# Daily Intelligence Briefing — Wednesday, July 1, 2026

> On 2026-07-01, Threadlinqs published 37 new threat reports and updated 1, 12 rated critical and 20 high, spanning 235 MITRE ATT&CK techniques and 12 named threat actors. Coverage that day added 333 new detection rules and 944 extracted indicators.

- **Edition:** 2026-07-01 (Wednesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-07-01
- **Last updated:** 2026-07-06
- **New threats:** 37 (1 updated)
- **Critical / high:** 12 critical, 20 high, 5 medium, 0 low
- **ATT&CK techniques:** 235
- **Threat actors:** 12
- **Indicators (count only):** 944
- **New detection rules (count only):** 333

## Summary & highlights

CVE-2026-55407: Unbounded Heap Allocation DoS in Anthropic's Buffa Rust Protobuf Library (decode_unknown_field). Serbian 'Putevi Srbije' Traffic-Fine Smishing Campaign Using Darcula and Phoenix PhaaS Platforms. Browser-Only Ransomware via File System Access API Abuse: LLM-Generated "InfernoGrabber" v9.0 (DeepSeek-Attributed).

- [TL-2026-1023](https://intel.threadlinqs.com/threat/TL-2026-1023) — Xsolis Data Breach: Targeted Phishing Attack Exposes PHI/PII of 1,396,519 Individuals
- [TL-2026-1024](https://intel.threadlinqs.com/threat/TL-2026-1024) — Malicious ClawHub Skills Threaten OpenClaw AI Agent Supply Chain (AMOS, cluw, Solana Front-Running)
- [TL-2026-1027](https://intel.threadlinqs.com/threat/TL-2026-1027) — ClickFix Campaigns Evolve API-Driven Payload Delivery: Analysis of 3,000 Live Payloads Reveals New Evasion Techniques
- [TL-2026-1028](https://intel.threadlinqs.com/threat/TL-2026-1028) — Microsoft AI-Assisted Investigation Links StealC and Amadey Malware-as-a-Service Operations in RICO Suit (Operation Endgame)
- [TL-2026-1029](https://intel.threadlinqs.com/threat/TL-2026-1029) — Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret Blizzard Against Ukrainian Military

## Theme of the day

Activity centered on address-exposure, adventhealth, almeida-law-group.

credential-theft, financially-motivated, social-engineering, remote-access-trojan, credential-harvesting

## Threats published

- [TL-2026-1025](https://intel.threadlinqs.com/threat/TL-2026-1025) — CRITICAL — Active Exploitation of Cisco Unified Communications Manager WebDialer SSRF (CVE-2026-20230) and Catalyst SD-WAN Manager Root Privilege-Escalation Zero-Day (CVE-2026-20245)
- [TL-2026-1026](https://intel.threadlinqs.com/threat/TL-2026-1026) — CRITICAL — Chrome 151 Security Update Patches 382 Vulnerabilities, Including 15 Critical Memory-Corruption Flaws (CVE-2026-13774 to CVE-2026-13788)
- [TL-2026-1034](https://intel.threadlinqs.com/threat/TL-2026-1034) — CRITICAL — Adobe Patches Seven Priority-1 ColdFusion and Campaign Classic Flaws (CVE-2026-48276, CVE-2026-48277, CVE-2026-48281, CVE-2026-48282, CVE-2026-48316, CVE-2026-48286)
- [TL-2026-1044](https://intel.threadlinqs.com/threat/TL-2026-1044) — CRITICAL — JADEPUFFER: Agentic (LLM-Driven) Ransomware Automating Database Extortion via Langflow RCE (CVE-2025-3248) and Nacos Auth Bypass (CVE-2021-29441)
- [TL-2026-1045](https://intel.threadlinqs.com/threat/TL-2026-1045) — CRITICAL — CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap escape_quotes() Flaw on /accessv2
- [TL-2026-1047](https://intel.threadlinqs.com/threat/TL-2026-1047) — CRITICAL — Cursor IDE "DuneSlide" Sandbox Escape RCE via Zero-Click Prompt Injection (CVE-2026-50548, CVE-2026-50549)
- [TL-2026-1048](https://intel.threadlinqs.com/threat/TL-2026-1048) — CRITICAL — Adobe Patches Nine CVSS 10.0/9.3 Flaws in ColdFusion and Campaign Classic Enabling Arbitrary Code Execution (APSB26-68, APSB26-69)
- [TL-2026-1049](https://intel.threadlinqs.com/threat/TL-2026-1049) — CRITICAL — Critical Cursor AI Code Editor Flaws (CVE-2026-50548, CVE-2026-50549) — "DuneSlide" Zero-Click Prompt Injection to Sandbox Escape and RCE
- [TL-2026-1054](https://intel.threadlinqs.com/threat/TL-2026-1054) — CRITICAL — CVE-2026-46817: Critical Unauthenticated File-Read/Takeover Flaw in Oracle E-Business Suite Payments Exploited Pre-PoC
- [TL-2026-1120](https://intel.threadlinqs.com/threat/TL-2026-1120) — CRITICAL — PolinRider: North Korea-Linked Supply Chain Campaign Expands Across npm, Packagist, Go Modules, and Chrome Extensions
- [TL-2026-1123](https://intel.threadlinqs.com/threat/TL-2026-1123) — CRITICAL — CISA KEV Addition: Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659) Actively Exploited by Storm-2603 / Warlock Ransomware
- [TL-2026-1124](https://intel.threadlinqs.com/threat/TL-2026-1124) — CRITICAL — FortiBleed Credential Theft Campaign: FortigateSniffer Tool Deployed Against 430,000+ FortiGate Firewalls, Linked to INC Ransom and Lynx Ransomware
- [TL-2026-1023](https://intel.threadlinqs.com/threat/TL-2026-1023) — HIGH — Xsolis Data Breach: Targeted Phishing Attack Exposes PHI/PII of 1,396,519 Individuals
- [TL-2026-1024](https://intel.threadlinqs.com/threat/TL-2026-1024) — HIGH — Malicious ClawHub Skills Threaten OpenClaw AI Agent Supply Chain (AMOS, cluw, Solana Front-Running)
- [TL-2026-1027](https://intel.threadlinqs.com/threat/TL-2026-1027) — HIGH — ClickFix Campaigns Evolve API-Driven Payload Delivery: Analysis of 3,000 Live Payloads Reveals New Evasion Techniques
- [TL-2026-1028](https://intel.threadlinqs.com/threat/TL-2026-1028) — HIGH — Microsoft AI-Assisted Investigation Links StealC and Amadey Malware-as-a-Service Operations in RICO Suit (Operation Endgame)
- [TL-2026-1029](https://intel.threadlinqs.com/threat/TL-2026-1029) — HIGH — Amadey: Commodity Loader/Botnet Evolved into RAT — Dominant LockBit 3.0 Loader, Adopted by FSB's Secret Blizzard Against Ukrainian Military
- [TL-2026-1030](https://intel.threadlinqs.com/threat/TL-2026-1030) — HIGH — Lazarus-Linked npm Malware Masquerades as Rollup Polyfills (rollup-packages-polyfill-core, rollup-runtime-polyfill-core, swift-parse-stream, quirky-token, rollup-plugin-polyfill-connect, react-icon-svgs)
- [TL-2026-1031](https://intel.threadlinqs.com/threat/TL-2026-1031) — HIGH — Phantom Squatting: Attackers Register AI-Hallucinated Domains to Hijack LLM-Guided Traffic (Montana Empire / PhantomRaven)
- [TL-2026-1033](https://intel.threadlinqs.com/threat/TL-2026-1033) — HIGH — Operation Endgame Disrupts Amadey Loader and StealC Infostealer Malware-as-a-Service Infrastructure (CVE: N/A)
- [TL-2026-1036](https://intel.threadlinqs.com/threat/TL-2026-1036) — HIGH — ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens Affiliate)
- [TL-2026-1037](https://intel.threadlinqs.com/threat/TL-2026-1037) — HIGH — ARToken Phishing Panel Abuses Microsoft OAuth Device Code Flow to Hijack Microsoft 365 Accounts (EvilTokens PhaaS)
- [TL-2026-1038](https://intel.threadlinqs.com/threat/TL-2026-1038) — HIGH — Mistic Backdoor (MLTBackdoor) Impersonates Microsoft Endpoint Security via DLL Sideloading — Woodgnat/KongTuke Access Broker
- [TL-2026-1040](https://intel.threadlinqs.com/threat/TL-2026-1040) — HIGH — ScreenConnect Masked as Freeware: Large-Scale AsyncRAT Distribution Campaign via SEO-Poisoned Fake Software Sites
- [TL-2026-1041](https://intel.threadlinqs.com/threat/TL-2026-1041) — HIGH — Multiple Fluentd Vulnerabilities: RCE via Tag Placeholder (CVE-2026-44024), Info Disclosure (CVE-2026-44025), Decompression Bomb DoS (CVE-2026-44160), and SSRF (CVE-2026-44161)
- [TL-2026-1042](https://intel.threadlinqs.com/threat/TL-2026-1042) — HIGH — MacSync Stealer v1.1.2 ("claude1"): Malicious Google Ad Impersonates Claude Code Installer to Hijack macOS Systems
- [TL-2026-1046](https://intel.threadlinqs.com/threat/TL-2026-1046) — HIGH — Ousaban (Javali) Banking Trojan Expands Grandoreiro-Linked Tetrade Campaign to Target Iberian Banking Users in Spain and Portugal
- [TL-2026-1050](https://intel.threadlinqs.com/threat/TL-2026-1050) — HIGH — Phantom Squatting: Adversaries Preemptively Register AI-Hallucinated Domains to Hijack Software Supply Chain Trust (Unit 42 "Montana Empire" Case)
- [TL-2026-1055](https://intel.threadlinqs.com/threat/TL-2026-1055) — HIGH — PolinRider Campaign: North Korea-Linked Supply Chain Attack Expands Across npm, Packagist, Go Modules, and Chrome Web Store (DEV#POPPER / OmniStealer)
- [TL-2026-1125](https://intel.threadlinqs.com/threat/TL-2026-1125) — HIGH — ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security Researchers
- [TL-2026-1126](https://intel.threadlinqs.com/threat/TL-2026-1126) — HIGH — Cross-Platform Phishing Campaigns Auto-Adapt Payloads to Victim Device/OS via Fingerprinting
- [TL-2026-1053](https://intel.threadlinqs.com/threat/TL-2026-1053) — HIGH — Schneider Electric Floating License Manager - CVE-2024-2658 Local Privilege Escalation via Uncontrolled Search Path in FlexNet Publisher (update)
- [TL-2026-1032](https://intel.threadlinqs.com/threat/TL-2026-1032) — MEDIUM — Serbian 'Putevi Srbije' Traffic-Fine Smishing Campaign Using Darcula and Phoenix PhaaS Platforms
- [TL-2026-1035](https://intel.threadlinqs.com/threat/TL-2026-1035) — MEDIUM — Browser-Only Ransomware via File System Access API Abuse: LLM-Generated "InfernoGrabber" v9.0 (DeepSeek-Attributed)
- [TL-2026-1043](https://intel.threadlinqs.com/threat/TL-2026-1043) — MEDIUM — Apple 'Hide My Email' Aliases Deanonymizable to Real Email Addresses (Unpatched 1+ Year)
- [TL-2026-1051](https://intel.threadlinqs.com/threat/TL-2026-1051) — MEDIUM — InfernoGrabber v9.0: AI-Generated In-Browser Ransomware Abusing the Chromium File System Access API
- [TL-2026-1052](https://intel.threadlinqs.com/threat/TL-2026-1052) — MEDIUM — VEIL#DROP Campaign Uses Blogger-Hosted Stager to Deliver PureLogs Stealer
- [TL-2026-1039](https://intel.threadlinqs.com/threat/TL-2026-1039) — MODERATE — CVE-2026-55407: Unbounded Heap Allocation DoS in Anthropic's Buffa Rust Protobuf Library (decode_unknown_field)

## Techniques observed

[T1003](https://intel.threadlinqs.com/technique/T1003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1007](https://intel.threadlinqs.com/technique/T1007), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.003](https://intel.threadlinqs.com/technique/T1027.003), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.007](https://intel.threadlinqs.com/technique/T1036.007), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1049](https://intel.threadlinqs.com/technique/T1049), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.003](https://intel.threadlinqs.com/technique/T1053.003), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.012](https://intel.threadlinqs.com/technique/T1055.012), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1056.002](https://intel.threadlinqs.com/technique/T1056.002), [T1056.004](https://intel.threadlinqs.com/technique/T1056.004), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.001, [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.001](https://intel.threadlinqs.com/technique/T1078.001), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.001](https://intel.threadlinqs.com/technique/T1087.001), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1087.004](https://intel.threadlinqs.com/technique/T1087.004), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.001](https://intel.threadlinqs.com/technique/T1098.001), [T1098.005](https://intel.threadlinqs.com/technique/T1098.005), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.001](https://intel.threadlinqs.com/technique/T1110.001), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1114.002](https://intel.threadlinqs.com/technique/T1114.002), [T1114.003](https://intel.threadlinqs.com/technique/T1114.003), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1129](https://intel.threadlinqs.com/technique/T1129), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1202](https://intel.threadlinqs.com/technique/T1202), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1204.004](https://intel.threadlinqs.com/technique/T1204.004), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1213.002](https://intel.threadlinqs.com/technique/T1213.002), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), T1218.004, [T1218.007](https://intel.threadlinqs.com/technique/T1218.007), T1218.009, [T1218.010](https://intel.threadlinqs.com/technique/T1218.010), [T1218.011](https://intel.threadlinqs.com/technique/T1218.011), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1222](https://intel.threadlinqs.com/technique/T1222), [T1222.002](https://intel.threadlinqs.com/technique/T1222.002), [T1480](https://intel.threadlinqs.com/technique/T1480), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1484](https://intel.threadlinqs.com/technique/T1484), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491.001](https://intel.threadlinqs.com/technique/T1491.001), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1538](https://intel.threadlinqs.com/technique/T1538), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546.004](https://intel.threadlinqs.com/technique/T1546.004), T1546.016, [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1547.013](https://intel.threadlinqs.com/technique/T1547.013), T1547.014, [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.002](https://intel.threadlinqs.com/technique/T1552.002), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.001](https://intel.threadlinqs.com/technique/T1555.001), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1558](https://intel.threadlinqs.com/technique/T1558), [T1558.003](https://intel.threadlinqs.com/technique/T1558.003), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1561](https://intel.threadlinqs.com/technique/T1561), T1562, T1562.001, T1562.008, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1569.002](https://intel.threadlinqs.com/technique/T1569.002), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574](https://intel.threadlinqs.com/technique/T1574), T1574.002, [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1584.001](https://intel.threadlinqs.com/technique/T1584.001), [T1584.004](https://intel.threadlinqs.com/technique/T1584.004), [T1584.006](https://intel.threadlinqs.com/technique/T1584.006), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1585.002](https://intel.threadlinqs.com/technique/T1585.002), [T1586](https://intel.threadlinqs.com/technique/T1586), T1586.003, [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.003](https://intel.threadlinqs.com/technique/T1588.003), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.001](https://intel.threadlinqs.com/technique/T1589.001), [T1589.002](https://intel.threadlinqs.com/technique/T1589.002), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1593](https://intel.threadlinqs.com/technique/T1593), T1593.002, [T1594](https://intel.threadlinqs.com/technique/T1594), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1596.005](https://intel.threadlinqs.com/technique/T1596.005), T1597, T1597.002, [T1598](https://intel.threadlinqs.com/technique/T1598), [T1598.003](https://intel.threadlinqs.com/technique/T1598.003), [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1614.001](https://intel.threadlinqs.com/technique/T1614.001), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1622](https://intel.threadlinqs.com/technique/T1622), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657)

## Threat actors

[Amadey](https://intel.threadlinqs.com/actor/Amadey), [Turla - G0010](https://intel.threadlinqs.com/actor/Turla%20-%20G0010), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group), [InCrease](https://intel.threadlinqs.com/actor/InCrease), [EvilTokens](https://intel.threadlinqs.com/actor/EvilTokens), [Woodgnat](https://intel.threadlinqs.com/actor/Woodgnat), [Tetrade](https://intel.threadlinqs.com/actor/Tetrade), [PolinRider](https://intel.threadlinqs.com/actor/PolinRider), [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview), [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603), [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom)

Nation-state attribution: Russia, Iran, North Korea, Russia, North Korea, Russia (loosely associated, unconfirmed for ARToken specifically), Brazil, North Korea (DPRK), China

Threat categories: VULNERABILITY, PHISHING, MALWARE, DATA_BREACH, SUPPLY_CHAIN, RANSOMWARE

## Severity breakdown

- critical: 12
- high: 20
- medium: 5
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 944 (network 203, behavioral 199, file 178, entity 87, malware 80, infrastructure 58, tool 58, package 49, technique 28, vulnerability 4)
- New detection rules: 333 (97% of the day’s threats covered)

## More editions

- Previous: [2026-06-30](https://intel.threadlinqs.com/debrief/2026-06-30)
- Next: [2026-07-02](https://intel.threadlinqs.com/debrief/2026-07-02)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-07-01
