# Daily Intelligence Briefing — Monday, June 15, 2026

> On 2026-06-15, Threadlinqs published 17 new threat reports, 4 rated critical and 11 high, spanning 148 MITRE ATT&CK techniques and 9 named threat actors. Coverage that day added 153 new detection rules and 439 extracted indicators.

- **Edition:** 2026-06-15 (Monday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-06-15
- **Last updated:** 2026-06-21
- **New threats:** 17
- **Critical / high:** 4 critical, 11 high, 2 medium, 0 low
- **ATT&CK techniques:** 148
- **Threat actors:** 9
- **Indicators (count only):** 439
- **New detection rules (count only):** 153

## Summary & highlights

SHADOWBYT3$ Claims Breach of Nintendo via Third-Party TINYpulse HR-Engagement SaaS Exposure (~859 MB, $2M Extortion). CVE-2026-20262: Cisco Catalyst SD-WAN Manager (vManage) Arbitrary File Upload Flaw Exploited as Zero-Day for Root Privilege Escalation. HAMLOCK: Split Hardware/Software Neural-Network Backdoor Evading ML Trojan Defenses (arXiv:2510.19145, USENIX Security 2026).

- [TL-2026-0798](https://intel.threadlinqs.com/threat/TL-2026-0798) — HAMLOCK: Split Hardware/Software Neural-Network Backdoor Evading ML Trojan Defenses (arXiv:2510.19145, USENIX Security 2026)
- [TL-2026-0799](https://intel.threadlinqs.com/threat/TL-2026-0799) — Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares\[.\]com / wetransfer\[.\]ICU SEO-Poisoning Operation)
- [TL-2026-0802](https://intel.threadlinqs.com/threat/TL-2026-0802) — NarwhalRAT: APT37 Python-based RAT delivered via LNK/PowerShell/Python loader chain in Microsoft-themed Korean spear-phishing campaign
- [TL-2026-0803](https://intel.threadlinqs.com/threat/TL-2026-0803) — Dark Web Data-Leak Roundup (June 2026): Iran Hajj Organization (168M records), AdressFakta/SUPEReROI Sweden (5.4M+), Chrysler/Salesforce (1TB+, Everest Ransomware), and Crypto-Platform Lead Lists
- [TL-2026-0804](https://intel.threadlinqs.com/threat/TL-2026-0804) — Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted

## Theme of the day

Unknown actors are actively exploiting critical vulnerabilities in Microsoft Exchange, Splunk Enterprise, and phpBB. These exploits enable authentication bypass, cross-site scripting, and remote code execution.

defense-evasion, masquerading, persistence, obfuscation, extortion

## Threats published

- [TL-2026-0800](https://intel.threadlinqs.com/threat/TL-2026-0800) — CRITICAL — Wazuh Manager 5.0 inventory_sync NDJSON Injection in OpenSearch _bulk API (GHSA-ff9g-85jq-r3g3, CVSS 10.0)
- [TL-2026-0801](https://intel.threadlinqs.com/threat/TL-2026-0801) — CRITICAL — Awesome Motive WordPress Plugin Supply-Chain Attack (OptinMonster, TrustPulse, PushEngage) Delivering Self-Hiding Backdoor via Poisoned CDN JavaScript
- [TL-2026-0806](https://intel.threadlinqs.com/threat/TL-2026-0806) — CRITICAL — SearchLeak: Microsoft 365 Copilot Enterprise One-Click Data Exfiltration (CVE-2026-42824)
- [TL-2026-0807](https://intel.threadlinqs.com/threat/TL-2026-0807) — CRITICAL — Velvet Ant (Operation Highland): Backdoored Linux PAM and OpenSSH for ~Decade-Long Espionage Persistence
- [TL-2026-0798](https://intel.threadlinqs.com/threat/TL-2026-0798) — HIGH — HAMLOCK: Split Hardware/Software Neural-Network Backdoor Evading ML Trojan Defenses (arXiv:2510.19145, USENIX Security 2026)
- [TL-2026-0799](https://intel.threadlinqs.com/threat/TL-2026-0799) — HIGH — Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares\[.\]com / wetransfer\[.\]ICU SEO-Poisoning Operation)
- [TL-2026-0802](https://intel.threadlinqs.com/threat/TL-2026-0802) — HIGH — NarwhalRAT: APT37 Python-based RAT delivered via LNK/PowerShell/Python loader chain in Microsoft-themed Korean spear-phishing campaign
- [TL-2026-0803](https://intel.threadlinqs.com/threat/TL-2026-0803) — HIGH — Dark Web Data-Leak Roundup (June 2026): Iran Hajj Organization (168M records), AdressFakta/SUPEReROI Sweden (5.4M+), Chrysler/Salesforce (1TB+, Everest Ransomware), and Crypto-Platform Lead Lists
- [TL-2026-0804](https://intel.threadlinqs.com/threat/TL-2026-0804) — HIGH — Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted
- [TL-2026-0805](https://intel.threadlinqs.com/threat/TL-2026-0805) — HIGH — The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to Deliver ConnectWise ScreenConnect RMM Access
- [TL-2026-0809](https://intel.threadlinqs.com/threat/TL-2026-0809) — HIGH — Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for Decade-Long Credential Theft in an Isolated Network
- [TL-2026-0810](https://intel.threadlinqs.com/threat/TL-2026-0810) — HIGH — Azure Blob Storage Ransomware: Four Storage-Encryption Abuse Methods (BlackCat/ALPHV, STORM-0501)
- [TL-2026-0812](https://intel.threadlinqs.com/threat/TL-2026-0812) — HIGH — SearchJack: 23 Malicious Chrome Extensions Hijack Search Queries via chrome_settings_overrides (Yahoo Affiliate Monetization)
- [TL-2026-0813](https://intel.threadlinqs.com/threat/TL-2026-0813) — HIGH — North Korean Threat Actors Weaponize Developer Tools (VS Code, npm, GitHub) for Cross-Platform Malware Delivery — Contagious Interview / UNK_DeadDrop
- [TL-2026-0814](https://intel.threadlinqs.com/threat/TL-2026-0814) — HIGH — EtherRAT: Node.js Remote Access Trojan with Ethereum Blockchain C2 Resolution and Per-Execution Self-Reobfuscation
- [TL-2026-0808](https://intel.threadlinqs.com/threat/TL-2026-0808) — MEDIUM — SHADOWBYT3$ Claims Breach of Nintendo via Third-Party TINYpulse HR-Engagement SaaS Exposure (~859 MB, $2M Extortion)
- [TL-2026-0811](https://intel.threadlinqs.com/threat/TL-2026-0811) — MEDIUM — CVE-2026-20262: Cisco Catalyst SD-WAN Manager (vManage) Arbitrary File Upload Flaw Exploited as Zero-Day for Root Privilege Escalation

## Techniques observed

AML.T0010, AML.T0015, AML.T0018, AML.T0031, AML.T0048, [T1003](https://intel.threadlinqs.com/technique/T1003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1010](https://intel.threadlinqs.com/technique/T1010), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021.004](https://intel.threadlinqs.com/technique/T1021.004), [T1025](https://intel.threadlinqs.com/technique/T1025), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.004](https://intel.threadlinqs.com/technique/T1036.004), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1037.004](https://intel.threadlinqs.com/technique/T1037.004), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.002, [T1070.006](https://intel.threadlinqs.com/technique/T1070.006), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.001](https://intel.threadlinqs.com/technique/T1078.001), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.004](https://intel.threadlinqs.com/technique/T1098.004), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1104](https://intel.threadlinqs.com/technique/T1104), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1110.001](https://intel.threadlinqs.com/technique/T1110.001), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1129](https://intel.threadlinqs.com/technique/T1129), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1218.007](https://intel.threadlinqs.com/technique/T1218.007), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1222](https://intel.threadlinqs.com/technique/T1222), [T1484](https://intel.threadlinqs.com/technique/T1484), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491.001](https://intel.threadlinqs.com/technique/T1491.001), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1538](https://intel.threadlinqs.com/technique/T1538), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1542](https://intel.threadlinqs.com/technique/T1542), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1556](https://intel.threadlinqs.com/technique/T1556), T1556.003, [T1559](https://intel.threadlinqs.com/technique/T1559), T1562, T1562.001, T1562.006, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1565.002](https://intel.threadlinqs.com/technique/T1565.002), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1569.002](https://intel.threadlinqs.com/technique/T1569.002), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.006](https://intel.threadlinqs.com/technique/T1574.006), [T1578](https://intel.threadlinqs.com/technique/T1578), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1608.004](https://intel.threadlinqs.com/technique/T1608.004), [T1608.005](https://intel.threadlinqs.com/technique/T1608.005), [T1608.006](https://intel.threadlinqs.com/technique/T1608.006), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1650](https://intel.threadlinqs.com/technique/T1650), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657)

## Threat actors

[SHADOWBYT3$](https://intel.threadlinqs.com/actor/SHADOWBYT3%24), [APT37](https://intel.threadlinqs.com/actor/APT37), Everest ransomware group; multiple unnamed data brokers; APT43/Kimsuky (claimed, unverified), ShinyHunters (UNC6040 / UNC6240), [RockyBelling](https://intel.threadlinqs.com/actor/RockyBelling), [Velvet Ant](https://intel.threadlinqs.com/actor/Velvet%20Ant), STORM-0501 / BlackCat (ALPHV), SearchJack operators (search-affiliate broker network), Contagious Interview (Famous Chollima)

Nation-state attribution: North Korea, North Korea (APT43/Kimsuky claim, unverified); Unknown (data brokers), China

Threat categories: DATA_BREACH, VULNERABILITY, RESEARCH, MALWARE, APT, PHISHING, RANSOMWARE, SUPPLY_CHAIN

## Severity breakdown

- critical: 4
- high: 11
- medium: 2
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 439 (network 131, behavioral 113, file 101, tool 23, entity 21, infrastructure 20, malware 15, package 10, technique 5)
- New detection rules: 153 (100% of the day’s threats covered)

## More editions

- Previous: [2026-06-10](https://intel.threadlinqs.com/debrief/2026-06-10)
- Next: [2026-06-16](https://intel.threadlinqs.com/debrief/2026-06-16)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-06-15
