Threadlinqs IntelligenceStart free

Daily debrief · Monday2026-07-13

Daily Intelligence Briefing — Monday, July 13, 2026

6 critical25 high6 medium

On 2026-07-13, Threadlinqs published 38 new threat reports, 6 rated critical and 25 high, spanning 238 MITRE ATT&CK techniques and 18 named threat actors. Coverage that day added 342 new detection rules and 895 extracted indicators.

New threats
3838 threat lines
Critical / high
316 critical · 25 high
ATT&CK techniques
238Observed in the day’s reports
Threat actors
18Named in the reports
Indicators
895Count only · values are Red+
Detection rules
342New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

SnakeKeylogger Infostealer Delivered via Phishing Emails Disguised as Project Proposals (ASEC, JS→PowerShell Fileless Loader). Misconfigured Python HTTP Server Exposes AiTM Phishing Toolkit Behind Three Active Campaigns (codemado, mail-argenta, saroula01). VEXAIoT: Autonomous Multi-Agent LLM Framework Automates End-to-End IoT Vulnerability Discovery and Exploitation (95% Success Rate).

Highlights

  • TL-2026-1249 — APT-C-60 2026 Campaign: SpyGlace Backdoor Delivered via LNK Files and Abused Legitimate Services
  • TL-2026-1251 — Unauthenticated RCE in Motorola MR2600 Wi-Fi Router via Firmware Upload Validation Bypass (related: CVE-2024-23630, CVE-2022-34885)
  • TL-2026-1252 — Remcos RAT Delivered via CVE-2017-0199 Phishing Campaign Impersonating Payment Confirmations
  • TL-2026-1253 — Claude Mythos / Project Glasswing: Autonomous AI Vulnerability Discovery Compresses the Find-to-Exploit Timeline (CVE-2026-4747 and the AI-Scale Disclosure Problem)
  • TL-2026-1257 — UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492)

Theme of the day

  • credential-theft
  • espionage
  • remote-code-execution
  • unauthenticated-rce
  • financially-motivated

Threats published

38 threat lines in the 2026-07-13 debrief, most severe first. Each links to its full profile.

Techniques observed

238 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

18 named threat actors across the reports.

Nation-state attribution

  • South Korea (assessed alignment)
  • China
  • Russia
  • Iran
  • South Korea (suspected origin/alignment)
  • North Korea

Threat categories

  • MALWARE
  • PHISHING
  • TOOL
  • THREAT_ACTOR
  • RECONNAISSANCE
  • THREAT_INTEL
  • VULNERABILITY
  • CAMPAIGN
  • RANSOMWARE
  • DATA_BREACH
  • APT
  • INTRUSION
  • NATION_STATE

Severity breakdown

  • critical6
  • high25
  • medium6
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

895 indicators of compromise · Red and above. Compare plans
  • network 206
  • file 189
  • behavioral 181
  • entity 101
  • malware 65
  • tool 64
  • infrastructure 44
  • technique 20
  • package 19
  • financial 3
  • vulnerability 3
342 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans