Threadlinqs IntelligenceStart free

Daily debrief · Tuesday2026-06-30

Daily Intelligence Briefing — Tuesday, June 30, 2026

13 critical6 high

On 2026-06-30, Threadlinqs published 19 new threat reports, 13 rated critical and 6 high, spanning 136 MITRE ATT&CK techniques and 7 named threat actors. Coverage that day added 171 new detection rules and 478 extracted indicators.

New threats
1919 threat lines
Critical / high
1913 critical · 6 high
ATT&CK techniques
136Observed in the day’s reports
Threat actors
7Named in the reports
Indicators
478Count only · values are Red+
Detection rules
171New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

XZ Utils Multithreaded Decoder Race Condition (CVE-2025-31115) - B&R & Siemens ICS Impact. TONResolver Remote Access Trojan - Active Campaign Targeting Japanese Hospitality Sector. Phantom Squatting: Adversaries Weaponize AI-Hallucinated Domains as Supply Chain Attack Vector.

Highlights

  • TL-2026-1001 — XZ Utils Multithreaded Decoder Race Condition (CVE-2025-31115) - B&R & Siemens ICS Impact
  • TL-2026-1010 — TONResolver Remote Access Trojan - Active Campaign Targeting Japanese Hospitality Sector
  • TL-2026-1018 — Phantom Squatting: Adversaries Weaponize AI-Hallucinated Domains as Supply Chain Attack Vector
  • TL-2026-1020 — Operation Endgame Disrupts Amadey Loader and StealC Infostealer Network, Recovers 27M Stolen Credentials
  • TL-2026-1022 — Operation Endgame Disrupts StealC Infostealer and Amadey Loader/Botnet Infrastructure (326 Servers, 142 Domains, 27M Credentials, EUR41M Seized)

Theme of the day

Routine activity — no dominant theme emerged.

  • credential-theft
  • privilege-escalation
  • lateral-movement
  • remote-code-execution
  • code-injection

Threats published

19 threat lines in the 2026-06-30 debrief, most severe first. Each links to its full profile.

Techniques observed

136 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

7 named threat actors across the reports.

Nation-state attribution

  • Russia
  • Russia / Post-Soviet

Threat categories

  • VULNERABILITY
  • MALWARE
  • SUPPLY_CHAIN
  • RANSOMWARE

Severity breakdown

  • critical13
  • high6
  • medium0
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

478 indicators of compromise · Red and above. Compare plans
  • behavioral 161
  • network 91
  • file 59
  • infrastructure 52
  • tool 37
  • malware 32
  • entity 27
  • technique 7
  • package 5
  • web 4
  • application 3
171 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans