BlueMoon Exploit Kit Chains Chrome V8 Flaws CVE-2026-85046 and CVE-2026-87491 with Windows Kernel LPE CVE-2026-85880 — CRITICAL, added
- GuidePoint GRIT Q3 2026 Ransomware Report: Record 2,760 Victims, New Top Group Edges Out Qilin, ShinyHunters Expands Extortion — HIGH, added
- FBI Arrests Founder of Ransomware Negotiation Firm (Edward Dubrovsky, Cypfer/CyberSteward) on Cyber Extortion and Conspiracy Charges Amid ShinyHunters Crackdown — MEDIUM, added
- Legitimate-Service Phishing (Living Off Trusted Services): ~10% of Threat Emails Abuse Trusted Platforms Such as DocuSign, QuickBooks, Adobe and Dropbox — HIGH, added
- Anthropic OSS Scanner: Free AI-Driven Vulnerability Scanning for Open-Source Projects (29,000+ Candidate Vulnerabilities Found) — INFO, added
- Cisco Talos Warns Autonomous AI Agent Swarms Could Evolve From Noisy Pentest-Style Attacks Into Stealthy Red Team Operations — MEDIUM, added
- GhostAction: Credential-Stealing GitHub Actions Workflows Planted in Compromised Maintainer Repositories — HIGH, added
- Working Public Exploit ("AnyPwn") for Pre-Auth AnyDesk Linux Heap Overflow Yielding Root Access — HIGH, added
- Multiple Vulnerabilities in Google Chrome prior to 155.0.8059.39 (incl. CVE-2026-102322 SiteIsolation RCE and CVE-2026-106386 WebAudio, public PoC reported) — CRITICAL, added
From the blog
- Anthropic AI Misuse Report (Sept 2026) Mapped
- Signal Hijacking: QR Phishing, APT44 WAVESIGN
- TLQL: Threadlinqs Query Language Reference
- TeamPCP: From LiteLLM to Vect Ransomware
- OS.ai: The Agentic OS Manager for Threat Intel
Browse the corpus
- Threat actors — every tracked adversary with its threats, techniques and targets
- CVEs — enriched vulnerabilities with CVSS, EPSS and CISA KEV status
- ATT&CK techniques — every MITRE technique seen in the corpus and the threats that use it
- Vendors — affected vendors and the threats and CVEs tied to them
- Weaknesses (CWE) — software weakness classes and the CVEs that instantiate them
- Daily debriefs — the archive of daily threat-intelligence briefings
Machine-readable overview: /llms.txt.
Threadlinqs Intelligence — Real-Time Threat Detection Platform
Live intelligence console