# Daily Intelligence Briefing — Tuesday, June 30, 2026

> On 2026-06-30, Threadlinqs published 19 new threat reports, 13 rated critical and 6 high, spanning 136 MITRE ATT&CK techniques and 7 named threat actors. Coverage that day added 171 new detection rules and 478 extracted indicators.

- **Edition:** 2026-06-30 (Tuesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-06-30
- **Last updated:** 2026-07-06
- **New threats:** 19
- **Critical / high:** 13 critical, 6 high, 0 medium, 0 low
- **ATT&CK techniques:** 136
- **Threat actors:** 7
- **Indicators (count only):** 478
- **New detection rules (count only):** 171

## Summary & highlights

XZ Utils Multithreaded Decoder Race Condition (CVE-2025-31115) - B&R & Siemens ICS Impact. TONResolver Remote Access Trojan - Active Campaign Targeting Japanese Hospitality Sector. Phantom Squatting: Adversaries Weaponize AI-Hallucinated Domains as Supply Chain Attack Vector.

- [TL-2026-1001](https://intel.threadlinqs.com/threat/TL-2026-1001) — XZ Utils Multithreaded Decoder Race Condition (CVE-2025-31115) - B&R & Siemens ICS Impact
- [TL-2026-1010](https://intel.threadlinqs.com/threat/TL-2026-1010) — TONResolver Remote Access Trojan - Active Campaign Targeting Japanese Hospitality Sector
- [TL-2026-1018](https://intel.threadlinqs.com/threat/TL-2026-1018) — Phantom Squatting: Adversaries Weaponize AI-Hallucinated Domains as Supply Chain Attack Vector
- [TL-2026-1020](https://intel.threadlinqs.com/threat/TL-2026-1020) — Operation Endgame Disrupts Amadey Loader and StealC Infostealer Network, Recovers 27M Stolen Credentials
- [TL-2026-1022](https://intel.threadlinqs.com/threat/TL-2026-1022) — Operation Endgame Disrupts StealC Infostealer and Amadey Loader/Botnet Infrastructure (326 Servers, 142 Domains, 27M Credentials, EUR41M Seized)

## Theme of the day

Routine activity — no dominant theme emerged.

credential-theft, privilege-escalation, lateral-movement, remote-code-execution, code-injection

## Threats published

- [TL-2026-1000](https://intel.threadlinqs.com/threat/TL-2026-1000) — CRITICAL — CVE-2026-46817: Oracle E-Business Suite Payments Authentication Bypass – Unauth Remote Takeover via /OA_HTML/ibytransmit
- [TL-2026-1002](https://intel.threadlinqs.com/threat/TL-2026-1002) — CRITICAL — Langflow CVE-2026-33017 Unauthenticated RCE Actively Exploited for Monero Mining (lambsys)
- [TL-2026-1004](https://intel.threadlinqs.com/threat/TL-2026-1004) — CRITICAL — SEO Poisoning Supply Chain Campaign Distributing Akira Ransomware via Trojanized Enterprise Software
- [TL-2026-1005](https://intel.threadlinqs.com/threat/TL-2026-1005) — CRITICAL — SystemBC (Coroxy) Malware: Tor-Based SOCKS5 Proxy Backdoor Enabling Ransomware Persistence and C2 Obfuscation
- [TL-2026-1006](https://intel.threadlinqs.com/threat/TL-2026-1006) — CRITICAL — RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector Exploitation
- [TL-2026-1007](https://intel.threadlinqs.com/threat/TL-2026-1007) — CRITICAL — CVE-2026-24294: NTLM Reflection Bypass via SMB on Arbitrary TCP Ports — Local Privilege Escalation to SYSTEM
- [TL-2026-1008](https://intel.threadlinqs.com/threat/TL-2026-1008) — CRITICAL — Multiple WolfSSL Critical Vulnerabilities: Certificate Bypass, RCE, and Post-Quantum Weakening
- [TL-2026-1012](https://intel.threadlinqs.com/threat/TL-2026-1012) — CRITICAL — Fake Bug Report Prompt Injection Attacks Hijacking AI Coding Agents (Agentjacking)
- [TL-2026-1014](https://intel.threadlinqs.com/threat/TL-2026-1014) — CRITICAL — Synology MailPlus Server Critical Remote Code Execution and Arbitrary File Access (CVE-2026-13136, CVE-2025-15660, CVE-2026-13135)
- [TL-2026-1015](https://intel.threadlinqs.com/threat/TL-2026-1015) — CRITICAL — Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdown
- [TL-2026-1017](https://intel.threadlinqs.com/threat/TL-2026-1017) — CRITICAL — Mistic Windows Backdoor - In-Memory Code Execution via DLL Sideloading
- [TL-2026-1019](https://intel.threadlinqs.com/threat/TL-2026-1019) — CRITICAL — CVE-2025-67038: Critical Code Injection in Lantronix EDS5000 Series Under Active Exploitation
- [TL-2026-1021](https://intel.threadlinqs.com/threat/TL-2026-1021) — CRITICAL — Cordyceps: Systemic CI/CD Workflow Flaws Expose 300+ GitHub Repositories (Microsoft, Google, Apache, Cloudflare, PSF) to Supply-Chain Attacks
- [TL-2026-1001](https://intel.threadlinqs.com/threat/TL-2026-1001) — HIGH — XZ Utils Multithreaded Decoder Race Condition (CVE-2025-31115) - B&R & Siemens ICS Impact
- [TL-2026-1010](https://intel.threadlinqs.com/threat/TL-2026-1010) — HIGH — TONResolver Remote Access Trojan - Active Campaign Targeting Japanese Hospitality Sector
- [TL-2026-1018](https://intel.threadlinqs.com/threat/TL-2026-1018) — HIGH — Phantom Squatting: Adversaries Weaponize AI-Hallucinated Domains as Supply Chain Attack Vector
- [TL-2026-1020](https://intel.threadlinqs.com/threat/TL-2026-1020) — HIGH — Operation Endgame Disrupts Amadey Loader and StealC Infostealer Network, Recovers 27M Stolen Credentials
- [TL-2026-1022](https://intel.threadlinqs.com/threat/TL-2026-1022) — HIGH — Operation Endgame Disrupts StealC Infostealer and Amadey Loader/Botnet Infrastructure (326 Servers, 142 Domains, 27M Credentials, EUR41M Seized)
- [TL-2026-1131](https://intel.threadlinqs.com/threat/TL-2026-1131) — HIGH — GuardFall: Shell-Injection Guardrail Bypass Exposes Open-Source AI Coding Agents to Supply-Chain Attacks

## Techniques observed

[T1001](https://intel.threadlinqs.com/technique/T1001), [T1003](https://intel.threadlinqs.com/technique/T1003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1010](https://intel.threadlinqs.com/technique/T1010), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1039](https://intel.threadlinqs.com/technique/T1039), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.001](https://intel.threadlinqs.com/technique/T1078.001), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1090](https://intel.threadlinqs.com/technique/T1090), T1092, [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.001](https://intel.threadlinqs.com/technique/T1098.001), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1120](https://intel.threadlinqs.com/technique/T1120), [T1124](https://intel.threadlinqs.com/technique/T1124), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), T1201, [T1202](https://intel.threadlinqs.com/technique/T1202), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1480](https://intel.threadlinqs.com/technique/T1480), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1484](https://intel.threadlinqs.com/technique/T1484), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1558](https://intel.threadlinqs.com/technique/T1558), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1561](https://intel.threadlinqs.com/technique/T1561), T1562, T1563, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.001](https://intel.threadlinqs.com/technique/T1589.001), [T1590](https://intel.threadlinqs.com/technique/T1590), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1598](https://intel.threadlinqs.com/technique/T1598), T1600, [T1601](https://intel.threadlinqs.com/technique/T1601), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1657](https://intel.threadlinqs.com/technique/T1657), [T1665](https://intel.threadlinqs.com/technique/T1665), T1678

## Threat actors

[InCrease](https://intel.threadlinqs.com/actor/InCrease), [Amadey](https://intel.threadlinqs.com/actor/Amadey), [Akira Ransomware Gang](https://intel.threadlinqs.com/actor/Akira%20Ransomware%20Gang), [Unnamed](https://intel.threadlinqs.com/actor/Unnamed), [Black Basta](https://intel.threadlinqs.com/actor/Black%20Basta), [Woodgnat](https://intel.threadlinqs.com/actor/Woodgnat), [Chaya_006](https://intel.threadlinqs.com/actor/Chaya_006)

Nation-state attribution: Russia, Russia / Post-Soviet

Threat categories: VULNERABILITY, MALWARE, SUPPLY_CHAIN, RANSOMWARE

## Severity breakdown

- critical: 13
- high: 6
- medium: 0
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 478 (behavioral 161, network 91, file 59, infrastructure 52, tool 37, malware 32, entity 27, technique 7, package 5, web 4, application 3)
- New detection rules: 171 (100% of the day’s threats covered)

## More editions

- Previous: [2026-06-28](https://intel.threadlinqs.com/debrief/2026-06-28)
- Next: [2026-07-01](https://intel.threadlinqs.com/debrief/2026-07-01)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-06-30
