Threadlinqs IntelligenceStart free

Daily debrief · Friday2026-07-10

Daily Intelligence Briefing — Friday, July 10, 2026

12 critical31 high8 medium

On 2026-07-10, Threadlinqs published 41 new threat reports and updated 10, 12 rated critical and 31 high, spanning 313 MITRE ATT&CK techniques and 23 named threat actors. Coverage that day added 459 new detection rules and 1301 extracted indicators.

New threats
4110 updated
Critical / high
4312 critical · 31 high
ATT&CK techniques
313Observed in the day’s reports
Threat actors
23Named in the reports
Indicators
1301Count only · values are Red+
Detection rules
459New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

npm 12 Disables Install Scripts, Git Dependencies, and Remote Tarball URLs by Default to Curb Supply-Chain Worms Like Shai-Hulud. HalluSquatting: AI Coding Assistant Hallucinations Weaponized to Deliver Botnet Malware via Fake Package/Tool/Skill Names. Former DigitalMint Ransomware Negotiator Angelo Martino Sentenced to 70 Months for BlackCat/ALPHV Extortion Scheme.

Highlights

  • TL-2026-1157 — RoguePlanet: Microsoft Defender Elevation of Privilege Vulnerability (CVE-2026-50656) Patched
  • TL-2026-1161 — Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise Microsoft 365 Accounts
  • TL-2026-1162 — UNK_MassTraction Exploits Roundcube XSS/Deserialization Flaws (CVE-2024-42009, CVE-2025-49113) to Spy on Academic Researchers
  • TL-2026-1165 — Braintree.Net NuGet Typosquat Uses XOR-Obfuscated WebSocket/HTTPS C2 to Exfiltrate Live Payment Card Data and Merchant Credentials
  • TL-2026-1167 — GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot Sabotage (CyberAv3ngers/Crucio/FlockWiper Lineage)

Theme of the day

  • credential-theft
  • privilege-escalation
  • financially-motivated
  • credential-harvesting
  • data-exfiltration

Threats published

51 threat lines in the 2026-07-10 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

313 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

23 named threat actors across the reports.

Nation-state attribution

  • China
  • Iran (assessed, not confirmed by Microsoft)
  • North Korea
  • Russia
  • Iran

Threat categories

  • SUPPLY_CHAIN
  • VULNERABILITY
  • RANSOMWARE
  • PHISHING
  • CYBERCRIME
  • MALWARE
  • INTRUSION
  • SURVEILLANCE

Severity breakdown

  • critical12
  • high31
  • medium8
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

1301 indicators of compromise · Red and above. Compare plans
  • behavioral 288
  • file 279
  • network 233
  • entity 146
  • tool 92
  • infrastructure 91
  • malware 70
  • technique 50
  • package 37
  • vulnerability 15
459 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans