Threadlinqs IntelligenceStart free

Daily debrief · Saturday2026-07-11

Daily Intelligence Briefing — Saturday, July 11, 2026

13 critical30 high3 medium

On 2026-07-11, Threadlinqs published 42 new threat reports and updated 6, 13 rated critical and 30 high, spanning 276 MITRE ATT&CK techniques and 18 named threat actors. Coverage that day added 432 new detection rules and 1169 extracted indicators.

New threats
426 updated
Critical / high
4313 critical · 30 high
ATT&CK techniques
276Observed in the day’s reports
Threat actors
18Named in the reports
Indicators
1169Count only · values are Red+
Detection rules
432New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flash. DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto Fraud Across 236,000+ Domains. Rapid7 Policy Paper 'Modernizing Global Vulnerability Standards' Warns AI-Driven Vulnerability Discovery Is Outpacing CVE/CVSS/NVD Standards.

Highlights

  • TL-2026-1201 — EvilTokens Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication with AES-GCM "Ghost Code" to Breach Finance, Tech, and Managed Security Firms
  • TL-2026-1202 — Forg365: Telegram-Distributed Phishing-as-a-Service Abusing Microsoft Device-Code Flow and AiTM to Hijack Microsoft 365/Entra Sessions
  • TL-2026-1203 — CVE-2026-20251: Splunk Secure Gateway jsonpickle Deserialization RCE with Public PoC
  • TL-2026-1205 — CVE-2025-60727: Microsoft 365 Apps Excel Out-of-Bounds Read Enables Remote Code Execution
  • TL-2026-1207 — StegoAd Campaign: 119 Malicious Microsoft Edge Extensions Deliver Steganographic Malware to 2.6M Users

Theme of the day

Unattributed actors exploited vulnerabilities in government systems and router firmware, posing risks to sensitive information. Access token theft and account takeover were notable tactics used today.

  • credential-theft
  • remote-code-execution
  • cisa-kev
  • financially-motivated
  • supply-chain-attack

Threats published

48 threat lines in the 2026-07-11 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

276 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

18 named threat actors across the reports.

Nation-state attribution

  • China
  • Russia
  • China (suspected, based on tooling/language; unconfirmed)
  • North Korea (DPRK)
  • Belarus
  • RU
  • China / India

Threat categories

  • VULNERABILITY
  • FRAUD
  • THREAT_INTEL
  • PHISHING
  • MALWARE
  • RANSOMWARE
  • THREAT_ACTOR
  • SUPPLY_CHAIN
  • CAMPAIGN
  • DATA_BREACH
  • APT

Severity breakdown

  • critical13
  • high30
  • medium3
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

1169 indicators of compromise · Red and above. Compare plans
  • behavioral 229
  • file 228
  • network 222
  • entity 148
  • tool 83
  • infrastructure 82
  • malware 64
  • package 63
  • technique 34
  • vulnerability 16
432 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans