Threadlinqs IntelligenceStart free

Daily debrief · Thursday2026-03-12

Daily Intelligence Briefing — Thursday, March 12, 2026

25 critical22 high

On 2026-03-12, Threadlinqs published 7 new threat reports and updated 40, 25 rated critical and 22 high, spanning 214 MITRE ATT&CK techniques and 26 named threat actors. Coverage that day added 423 new detection rules and 1255 extracted indicators.

New threats
740 updated
Critical / high
4725 critical · 22 high
ATT&CK techniques
214Observed in the day’s reports
Threat actors
26Named in the reports
Indicators
1255Count only · values are Red+
Detection rules
423New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

CVE-2026-21262: Microsoft SQL Server Elevation of Privilege via Improper Access Control in Merge Replication. Malicious Packagist Packages Deliver Cross-Platform PHP RAT via Fake Laravel Utilities (nhattuanbl Campaign). Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential Theft.

Highlights

  • TL-2026-0216 — CVE-2026-21262: Microsoft SQL Server Elevation of Privilege via Improper Access Control in Merge Replication
  • TL-2026-0217 — Malicious Packagist Packages Deliver Cross-Platform PHP RAT via Fake Laravel Utilities (nhattuanbl Campaign)
  • TL-2026-0218 — Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential Theft
  • TL-2026-0219 — Mustang Panda Deploys PlugX RAT via Multi-Stage CHM Sideloading Campaign Targeting Persian Gulf Region (March 2026)
  • TL-2026-0214 — Lotus Blossom APT Supply Chain Compromise of Notepad++ Update Infrastructure (CVE-2025-15556)

Theme of the day

Iranian MOIS operations led the day as Void Manticore and MuddyWater ran wiper and cybercrime campaigns, joined by Lotus Blossom's Notepad++ supply-chain compromise, Mustang Panda PlugX, malicious Packagist packages, and Storm-2561 SEO poisoning.

  • data-exfiltration
  • credential-theft
  • lateral-movement
  • espionage
  • active-exploitation

Threats published

47 threat lines in the 2026-03-12 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

214 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

26 named threat actors across the reports.

  • nhattuanbl
  • Storm-2561
  • Mustang Panda (medium confidence)
  • Lotus Blossom / Spring Dragon
  • Void Manticore / MuddyWater (MOIS)
  • Handala Hack / Void Manticore
  • Mustang Panda / Earth Preta
  • CL-UNK-1068
  • APT28 / Fancy Bear
  • APT36 / Transparent Tribe
  • UAT-9244 / FamousSparrow
  • Arid Viper / APT-C-23
  • HoneyMyte / Mustang Panda
  • APT28 / Fancy Bear / Sednit
  • KongTuke / TAG-124
  • Famous Chollima / Tenacious Pungsan / DEV#POPPER
  • APT29 / Midnight Blizzard (IRON TWILIGHT cluster)
  • Seedworm / MuddyWater
  • Saito Tech (Candiru)
  • CyberAv3ngers / APT33 / MuddyWater / APT34 / Handala Hack Team / APT35
  • UNC6353 / UNC6691
  • UNC6201
  • UNC2814 / Gallium
  • MuddyWater / Seedworm
  • INC Ransom / GOLD IONIC
  • UNC4899 / Jade Sleet

Nation-state attribution

  • China
  • Iran
  • Russia
  • Pakistan
  • Palestine
  • North Korea
  • Israel
  • Russia / China

Threat categories

  • VULNERABILITY
  • SUPPLY_CHAIN
  • MALWARE
  • APT
  • ZERO_DAY
  • ICS_SCADA
  • RANSOMWARE

Severity breakdown

  • critical25
  • high22
  • medium0
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

1255 indicators of compromise · Red and above. Compare plans
  • file 416
  • network 364
  • behavioral 235
  • malware 93
  • infrastructure 67
  • tool 48
  • entity 13
  • package 11
  • technique 8
423 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans