Threadlinqs IntelligenceStart free

Daily debrief · Monday2026-06-15

Daily Intelligence Briefing — Monday, June 15, 2026

4 critical11 high2 medium

On 2026-06-15, Threadlinqs published 17 new threat reports, 4 rated critical and 11 high, spanning 148 MITRE ATT&CK techniques and 9 named threat actors. Coverage that day added 153 new detection rules and 439 extracted indicators.

New threats
1717 threat lines
Critical / high
154 critical · 11 high
ATT&CK techniques
148Observed in the day’s reports
Threat actors
9Named in the reports
Indicators
439Count only · values are Red+
Detection rules
153New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

SHADOWBYT3$ Claims Breach of Nintendo via Third-Party TINYpulse HR-Engagement SaaS Exposure (~859 MB, $2M Extortion). CVE-2026-20262: Cisco Catalyst SD-WAN Manager (vManage) Arbitrary File Upload Flaw Exploited as Zero-Day for Root Privilege Escalation. HAMLOCK: Split Hardware/Software Neural-Network Backdoor Evading ML Trojan Defenses (arXiv:2510.19145, USENIX Security 2026).

Highlights

  • TL-2026-0798 — HAMLOCK: Split Hardware/Software Neural-Network Backdoor Evading ML Trojan Defenses (arXiv:2510.19145, USENIX Security 2026)
  • TL-2026-0799 — Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares[.]com / wetransfer[.]ICU SEO-Poisoning Operation)
  • TL-2026-0802 — NarwhalRAT: APT37 Python-based RAT delivered via LNK/PowerShell/Python loader chain in Microsoft-themed Korean spear-phishing campaign
  • TL-2026-0803 — Dark Web Data-Leak Roundup (June 2026): Iran Hajj Organization (168M records), AdressFakta/SUPEReROI Sweden (5.4M+), Chrysler/Salesforce (1TB+, Everest Ransomware), and Crypto-Platform Lead Lists
  • TL-2026-0804 — Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted

Theme of the day

Unknown actors are actively exploiting critical vulnerabilities in Microsoft Exchange, Splunk Enterprise, and phpBB. These exploits enable authentication bypass, cross-site scripting, and remote code execution.

  • defense-evasion
  • masquerading
  • persistence
  • obfuscation
  • extortion

Threats published

17 threat lines in the 2026-06-15 debrief, most severe first. Each links to its full profile.

Techniques observed

148 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

9 named threat actors across the reports.

  • SHADOWBYT3$
  • APT37
  • Everest ransomware group; multiple unnamed data brokers; APT43/Kimsuky (claimed, unverified)
  • ShinyHunters (UNC6040 / UNC6240)
  • RockyBelling
  • Velvet Ant
  • STORM-0501 / BlackCat (ALPHV)
  • SearchJack operators (search-affiliate broker network)
  • Contagious Interview (Famous Chollima)

Nation-state attribution

  • North Korea
  • North Korea (APT43/Kimsuky claim, unverified); Unknown (data brokers)
  • China

Threat categories

  • DATA_BREACH
  • VULNERABILITY
  • RESEARCH
  • MALWARE
  • APT
  • PHISHING
  • RANSOMWARE
  • SUPPLY_CHAIN

Severity breakdown

  • critical4
  • high11
  • medium2
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

439 indicators of compromise · Red and above. Compare plans
  • network 131
  • behavioral 113
  • file 101
  • tool 23
  • entity 21
  • infrastructure 20
  • malware 15
  • package 10
  • technique 5
153 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans