Threadlinqs IntelligenceStart free

Daily debrief · Wednesday2026-05-27

Daily Intelligence Briefing — Wednesday, May 27, 2026

5 critical9 high

On 2026-05-27, Threadlinqs published 14 new threat reports, 5 rated critical and 9 high, spanning 216 MITRE ATT&CK techniques and 6 named threat actors. Coverage that day added 126 new detection rules and 398 extracted indicators.

New threats
1414 threat lines
Critical / high
145 critical · 9 high
ATT&CK techniques
216Observed in the day’s reports
Threat actors
6Named in the reports
Indicators
398Count only · values are Red+
Detection rules
126New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039). BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services Abuse. Nested Triple-Chain Google Domain Phishing — Microsoft SafeLinks -> meet.google.com/linkredirect -> google.com/url -> adservice.google.com.ph Evades SEGs and Lands M365 Credential Theft Plus OAuth 2.0 Device-Code Phishing (KnowBe4 ThreatLabs Nested Delivery Matrix).

Highlights

  • TL-2026-0599 — BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039)
  • TL-2026-0600 — BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services Abuse
  • TL-2026-0601 — Nested Triple-Chain Google Domain Phishing — Microsoft SafeLinks -> meet.google.com/linkredirect -> google.com/url -> adservice.google.com.ph Evades SEGs and Lands M365 Credential Theft Plus OAuth 2.0 Device-Code Phishing (KnowBe4 ThreatLabs Nested Delivery Matrix)
  • TL-2026-0602 — Gitea Container Registry Authorization Bypass (CVE-2026-27771) — Unauthenticated Pull of Private Container Images Across 31,000+ Self-Hosted Instances
  • TL-2026-0603 — GlassWorm Developer Supply Chain Campaign Takedown — CrowdStrike + Google + Shadowserver Disrupt 4-Channel C2 (Solana / BitTorrent DHT / Google Calendar / VPS)

Theme of the day

Credential theft and active exploitation prevailed: Android banking trojans OverlayPhantom and BTMOB, nested Google-domain phishing, and Akira ransomware via SSLVPN. Critical CVEs hit Windows Kernel, GitHub Enterprise, Starlette/AI infra, plus a multi-CVE BIND 9 disclosure.

  • credential-theft
  • linux
  • active-exploitation
  • financially-motivated
  • phishing

Threats published

14 threat lines in the 2026-05-27 debrief, most severe first. Each links to its full profile.

Techniques observed

216 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

6 named threat actors across the reports.

  • BTMOB MaaS operator (Unattributed)
  • GlassWorm Operators (Russian-speaking crimeware crew)
  • jacksonkaandorp2 (npm supply-chain operator)
  • Grandoreiro operators
  • Akira (ransomware-as-a-service operation)
  • JINX-0164

Nation-state attribution

  • Russia
  • Brazil

Threat categories

  • VULNERABILITY
  • MALWARE
  • PHISHING
  • SUPPLY_CHAIN
  • RANSOMWARE
  • APT

Severity breakdown

  • critical5
  • high9
  • medium0
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

398 indicators of compromise · Red and above. Compare plans
  • network 111
  • behavioral 104
  • file 64
  • infrastructure 29
  • package 29
  • technique 22
  • malware 19
  • tool 16
  • entity 4
126 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans