# Daily Intelligence Briefing — Thursday, July 2, 2026

> On 2026-07-02, Threadlinqs published 40 new threat reports and updated 24, 30 rated critical and 27 high, spanning 302 MITRE ATT&CK techniques and 30 named threat actors. Coverage that day added 586 new detection rules and 1626 extracted indicators.

- **Edition:** 2026-07-02 (Thursday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-07-02
- **Last updated:** 2026-07-06
- **New threats:** 40 (24 updated)
- **Critical / high:** 30 critical, 27 high, 7 medium, 0 low
- **ATT&CK techniques:** 302
- **Threat actors:** 30
- **Indicators (count only):** 1626
- **New detection rules (count only):** 586

## Summary & highlights

Microsoft Teams Impersonation Phishing Campaign Deploys Signed RMM Installers via Fake Meeting Pages (CYFIRMA). WinRAR 7.23 Fixes Heap Overflow in RAR5 Recovery Volume Processing (CVE-2026-14191). ChatGPT File Download Flow Path Traversal / Local File Inclusion (LFI) via Guardrail Bypass Social Engineering.

- [TL-2026-1059](https://intel.threadlinqs.com/threat/TL-2026-1059) — Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play
- [TL-2026-1060](https://intel.threadlinqs.com/threat/TL-2026-1060) — BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege Dominates (CVE-2025-55241, CVE-2025-62557, CVE-2025-62554)
- [TL-2026-1061](https://intel.threadlinqs.com/threat/TL-2026-1061) — CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 Exploitation
- [TL-2026-1062](https://intel.threadlinqs.com/threat/TL-2026-1062) — ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers
- [TL-2026-1065](https://intel.threadlinqs.com/threat/TL-2026-1065) — CVE-2026-45659: Microsoft SharePoint Server Deserialization RCE Added to CISA KEV

## Theme of the day

Activity centered on linux, responsible-disclosure, windows.

credential-theft, active-exploitation, data-exfiltration, remote-code-execution, cisa-kev

## Threats published

- [TL-2026-1056](https://intel.threadlinqs.com/threat/TL-2026-1056) — CRITICAL — FortiBleed Credential-Harvesting Campaign Feeds INC Ransom and Lynx Ransomware-as-a-Service Operations
- [TL-2026-1057](https://intel.threadlinqs.com/threat/TL-2026-1057) — CRITICAL — Multiple Critical Adobe ColdFusion Vulnerabilities (CVE-2026-48276 et al., APSB26-68) Enable Unauthenticated Remote Code Execution
- [TL-2026-1064](https://intel.threadlinqs.com/threat/TL-2026-1064) — CRITICAL — Cisco Catalyst SD-WAN Manager Zero-Day Exploitation Chain (CVE-2026-20245, CVE-2026-20127, CVE-2026-20182)
- [TL-2026-1066](https://intel.threadlinqs.com/threat/TL-2026-1066) — CRITICAL — CVE-2026-45659: Microsoft SharePoint Server Deserialization RCE Actively Exploited, Added to CISA KEV
- [TL-2026-1067](https://intel.threadlinqs.com/threat/TL-2026-1067) — CRITICAL — CVE-2026-8037: Unauthenticated OS Command Injection in Progress Kemp LoadMaster via Uninitialized Heap in escape_quotes() (CVSS 9.6-9.8, Active Exploitation)
- [TL-2026-1073](https://intel.threadlinqs.com/threat/TL-2026-1073) — CRITICAL — CVE-2026-46817: Active Exploitation Against ~950 Internet-Exposed Oracle E-Business Suite Payments Instances
- [TL-2026-1077](https://intel.threadlinqs.com/threat/TL-2026-1077) — CRITICAL — Fake Google/Cloudflare Verification Pages Spread Multiple Malware Families via ClickFix (HijackLoader, StealC, Remus Stealer, Amatera Stealer, CastleLoader, NetSupport RAT, ResiLoader)
- [TL-2026-1078](https://intel.threadlinqs.com/threat/TL-2026-1078) — CRITICAL — CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest Memory Disclosure (CVE-2026-8451) Exploited Within 24 Hours of Disclosure
- [TL-2026-1083](https://intel.threadlinqs.com/threat/TL-2026-1083) — CRITICAL — JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos (CVE-2021-29441)
- [TL-2026-1085](https://intel.threadlinqs.com/threat/TL-2026-1085) — CRITICAL — FortiBleed Credential-Theft Campaign Linked to INC and Lynx Ransomware Operations
- [TL-2026-1086](https://intel.threadlinqs.com/threat/TL-2026-1086) — CRITICAL — Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege Escalation
- [TL-2026-1089](https://intel.threadlinqs.com/threat/TL-2026-1089) — CRITICAL — CVE-2026-46817: Unauthenticated Arbitrary File Read in Oracle E-Business Suite Payments File Transmission Exploited Before Public PoC
- [TL-2026-1090](https://intel.threadlinqs.com/threat/TL-2026-1090) — CRITICAL — FortiBleed Credential-Harvesting Campaign Against 430,000 FortiGate Firewalls Feeds INC Ransom and Lynx Ransomware Operations
- [TL-2026-1091](https://intel.threadlinqs.com/threat/TL-2026-1091) — CRITICAL — Adobe ColdFusion & Campaign Classic Priority 1 Patches for 12 Vulnerabilities Including Six Maximum-Severity RCE Flaws (APSB26-68, APSB26-69)
- [TL-2026-1116](https://intel.threadlinqs.com/threat/TL-2026-1116) — CRITICAL — JADEPUFFER Agentic Ransomware Exploits Langflow CVE-2025-3248 and Nacos CVE-2021-29441 via Base64-Encoded Python Payloads
- [TL-2026-0103](https://intel.threadlinqs.com/threat/TL-2026-0103) — CRITICAL — SmarterMail Dual-CVE Pre-Auth RCE Chain — CVE-2026-23760 Admin Password Reset + CVE-2026-24423 ConnectToHub RCE, CISA KEV, Mass Automated Exploitation, 2-Day Patch Weaponization via .NET Decompiler (update)
- [TL-2026-0139](https://intel.threadlinqs.com/threat/TL-2026-0139) — CRITICAL — Malicious Next.js Repositories — Developer-Targeting C2 Campaign via VSCode Workspace Abuse, Job-Themed Lures, and Staged JavaScript Execution (update)
- [TL-2026-0300](https://intel.threadlinqs.com/threat/TL-2026-0300) — CRITICAL — Axios npm Supply Chain Attack via Malicious plain-crypto-js Dependency (Cross-Platform RAT Dropper) (update)
- [TL-2026-0301](https://intel.threadlinqs.com/threat/TL-2026-0301) — CRITICAL — Axios npm Supply Chain Attack: Cross-Platform RAT Delivery via Compromised Maintainer Credentials (GHSA-fw8c-xr5c-95f9) (update)
- [TL-2026-0303](https://intel.threadlinqs.com/threat/TL-2026-0303) — CRITICAL — Axios NPM Supply Chain Compromise — Cross-Platform RAT via Malicious Transitive Dependency (plain-crypto-js) (update)
- [TL-2026-0312](https://intel.threadlinqs.com/threat/TL-2026-0312) — CRITICAL — F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack Buffer Overflow (CVE-2025-53521) — CISA KEV Active Exploitation by Chinese Nation-State Actor (update)
- [TL-2026-0344](https://intel.threadlinqs.com/threat/TL-2026-0344) — CRITICAL — ChipSoft HiX Healthcare EHR Ransomware Attack — Dutch Hospital Infrastructure Disruption (update)
- [TL-2026-0397](https://intel.threadlinqs.com/threat/TL-2026-0397) — CRITICAL — Axios npm Supply Chain Compromise — Malicious axios@1.14.1 and axios@0.30.4 Inject plain-crypto-js@4.2.1 RAT Dropper (update)
- [TL-2026-0438](https://intel.threadlinqs.com/threat/TL-2026-0438) — CRITICAL — Xinference PyPI Supply Chain Compromise — TeamPCP-Marked Credential Harvester (v2.6.0–2.6.2) (update)
- [TL-2026-0444](https://intel.threadlinqs.com/threat/TL-2026-0444) — CRITICAL — lightning PyPI Package Compromise — Versions 2.6.2 & 2.6.3 Execute Bun-Based JavaScript Credential Stealer on Import (Shai-Hulud-Overlapping) (update)
- [TL-2026-0465](https://intel.threadlinqs.com/threat/TL-2026-0465) — CRITICAL — PAN-OS User-ID Authentication Portal RCE Zero-Day (CVE-2026-0300) — Active Exploitation on PA-Series & VM-Series Firewalls (update)
- [TL-2026-0834](https://intel.threadlinqs.com/threat/TL-2026-0834) — CRITICAL — Mastra npm Supply-Chain Compromise (@mastra/* namespace) via Typosquatted 'easy-day-js' — Multi-Stage Cross-Platform Infostealer (update)
- [TL-2026-0976](https://intel.threadlinqs.com/threat/TL-2026-0976) — CRITICAL — Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data Exfiltration (update)
- [TL-2026-0977](https://intel.threadlinqs.com/threat/TL-2026-0977) — CRITICAL — Mastra NPM Packages Trojanized with Malicious Dependency Injection - 116 Packages Compromised (update)
- [TL-2026-0989](https://intel.threadlinqs.com/threat/TL-2026-0989) — CRITICAL — Dropping Elephant Malware Campaign - China-Themed Loader Chain for Initial Access and Payload Delivery (update)
- [TL-2026-1059](https://intel.threadlinqs.com/threat/TL-2026-1059) — HIGH — Anatsa (TeaBot) Banking Trojan Distributed via Fake "File Horizon Explorer" Document Reader App on Google Play
- [TL-2026-1060](https://intel.threadlinqs.com/threat/TL-2026-1060) — HIGH — BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege Dominates (CVE-2025-55241, CVE-2025-62557, CVE-2025-62554)
- [TL-2026-1061](https://intel.threadlinqs.com/threat/TL-2026-1061) — HIGH — CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 Exploitation
- [TL-2026-1062](https://intel.threadlinqs.com/threat/TL-2026-1062) — HIGH — ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers
- [TL-2026-1065](https://intel.threadlinqs.com/threat/TL-2026-1065) — HIGH — CVE-2026-45659: Microsoft SharePoint Server Deserialization RCE Added to CISA KEV
- [TL-2026-1068](https://intel.threadlinqs.com/threat/TL-2026-1068) — HIGH — CVE-2026-45659: Microsoft SharePoint Deserialization RCE Actively Exploited, Added to CISA KEV
- [TL-2026-1069](https://intel.threadlinqs.com/threat/TL-2026-1069) — HIGH — Multiple JetBrains Product Vulnerabilities: Account Takeover, Privilege Escalation, and RCE Across Hub, YouTrack, IntelliJ IDEA, Kotlin, GoLand, and TeamCity
- [TL-2026-1070](https://intel.threadlinqs.com/threat/TL-2026-1070) — HIGH — CVE-2026-20230: Active Exploitation of Cisco Unified CM WebDialer SSRF Flaw Leading to Root-Level Compromise
- [TL-2026-1071](https://intel.threadlinqs.com/threat/TL-2026-1071) — HIGH — Cisco Catalyst Center Unauthenticated Path Traversal / Arbitrary File Read Vulnerability (CVE-2026-20191)
- [TL-2026-1072](https://intel.threadlinqs.com/threat/TL-2026-1072) — HIGH — ToddyCat-Linked Umbrij Malware Abuses OAuth via 'Shadow Token via Remote Debug' (STRD) to Access Gmail, Drive, Calendar and Contacts
- [TL-2026-1074](https://intel.threadlinqs.com/threat/TL-2026-1074) — HIGH — CVE-2026-45659: Microsoft SharePoint Deserialization RCE Added to CISA KEV Despite 'Exploitation Less Likely' Rating
- [TL-2026-1076](https://intel.threadlinqs.com/threat/TL-2026-1076) — HIGH — AI Compute Hijacking: Stolen Ollama Server Wired Into Autonomous "VAPT" Exploit Pipeline (Sysdig)
- [TL-2026-1079](https://intel.threadlinqs.com/threat/TL-2026-1079) — HIGH — Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian Banks via Phishing PDFs, Fake Tax Portal, and Steganographic VBS Downloader
- [TL-2026-1080](https://intel.threadlinqs.com/threat/TL-2026-1080) — HIGH — Remus Stealer: 64-bit Lumma-Derived Infostealer-as-a-Service with EtherHiding Blockchain C2 and Application-Bound Encryption Bypass
- [TL-2026-1081](https://intel.threadlinqs.com/threat/TL-2026-1081) — HIGH — AsyncRAT Campaign Uses DLL Sideloading and ScreenConnect for Stealthy Remote Access (SEO-Poisoned Fake Installer Sites)
- [TL-2026-1084](https://intel.threadlinqs.com/threat/TL-2026-1084) — HIGH — FBI Seizes NetNut Residential Proxy Platform Tied to Popa Botnet (2M+ Devices) — Alarum Technologies, Kimwolf/Vo1d Convergence
- [TL-2026-1088](https://intel.threadlinqs.com/threat/TL-2026-1088) — HIGH — ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as Dead-Drop C2
- [TL-2026-1092](https://intel.threadlinqs.com/threat/TL-2026-1092) — HIGH — CVE-2026-8451: Memory Overread in Citrix NetScaler ADC/Gateway SAML IdP ('CitrixBleed'-class, CVSS 8.8) — Exploited Within 24 Hours of Disclosure
- [TL-2026-1114](https://intel.threadlinqs.com/threat/TL-2026-1114) — HIGH — AsyncRAT Campaign Abuses TryCloudflare Tunnels and Python Scripts for Malware Delivery (AsyncRAT/VenomRAT/XWorm)
- [TL-2026-0021](https://intel.threadlinqs.com/threat/TL-2026-0021) — HIGH — CVE-2026-21509 - Microsoft Office Security Feature Bypass (CISA KEV) (update)
- [TL-2026-0095](https://intel.threadlinqs.com/threat/TL-2026-0095) — HIGH — NginRAT/CronRAT Server-Side Magecart Campaign — NGINX LD_PRELOAD Process Parasitism, Impossible Cron Date Persistence (February 31st), Fileless Payment Card Skimming, Dropbear SSH C2 Impersonation, Chinese-Nexus eCommerce Targeting (update)
- [TL-2026-0259](https://intel.threadlinqs.com/threat/TL-2026-0259) — HIGH — CanisterWorm npm Supply Chain Compromise — Worm-Enabled Backdoor Across 29+ Packages via Publisher Credential Theft (update)
- [TL-2026-0592](https://intel.threadlinqs.com/threat/TL-2026-0592) — HIGH — ClearFake EtherHiding on BNB Smart Chain Testnet — Smart Contract C2 Delivering SectopRAT + ACRStealer via ClickFix Fake-CAPTCHA (update)
- [TL-2026-0699](https://intel.threadlinqs.com/threat/TL-2026-0699) — HIGH — Magecart Skimmer Abuses Stripe API + Google Tag Manager for Payload Hosting, C2 & Card Exfiltration (update)
- [TL-2026-0822](https://intel.threadlinqs.com/threat/TL-2026-0822) — HIGH — Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers (update)
- [TL-2026-0889](https://intel.threadlinqs.com/threat/TL-2026-0889) — HIGH — Deno-Based Modular RAT & Internal Proxy Delivered via Mailbombing + Microsoft Teams Vishing ("DenoJSEnv") (update)
- [TL-2026-0895](https://intel.threadlinqs.com/threat/TL-2026-0895) — HIGH — FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN Gateways (update)
- [TL-2026-1058](https://intel.threadlinqs.com/threat/TL-2026-1058) — MEDIUM — Microsoft Teams Impersonation Phishing Campaign Deploys Signed RMM Installers via Fake Meeting Pages (CYFIRMA)
- [TL-2026-1063](https://intel.threadlinqs.com/threat/TL-2026-1063) — MEDIUM — WinRAR 7.23 Fixes Heap Overflow in RAR5 Recovery Volume Processing (CVE-2026-14191)
- [TL-2026-1075](https://intel.threadlinqs.com/threat/TL-2026-1075) — MEDIUM — ChatGPT File Download Flow Path Traversal / Local File Inclusion (LFI) via Guardrail Bypass Social Engineering
- [TL-2026-1082](https://intel.threadlinqs.com/threat/TL-2026-1082) — MEDIUM — Fake Interpol Investigation Emails Deliver Custom Ransomware to Small Businesses
- [TL-2026-1087](https://intel.threadlinqs.com/threat/TL-2026-1087) — MEDIUM — Indirect Prompt Injection via Web Content Targets AI Agents (SEO Poisoning + Payment Scam / Typosquat Campaigns)
- [TL-2026-1115](https://intel.threadlinqs.com/threat/TL-2026-1115) — MEDIUM — Claude Cowork Sandbox Escape: RPC Parameter Bypass Enables Root Command Execution
- [TL-2026-0031](https://intel.threadlinqs.com/threat/TL-2026-0031) — MEDIUM — Panera Bread Data Breach - 5.1 Million Accounts Exposed (update)

## Techniques observed

AML.T0031, AML.T0043, AML.T0047, [AML.T0051](https://intel.threadlinqs.com/technique/AML.T0051), [AML.T0051.001](https://intel.threadlinqs.com/technique/AML.T0051.001), [T1001](https://intel.threadlinqs.com/technique/T1001), T1001.001, T1001.002, T1001.003, [T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.001](https://intel.threadlinqs.com/technique/T1003.001), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1010](https://intel.threadlinqs.com/technique/T1010), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1016](https://intel.threadlinqs.com/technique/T1016), T1016.001, [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1021.004](https://intel.threadlinqs.com/technique/T1021.004), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1027.003](https://intel.threadlinqs.com/technique/T1027.003), [T1027.004](https://intel.threadlinqs.com/technique/T1027.004), [T1027.007](https://intel.threadlinqs.com/technique/T1027.007), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1030](https://intel.threadlinqs.com/technique/T1030), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.003](https://intel.threadlinqs.com/technique/T1036.003), [T1036.004](https://intel.threadlinqs.com/technique/T1036.004), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.008](https://intel.threadlinqs.com/technique/T1036.008), [T1037](https://intel.threadlinqs.com/technique/T1037), [T1039](https://intel.threadlinqs.com/technique/T1039), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1049](https://intel.threadlinqs.com/technique/T1049), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.003](https://intel.threadlinqs.com/technique/T1053.003), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.001](https://intel.threadlinqs.com/technique/T1055.001), T1055.003, [T1055.012](https://intel.threadlinqs.com/technique/T1055.012), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1056.002](https://intel.threadlinqs.com/technique/T1056.002), [T1056.003](https://intel.threadlinqs.com/technique/T1056.003), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.002](https://intel.threadlinqs.com/technique/T1059.002), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1069.002](https://intel.threadlinqs.com/technique/T1069.002), [T1069.003](https://intel.threadlinqs.com/technique/T1069.003), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.001, T1070.002, [T1070.003](https://intel.threadlinqs.com/technique/T1070.003), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1070.006](https://intel.threadlinqs.com/technique/T1070.006), T1070.007, [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1072](https://intel.threadlinqs.com/technique/T1072), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1074.001](https://intel.threadlinqs.com/technique/T1074.001), T1074.002, [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.003](https://intel.threadlinqs.com/technique/T1078.003), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.001](https://intel.threadlinqs.com/technique/T1087.001), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1087.004](https://intel.threadlinqs.com/technique/T1087.004), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1090.004](https://intel.threadlinqs.com/technique/T1090.004), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.003](https://intel.threadlinqs.com/technique/T1098.003), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.002](https://intel.threadlinqs.com/technique/T1110.002), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1114.001](https://intel.threadlinqs.com/technique/T1114.001), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1120](https://intel.threadlinqs.com/technique/T1120), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1127](https://intel.threadlinqs.com/technique/T1127), [T1129](https://intel.threadlinqs.com/technique/T1129), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1132.001](https://intel.threadlinqs.com/technique/T1132.001), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1136.002](https://intel.threadlinqs.com/technique/T1136.002), [T1137](https://intel.threadlinqs.com/technique/T1137), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1204.003](https://intel.threadlinqs.com/technique/T1204.003), [T1204.004](https://intel.threadlinqs.com/technique/T1204.004), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1218.007](https://intel.threadlinqs.com/technique/T1218.007), [T1218.011](https://intel.threadlinqs.com/technique/T1218.011), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1406](https://intel.threadlinqs.com/technique/T1406), [T1407](https://intel.threadlinqs.com/technique/T1407), T1411, [T1417](https://intel.threadlinqs.com/technique/T1417), [T1418](https://intel.threadlinqs.com/technique/T1418), [T1426](https://intel.threadlinqs.com/technique/T1426), [T1437](https://intel.threadlinqs.com/technique/T1437), T1472, T1475, T1476, [T1480](https://intel.threadlinqs.com/technique/T1480), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1484.001](https://intel.threadlinqs.com/technique/T1484.001), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1491.001](https://intel.threadlinqs.com/technique/T1491.001), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), T1497.002, [T1498](https://intel.threadlinqs.com/technique/T1498), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), T1505.004, T1509, [T1513](https://intel.threadlinqs.com/technique/T1513), [T1516](https://intel.threadlinqs.com/technique/T1516), [T1517](https://intel.threadlinqs.com/technique/T1517), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1521](https://intel.threadlinqs.com/technique/T1521), T1523, [T1525](https://intel.threadlinqs.com/technique/T1525), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1533](https://intel.threadlinqs.com/technique/T1533), [T1534](https://intel.threadlinqs.com/technique/T1534), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1541](https://intel.threadlinqs.com/technique/T1541), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1546.015](https://intel.threadlinqs.com/technique/T1546.015), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1550.002](https://intel.threadlinqs.com/technique/T1550.002), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1552.007](https://intel.threadlinqs.com/technique/T1552.007), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1556.006](https://intel.threadlinqs.com/technique/T1556.006), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1558](https://intel.threadlinqs.com/technique/T1558), [T1559](https://intel.threadlinqs.com/technique/T1559), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), [T1561](https://intel.threadlinqs.com/technique/T1561), T1562, T1562.001, T1562.008, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1564.003](https://intel.threadlinqs.com/technique/T1564.003), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1568.002](https://intel.threadlinqs.com/technique/T1568.002), T1568.003, [T1569](https://intel.threadlinqs.com/technique/T1569), [T1569.002](https://intel.threadlinqs.com/technique/T1569.002), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), [T1574](https://intel.threadlinqs.com/technique/T1574), T1574.002, T1574.005, [T1574.006](https://intel.threadlinqs.com/technique/T1574.006), [T1578](https://intel.threadlinqs.com/technique/T1578), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1584.004](https://intel.threadlinqs.com/technique/T1584.004), [T1584.006](https://intel.threadlinqs.com/technique/T1584.006), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.001](https://intel.threadlinqs.com/technique/T1588.001), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.003](https://intel.threadlinqs.com/technique/T1588.003), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1590](https://intel.threadlinqs.com/technique/T1590), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.001](https://intel.threadlinqs.com/technique/T1595.001), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1596.005](https://intel.threadlinqs.com/technique/T1596.005), [T1602](https://intel.threadlinqs.com/technique/T1602), [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1608.002](https://intel.threadlinqs.com/technique/T1608.002), [T1608.006](https://intel.threadlinqs.com/technique/T1608.006), [T1610](https://intel.threadlinqs.com/technique/T1610), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1614.001](https://intel.threadlinqs.com/technique/T1614.001), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1622](https://intel.threadlinqs.com/technique/T1622), [T1624](https://intel.threadlinqs.com/technique/T1624), [T1626](https://intel.threadlinqs.com/technique/T1626), [T1629](https://intel.threadlinqs.com/technique/T1629), T1633, [T1636](https://intel.threadlinqs.com/technique/T1636), [T1655](https://intel.threadlinqs.com/technique/T1655), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657)

## Threat actors

independent operator, [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603), [ToddyCat](https://intel.threadlinqs.com/actor/ToddyCat), [Tetrade](https://intel.threadlinqs.com/actor/Tetrade), [REMUS MaaS operator](https://intel.threadlinqs.com/actor/REMUS%20MaaS%20operator), [NetNut](https://intel.threadlinqs.com/actor/NetNut), not attributed to a named APT), [FortiBleed IAB](https://intel.threadlinqs.com/actor/FortiBleed%20IAB), [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616), [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER), [FortiBleed Operator](https://intel.threadlinqs.com/actor/FortiBleed%20operator), [Anubis](https://intel.threadlinqs.com/actor/Anubis), [FortiBleed IAB Crew](https://intel.threadlinqs.com/actor/FortiBleed%20IAB%20Crew), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters), [APT28](https://intel.threadlinqs.com/actor/APT28), [Magecart](https://intel.threadlinqs.com/actor/Magecart), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP), [UNC5142](https://intel.threadlinqs.com/actor/UNC5142), [Vanilla Tempest](https://intel.threadlinqs.com/actor/Vanilla%20Tempest), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater), [INC Ransom](https://intel.threadlinqs.com/actor/INC%20Ransom), [Warlock](https://intel.threadlinqs.com/actor/Warlock), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview), [UNC1069](https://intel.threadlinqs.com/actor/UNC1069), [UNC5221](https://intel.threadlinqs.com/actor/UNC5221), [Embargo](https://intel.threadlinqs.com/actor/Embargo), [CL-STA-1132](https://intel.threadlinqs.com/actor/CL-STA-1132), [APT38](https://intel.threadlinqs.com/actor/APT38), [Icarus](https://intel.threadlinqs.com/actor/Icarus), [Patchwork](https://intel.threadlinqs.com/actor/Patchwork)

Nation-state attribution: China, India (assessed, residential-ISP origin), Brazil, Russia, Iran, North Korea, India

Threat categories: PHISHING, VULNERABILITY, RANSOMWARE, THREAT_INTEL, MALWARE, APT, BOTNET, DATA_BREACH, SUPPLY_CHAIN, ZERO_DAY

## Severity breakdown

- critical: 30
- high: 27
- medium: 7
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 1626 (behavioral 413, network 350, file 306, entity 109, tool 91, infrastructure 86, technique 84, package 74, malware 65, host 26, vulnerability 22)
- New detection rules: 586 (100% of the day’s threats covered)

## More editions

- Previous: [2026-07-01](https://intel.threadlinqs.com/debrief/2026-07-01)
- Next: [2026-07-05](https://intel.threadlinqs.com/debrief/2026-07-05)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-07-02
