Threadlinqs IntelligenceStart free

Daily debrief · Friday2026-06-19

Daily Intelligence Briefing — Friday, June 19, 2026

5 critical14 high1 medium

On 2026-06-19, Threadlinqs published 18 new threat reports and updated 2, 5 rated critical and 14 high, spanning 147 MITRE ATT&CK techniques and 5 named threat actors. Coverage that day added 180 new detection rules and 405 extracted indicators.

New threats
182 updated
Critical / high
195 critical · 14 high
ATT&CK techniques
147Observed in the day’s reports
Threat actors
5Named in the reports
Indicators
405Count only · values are Red+
Detection rules
180New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPs. Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 Address Obfuscation (RFC 4291) to Evade URL Extraction. Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity TLS Authentication Bypass and WebCrypto DoS Flaws (CVE-2026-48618, CVE-2026-48933).

Highlights

  • TL-2026-0864 — OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPs
  • TL-2026-0865 — Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 Address Obfuscation (RFC 4291) to Evade URL Extraction
  • TL-2026-0866 — Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity TLS Authentication Bypass and WebCrypto DoS Flaws (CVE-2026-48618, CVE-2026-48933)
  • TL-2026-0867 — Pony (Fareit/Siplog) Credential-Stealing Trojan and Downloader
  • TL-2026-0869 — Xctdoor Backdoor Delivered via Resume-Themed LNK Files, PowerShell/VBScript Loaders, and ProximityUxHost.exe DLL Side-Loading (Andariel)

Theme of the day

Supply chain attacks and zero-day vulnerabilities are being actively exploited by unknown actors. Multiple high-severity threats enable malware delivery, code execution, and data theft.

  • poc-public
  • windows
  • rce
  • remote-code-execution
  • espionage

Threats published

20 threat lines in the 2026-06-19 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

147 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

5 named threat actors across the reports.

  • OceanLotus (APT32)
  • Andariel
  • Paradigm Shift (security research group)
  • Poisson
  • FortiBleed operators (Russian-speaking cybercriminal collective)

Nation-state attribution

  • Vietnam
  • North Korea

Threat categories

  • APT
  • PHISHING
  • VULNERABILITY
  • MALWARE
  • THREAT_INTEL
  • DATA_BREACH

Severity breakdown

  • critical5
  • high14
  • medium1
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

405 indicators of compromise · Red and above. Compare plans
  • behavioral 156
  • file 76
  • network 73
  • infrastructure 30
  • tool 25
  • package 15
  • entity 12
  • malware 8
  • technique 7
  • domain 3
180 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans