Summary & highlights
XZ Utils Multithreaded Decoder Race Condition (CVE-2025-31115) - B&R & Siemens ICS Impact. TONResolver Remote Access Trojan - Active Campaign Targeting Japanese Hospitality Sector. Phantom Squatting: Adversaries Weaponize AI-Hallucinated Domains as Supply Chain Attack Vector.
Highlights
- TL-2026-1001 — XZ Utils Multithreaded Decoder Race Condition (CVE-2025-31115) - B&R & Siemens ICS Impact
- TL-2026-1010 — TONResolver Remote Access Trojan - Active Campaign Targeting Japanese Hospitality Sector
- TL-2026-1018 — Phantom Squatting: Adversaries Weaponize AI-Hallucinated Domains as Supply Chain Attack Vector
- TL-2026-1020 — Operation Endgame Disrupts Amadey Loader and StealC Infostealer Network, Recovers 27M Stolen Credentials
- TL-2026-1022 — Operation Endgame Disrupts StealC Infostealer and Amadey Loader/Botnet Infrastructure (326 Servers, 142 Domains, 27M Credentials, EUR41M Seized)
Theme of the day
Routine activity — no dominant theme emerged.
- credential-theft
- privilege-escalation
- lateral-movement
- remote-code-execution
- code-injection
Threats published
19 threat lines in the 2026-06-30 debrief, most severe first. Each links to its full profile.
- CVE-2026-46817: Oracle E-Business Suite Payments Authentication Bypass – Unauth Remote Takeover via /OA_HTML/ibytransmitCRITICAL
- Langflow CVE-2026-33017 Unauthenticated RCE Actively Exploited for Monero Mining (lambsys)CRITICAL
- SEO Poisoning Supply Chain Campaign Distributing Akira Ransomware via Trojanized Enterprise SoftwareCRITICAL
- SystemBC (Coroxy) Malware: Tor-Based SOCKS5 Proxy Backdoor Enabling Ransomware Persistence and C2 ObfuscationCRITICAL
- RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector ExploitationCRITICAL
- CVE-2026-24294: NTLM Reflection Bypass via SMB on Arbitrary TCP Ports — Local Privilege Escalation to SYSTEMCRITICAL
- Multiple WolfSSL Critical Vulnerabilities: Certificate Bypass, RCE, and Post-Quantum WeakeningCRITICAL
- Fake Bug Report Prompt Injection Attacks Hijacking AI Coding Agents (Agentjacking)CRITICAL
- Synology MailPlus Server Critical Remote Code Execution and Arbitrary File Access (CVE-2026-13136, CVE-2025-15660, CVE-2026-13135)CRITICAL
- Black Basta Ransomware Operation - Organizational Breakdown & 2025 ShutdownCRITICAL
- Mistic Windows Backdoor - In-Memory Code Execution via DLL SideloadingCRITICAL
- CVE-2025-67038: Critical Code Injection in Lantronix EDS5000 Series Under Active ExploitationCRITICAL
- Cordyceps: Systemic CI/CD Workflow Flaws Expose 300+ GitHub Repositories (Microsoft, Google, Apache, Cloudflare, PSF) to Supply-Chain AttacksCRITICAL
- XZ Utils Multithreaded Decoder Race Condition (CVE-2025-31115) - B&R & Siemens ICS ImpactHIGH
- TONResolver Remote Access Trojan - Active Campaign Targeting Japanese Hospitality SectorHIGH
- Phantom Squatting: Adversaries Weaponize AI-Hallucinated Domains as Supply Chain Attack VectorHIGH
- Operation Endgame Disrupts Amadey Loader and StealC Infostealer Network, Recovers 27M Stolen CredentialsHIGH
- Operation Endgame Disrupts StealC Infostealer and Amadey Loader/Botnet Infrastructure (326 Servers, 142 Domains, 27M Credentials, EUR41M Seized)HIGH
- GuardFall: Shell-Injection Guardrail Bypass Exposes Open-Source AI Coding Agents to Supply-Chain AttacksHIGH
Techniques observed
136 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1003
- T1005
- T1008
- T1010
- T1012
- T1016
- T1020
- T1021
- T1027
- T1036
- T1039
- T1040
- T1041
- T1046
- T1047
- T1048
- T1053
- T1055
- T1056
- T1057
- T1059
- T1059.004
- T1059.007
- T1068
- T1069
- T1070
- T1071
- T1074
- T1078
- T1078.001
- T1078.004
- T1082
- T1083
- T1087
- T1090
- T1092
- T1095
- T1098
- T1098.001
- T1102
- T1105
- T1106
- T1110
- T1112
- T1113
- T1114
- T1115
- T1120
- T1124
- T1133
- T1134
- T1135
- T1136
- T1140
- T1187
- T1189
- T1190
- T1195
- T1195.002
- T1199
- T1201
- T1202
- T1203
- T1204
- T1210
- T1213
- T1217
- T1218
- T1219
- T1480
- T1482
- T1484
- T1485
- T1486
- T1490
- T1491
- T1496
- T1497
- T1499
- T1505
- T1518
- T1528
- T1529
- T1531
- T1537
- T1539
- T1543
- T1547
- T1548
- T1548.002
- T1550
- T1550.001
- T1552
- T1552.001
- T1553
- T1554
- T1555
- T1556
- T1557
- T1558
- T1560
- T1561
- T1562
- T1563
- T1564
- T1565
- T1566
- T1567
- T1568
- T1569
- T1570
- T1571
- T1572
- T1573
- T1574
- T1583
- T1584
- T1585
- T1586
- T1587
- T1588
- T1589
- T1589.001
- T1590
- T1592
- T1595
- T1598
- T1600
- T1601
- T1608
- T1614
- T1620
- T1657
- T1665
- T1678
Threat actors
7 named threat actors across the reports.
Nation-state attribution
- Russia
- Russia / Post-Soviet
Threat categories
- VULNERABILITY
- MALWARE
- SUPPLY_CHAIN
- RANSOMWARE
Severity breakdown
- critical13
- high6
- medium0
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 161
- network 91
- file 59
- infrastructure 52
- tool 37
- malware 32
- entity 27
- technique 7
- package 5
- web 4
- application 3