Threadlinqs IntelligenceStart free

Daily debrief · Thursday2026-07-02

Daily Intelligence Briefing — Thursday, July 2, 2026

30 critical27 high7 medium

On 2026-07-02, Threadlinqs published 40 new threat reports and updated 24, 30 rated critical and 27 high, spanning 302 MITRE ATT&CK techniques and 30 named threat actors. Coverage that day added 586 new detection rules and 1626 extracted indicators.

New threats
4024 updated
Critical / high
5730 critical · 27 high
ATT&CK techniques
302Observed in the day’s reports
Threat actors
30Named in the reports
Indicators
1626Count only · values are Red+
Detection rules
586New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Microsoft Teams Impersonation Phishing Campaign Deploys Signed RMM Installers via Fake Meeting Pages (CYFIRMA). WinRAR 7.23 Fixes Heap Overflow in RAR5 Recovery Volume Processing (CVE-2026-14191). ChatGPT File Download Flow Path Traversal / Local File Inclusion (LFI) via Guardrail Bypass Social Engineering.

Highlights

  • TL-2026-1059 — Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play
  • TL-2026-1060 — BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege Dominates (CVE-2025-55241, CVE-2025-62557, CVE-2025-62554)
  • TL-2026-1061 — CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 Exploitation
  • TL-2026-1062 — ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers
  • TL-2026-1065 — CVE-2026-45659: Microsoft SharePoint Server Deserialization RCE Added to CISA KEV

Theme of the day

Activity centered on linux, responsible-disclosure, windows.

  • credential-theft
  • active-exploitation
  • data-exfiltration
  • remote-code-execution
  • cisa-kev

Threats published

64 threat lines in the 2026-07-02 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

302 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

30 named threat actors across the reports.

Nation-state attribution

  • China
  • India (assessed, residential-ISP origin)
  • Brazil
  • Russia
  • Iran
  • North Korea
  • India

Threat categories

  • PHISHING
  • VULNERABILITY
  • RANSOMWARE
  • THREAT_INTEL
  • MALWARE
  • APT
  • BOTNET
  • DATA_BREACH
  • SUPPLY_CHAIN
  • ZERO_DAY

Severity breakdown

  • critical30
  • high27
  • medium7
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

1626 indicators of compromise · Red and above. Compare plans
  • behavioral 413
  • network 350
  • file 306
  • entity 109
  • tool 91
  • infrastructure 86
  • technique 84
  • package 74
  • malware 65
  • host 26
  • vulnerability 22
586 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans