Threadlinqs IntelligenceStart free

Daily debrief · Tuesday2026-06-02

Daily Intelligence Briefing — Tuesday, June 2, 2026

4 critical9 high1 medium

On 2026-06-02, Threadlinqs published 14 new threat reports, 4 rated critical and 9 high, spanning 125 MITRE ATT&CK techniques and 4 named threat actors. Coverage that day added 126 new detection rules and 269 extracted indicators.

New threats
1414 threat lines
Critical / high
134 critical · 9 high
ATT&CK techniques
125Observed in the day’s reports
Threat actors
4Named in the reports
Indicators
269Count only · values are Red+
Detection rules
126New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

New Wave of SVG-Attachment Phishing — application/ecmascript MIME Evasion + XOR-Decoded Browser Redirect (chinougoo.cfd). Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access. StrongDM Desktop CVE-2026-4387 — Plaintext Session State (JWT + Asymmetric Keypair) Enables Credential-less Cross-Host Session Hijack.

Highlights

  • TL-2026-0653 — Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access
  • TL-2026-0654 — StrongDM Desktop CVE-2026-4387 — Plaintext Session State (JWT + Asymmetric Keypair) Enables Credential-less Cross-Host Session Hijack
  • TL-2026-0655 — Android Framework Integer-Overflow Elevation-of-Privilege 0-Day (CVE-2025-48595) Under Limited Targeted Exploitation — June 2026 Android Security Bulletin
  • TL-2026-0656 — Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix Recruitment Portal — TOTPGuard.dll AppDomainManager Hijacking Sideloading Chain Delivering main.dll Implant
  • TL-2026-0658 — Mustang Panda PlugX RAT — Multi-Stage Fake Browser Update Chain via G DATA AntiVirus DLL Sideloading (BlueCyber)

Theme of the day

Critical vulnerabilities and supply chain attacks dominate the threat landscape. Unknown actors are actively exploiting multiple high-severity flaws, including Windows Netlogon and others.

  • windows
  • defense-evasion
  • espionage
  • social-engineering
  • apt

Threats published

14 threat lines in the 2026-06-02 debrief, most severe first. Each links to its full profile.

Techniques observed

125 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

4 named threat actors across the reports.

Nation-state attribution

  • Russia
  • Iran
  • China

Threat categories

  • PHISHING
  • MALWARE
  • VULNERABILITY

Severity breakdown

  • critical4
  • high9
  • medium1
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

269 indicators of compromise · Red and above. Compare plans
  • behavioral 101
  • network 68
  • file 65
  • infrastructure 10
  • tool 8
  • technique 7
  • malware 5
  • package 3
  • entity 2
126 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans