Threadlinqs IntelligenceStart free

Daily debrief · Sunday2026-07-05

Daily Intelligence Briefing — Sunday, July 5, 2026

10 critical15 high3 medium

On 2026-07-05, Threadlinqs published 19 new threat reports and updated 11, 10 rated critical and 15 high, spanning 253 MITRE ATT&CK techniques and 12 named threat actors. Coverage that day added 270 new detection rules and 865 extracted indicators.

New threats
1911 updated
Critical / high
2510 critical · 15 high
ATT&CK techniques
253Observed in the day’s reports
Threat actors
12Named in the reports
Indicators
865Count only · values are Red+
Detection rules
270New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Browser-Only Ransomware (InfernoGrabber v9.0) Abuses Chrome File System Access API to Encrypt Android Photos. AI-Generated Browser-Only Ransomware Abuses Chrome File System Access API (InfernoGrabber 9000 / DeepSeek). Nebula — AI-Integrated Open-Source Penetration Testing Tool (BerylliumSec) — Dual-Use Tool Tracking, No CVE/Active Exploitation.

Highlights

  • TL-2026-1104 — PamStealer: Rust-Based macOS Infostealer Masquerades as Maccy Clipboard Manager, Validates Stolen Passwords via PAM
  • TL-2026-1105 — Bad Epoll (CVE-2026-46242): Use-After-Free Zero-Day in Linux Kernel epoll Subsystem Enables Root Privilege Escalation
  • TL-2026-1106 — "Bad Epoll" Linux Kernel Use-After-Free (CVE-2026-46242) Enables Unprivileged Root Escalation, Impacts Android
  • TL-2026-1107 — ARToken PhaaS Platform Exposes EvilTokens-Affiliated Microsoft 365 Device Code Phishing Toolkit
  • TL-2026-1111 — North Korea-Linked "Contagious Interview"/Famous Chollima Actors Hide JavaScript Loaders (PolinRider) in Open-Source Packages

Theme of the day

  • defense-evasion
  • credential-theft
  • social-engineering
  • data-exfiltration
  • financially-motivated

Threats published

30 threat lines in the 2026-07-05 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

253 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

12 named threat actors across the reports.

Nation-state attribution

  • Russia (affiliate nationals per 2024 DOJ/Operation Cronos indictments; LockBit is a financially motivated criminal RaaS operation, not confirmed state-sponsored)
  • North Korea
  • Russia
  • North Korea (DPRK)
  • China

Threat categories

  • MALWARE
  • RANSOMWARE
  • THREAT_INTEL
  • VULNERABILITY
  • PHISHING
  • SUPPLY_CHAIN

Severity breakdown

  • critical10
  • high15
  • medium3
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

865 indicators of compromise · Red and above. Compare plans
  • behavioral 182
  • file 174
  • network 167
  • tool 109
  • entity 71
  • malware 62
  • infrastructure 56
  • package 32
  • technique 12
270 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans