Threadlinqs IntelligenceStart free

Daily debrief · Tuesday2026-07-14

Daily Intelligence Briefing — Tuesday, July 14, 2026

19 critical33 high6 medium

On 2026-07-14, Threadlinqs published 58 new threat reports, 19 rated critical and 33 high, spanning 295 MITRE ATT&CK techniques and 17 named threat actors. Coverage that day added 522 new detection rules and 1310 extracted indicators.

New threats
5858 threat lines
Critical / high
5219 critical · 33 high
ATT&CK techniques
295Observed in the day’s reports
Threat actors
17Named in the reports
Indicators
1310Count only · values are Red+
Detection rules
522New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise. US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB Center 16 Router Exploitation via CVE-2018-0171/CVE-2008-4128). OFAC Sanctions First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Vendor Yevgeniy Silayev for Enabling Ransomware Attacks on U.S. Critical Infrastructure.

Highlights

  • TL-2026-1288 — Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths (UNC6040/UNC6240/UNC6395/GRUB1/Storm-3138)
  • TL-2026-1289 — ModHeader Chrome/Edge Extension (v7.0.17-7.0.18, 1.6M Installs) Contains Dormant AES-GCM Browsing-History Exfiltration Pipeline to api.stanfordstudies.com
  • TL-2026-1292 — SolidPDFCreator: Mustang Panda Stage-1 Backdoor Targeting India via DLL Side-Loading
  • TL-2026-1293 — npm Supply-Chain Attack on @asyncapi Packages Deploys Miasma Botnet via IPFS-Hosted Second-Stage Payload
  • TL-2026-1294 — Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 Months

Theme of the day

Static Tundra and other nation-state actors drove active threat activity. Multiple new threats were tracked across various threat windows.

  • credential-theft
  • cisa-kev
  • privilege-escalation
  • patch-management
  • remote-code-execution

Threats published

58 threat lines in the 2026-07-14 debrief, most severe first. Each links to its full profile.

Techniques observed

295 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

17 named threat actors across the reports.

Nation-state attribution

  • North Korea, China, Russia, Iran
  • Russia
  • Iran
  • China
  • Pakistan

Threat categories

  • CAMPAIGN
  • THREAT_INTEL
  • OTHER
  • PHISHING
  • DATA_BREACH
  • MALWARE
  • SUPPLY_CHAIN
  • RANSOMWARE
  • VULNERABILITY
  • THREAT_ACTOR
  • ICS_SCADA

Severity breakdown

  • critical19
  • high33
  • medium6
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

1310 indicators of compromise · Red and above. Compare plans
  • behavioral 242
  • entity 222
  • file 202
  • network 145
  • infrastructure 97
  • malware 96
  • technique 94
  • package 87
  • tool 78
  • vulnerability 36
  • financial 11
522 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans