Threadlinqs IntelligenceStart free

Daily debrief · Wednesday2026-06-10

Daily Intelligence Briefing — Wednesday, June 10, 2026

4 critical23 high1 medium1 low

On 2026-06-10, Threadlinqs published 27 new threat reports and updated 2, 4 rated critical and 23 high, spanning 207 MITRE ATT&CK techniques and 16 named threat actors. Coverage that day added 261 new detection rules and 793 extracted indicators.

New threats
272 updated
Critical / high
274 critical · 23 high
ATT&CK techniques
207Observed in the day’s reports
Threat actors
16Named in the reports
Indicators
793Count only · values are Red+
Detection rules
261New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Houthi/Yemen-Based Disinformation & Influence Campaign Targeting Israel and the Gulf States (ClearSky). Windows Defender 0-Day Local Privilege Escalation "RoguePlanet" (Nightmare Eclipse Defender Exploit Series). AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855).

Highlights

  • TL-2026-0743 — Windows Defender 0-Day Local Privilege Escalation "RoguePlanet" (Nightmare Eclipse Defender Exploit Series)
  • TL-2026-0745 — AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855)
  • TL-2026-0747 — Vidar Stealer 2.0 (Loadbaks) Distributed via Fake Game Cheats on GitHub and Reddit
  • TL-2026-0751 — Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human Rights Defenders (NSO Group)
  • TL-2026-0752 — P2P Botnets in the Wild: Pink, Hajime, Mozi, FritzFrog, and Panchan — Decentralized C2 Landscape (360 Netlab Continuous Monitoring)

Theme of the day

Activity centered on 0-day, actively-exploited, ahnlab-asec.

  • windows
  • defense-evasion
  • masquerading
  • credential-theft
  • espionage

Threats published

29 threat lines in the 2026-06-10 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

207 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

16 named threat actors across the reports.

Nation-state attribution

  • Yemen
  • Azerbaijan
  • Russia
  • Iran
  • North Korea
  • China

Threat categories

  • THREAT_INTEL
  • VULNERABILITY
  • APT
  • MALWARE
  • RANSOMWARE
  • SUPPLY_CHAIN

Severity breakdown

  • critical4
  • high23
  • medium1
  • low1

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

793 indicators of compromise · Red and above. Compare plans
  • file 260
  • network 226
  • behavioral 155
  • malware 53
  • tool 40
  • infrastructure 28
  • entity 17
  • technique 12
  • package 2
261 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans