# Daily Intelligence Briefing — Tuesday, July 14, 2026

> On 2026-07-14, Threadlinqs published 58 new threat reports, 19 rated critical and 33 high, spanning 295 MITRE ATT&CK techniques and 17 named threat actors. Coverage that day added 522 new detection rules and 1310 extracted indicators.

- **Edition:** 2026-07-14 (Tuesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-07-14
- **Last updated:** 2026-07-17
- **New threats:** 58
- **Critical / high:** 19 critical, 33 high, 6 medium, 0 low
- **ATT&CK techniques:** 295
- **Threat actors:** 17
- **Indicators (count only):** 1310
- **New detection rules (count only):** 522

## Summary & highlights

ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise. US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB Center 16 Router Exploitation via CVE-2018-0171/CVE-2008-4128). OFAC Sanctions First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Vendor Yevgeniy Silayev for Enabling Ransomware Attacks on U.S. Critical Infrastructure.

- [TL-2026-1288](https://intel.threadlinqs.com/threat/TL-2026-1288) — Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths (UNC6040/UNC6240/UNC6395/GRUB1/Storm-3138)
- [TL-2026-1289](https://intel.threadlinqs.com/threat/TL-2026-1289) — ModHeader Chrome/Edge Extension (v7.0.17-7.0.18, 1.6M Installs) Contains Dormant AES-GCM Browsing-History Exfiltration Pipeline to api.stanfordstudies.com
- [TL-2026-1292](https://intel.threadlinqs.com/threat/TL-2026-1292) — SolidPDFCreator: Mustang Panda Stage-1 Backdoor Targeting India via DLL Side-Loading
- [TL-2026-1293](https://intel.threadlinqs.com/threat/TL-2026-1293) — npm Supply-Chain Attack on @asyncapi Packages Deploys Miasma Botnet via IPFS-Hosted Second-Stage Payload
- [TL-2026-1294](https://intel.threadlinqs.com/threat/TL-2026-1294) — Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 Months

## Theme of the day

Static Tundra and other nation-state actors drove active threat activity. Multiple new threats were tracked across various threat windows.

credential-theft, cisa-kev, privilege-escalation, patch-management, remote-code-execution

## Threats published

- [TL-2026-1299](https://intel.threadlinqs.com/threat/TL-2026-1299) — CRITICAL — AsyncAPI npm Supply-Chain Compromise via GitHub Actions Pwn Request Deploys 'M-Red-Team v6.4' / Miasma-Derived Multi-Stage Malware
- [TL-2026-1300](https://intel.threadlinqs.com/threat/TL-2026-1300) — CRITICAL — CVE-2026-48939 & CVE-2026-56291: Perfect-10 Joomla Extension Bugs (iCagenda, Balbooa Forms) Actively Exploited, Added to CISA KEV
- [TL-2026-1302](https://intel.threadlinqs.com/threat/TL-2026-1302) — CRITICAL — SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761)
- [TL-2026-1303](https://intel.threadlinqs.com/threat/TL-2026-1303) — CRITICAL — SAP July 2026 Patch Day: Critical Memory Corruption in NetWeaver ABAP (CVE-2026-44747, CVSS 9.9) Among 16 Security Notes
- [TL-2026-1305](https://intel.threadlinqs.com/threat/TL-2026-1305) — CRITICAL — ServiceNow AI Platform Sandbox Escape Enables Unauthenticated Remote Code Execution (CVE-2026-6875)
- [TL-2026-1312](https://intel.threadlinqs.com/threat/TL-2026-1312) — CRITICAL — FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171) Against Routers
- [TL-2026-1318](https://intel.threadlinqs.com/threat/TL-2026-1318) — CRITICAL — Unpatched Claude for Chrome Extension Flaws Enable Unauthorized Account Actions via Fake Clicks and Permission Bypass
- [TL-2026-1320](https://intel.threadlinqs.com/threat/TL-2026-1320) — CRITICAL — AsyncAPI npm Supply Chain Compromise: GitHub Actions pull_request_target Exploit Deploys Miasma RAT to Packages with 2.9M Weekly Downloads
- [TL-2026-1323](https://intel.threadlinqs.com/threat/TL-2026-1323) — CRITICAL — SonicWall SMA1000 SSRF (CVE-2026-15409) and Code Injection (CVE-2026-15410) Actively Exploited in Tandem
- [TL-2026-1324](https://intel.threadlinqs.com/threat/TL-2026-1324) — CRITICAL — Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation
- [TL-2026-1325](https://intel.threadlinqs.com/threat/TL-2026-1325) — CRITICAL — Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155)
- [TL-2026-1327](https://intel.threadlinqs.com/threat/TL-2026-1327) — CRITICAL — Microsoft July 2026 Patch Tuesday: 569 CVEs, Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP)
- [TL-2026-1328](https://intel.threadlinqs.com/threat/TL-2026-1328) — CRITICAL — Langflow CVE-2025-3248 Unauthenticated RCE Exploited to Build Custom Gafgyt/BASHLITE DDoS Botnet
- [TL-2026-1329](https://intel.threadlinqs.com/threat/TL-2026-1329) — CRITICAL — SAP Patches CVSS 9.9 NetWeaver ABAP Out-of-Bounds Write Flaw (CVE-2026-44747), Plus Critical Approuter and Commerce Cloud Bugs
- [TL-2026-1331](https://intel.threadlinqs.com/threat/TL-2026-1331) — CRITICAL — Microsoft July 2026 Patch Tuesday: Record 622 CVEs Include Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint Server (CVE-2026-56164)
- [TL-2026-1334](https://intel.threadlinqs.com/threat/TL-2026-1334) — CRITICAL — Microsoft July 2026 Patch Tuesday: Record 622 Flaws Fixed, Two Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-56155)
- [TL-2026-1335](https://intel.threadlinqs.com/threat/TL-2026-1335) — CRITICAL — SonicWall SMA1000 SSRF (CVE-2026-15409) and Post-Auth Code Injection (CVE-2026-15410) Exploited as Zero-Days
- [TL-2026-1336](https://intel.threadlinqs.com/threat/TL-2026-1336) — CRITICAL — Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164)
- [TL-2026-1341](https://intel.threadlinqs.com/threat/TL-2026-1341) — CRITICAL — CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (Unpatched Chain Component, PoC Public)
- [TL-2026-1288](https://intel.threadlinqs.com/threat/TL-2026-1288) — HIGH — Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths (UNC6040/UNC6240/UNC6395/GRUB1/Storm-3138)
- [TL-2026-1289](https://intel.threadlinqs.com/threat/TL-2026-1289) — HIGH — ModHeader Chrome/Edge Extension (v7.0.17-7.0.18, 1.6M Installs) Contains Dormant AES-GCM Browsing-History Exfiltration Pipeline to api.stanfordstudies.com
- [TL-2026-1292](https://intel.threadlinqs.com/threat/TL-2026-1292) — HIGH — SolidPDFCreator: Mustang Panda Stage-1 Backdoor Targeting India via DLL Side-Loading
- [TL-2026-1293](https://intel.threadlinqs.com/threat/TL-2026-1293) — HIGH — npm Supply-Chain Attack on @asyncapi Packages Deploys Miasma Botnet via IPFS-Hosted Second-Stage Payload
- [TL-2026-1294](https://intel.threadlinqs.com/threat/TL-2026-1294) — HIGH — Insider Ransomware Negotiators Colluded with BlackCat/ALPHV, Cost Victims $75M+ — DigitalMint's Angelo Martino Sentenced to 70 Months
- [TL-2026-1296](https://intel.threadlinqs.com/threat/TL-2026-1296) — HIGH — 148 Malicious npm Packages ('Lucide Proxy') Disguise as School Wi-Fi Bypass / Tutoring Proxies to Hijack Browsers into a DDoS Botnet
- [TL-2026-1297](https://intel.threadlinqs.com/threat/TL-2026-1297) — HIGH — Operation ShadowRecruit: APT36-Linked SheetAgent RAT Campaign Abuses ControlR RMM and Google Sheets C2 to Target Indian Government Job Seekers
- [TL-2026-1298](https://intel.threadlinqs.com/threat/TL-2026-1298) — HIGH — Forgotten UEFI Shims Undermine Secure Boot (CVE-2026-8863, CVE-2026-10797)
- [TL-2026-1301](https://intel.threadlinqs.com/threat/TL-2026-1301) — HIGH — CVE-2008-4128 — Decades-Old Cisco IOS CSRF Vulnerability Added to CISA KEV After Active Exploitation
- [TL-2026-1304](https://intel.threadlinqs.com/threat/TL-2026-1304) — HIGH — 148 npm Packages Disguised as Student Tutoring Proxies Turn Browsers Into DDoS Botnet (Lucide Proxy)
- [TL-2026-1306](https://intel.threadlinqs.com/threat/TL-2026-1306) — HIGH — New Phishing Kits 'Jalisco' and 'OmegaLord' Bypass MFA on Microsoft 365 Accounts via OAuth Device Code Abuse and Fake PDF-Reader Credential Harvesting
- [TL-2026-1307](https://intel.threadlinqs.com/threat/TL-2026-1307) — HIGH — Cursor AI Code Editor Autorun Flaw Enables Silent Code Execution via Malicious Repositories
- [TL-2026-1308](https://intel.threadlinqs.com/threat/TL-2026-1308) — HIGH — AI-Jailbreak-Enabled C2 Automation: "bandcampro" Used Jailbroken Gemini to Build and Run Botnet in Patriot Bait Fraud Campaign
- [TL-2026-1310](https://intel.threadlinqs.com/threat/TL-2026-1310) — HIGH — Qilin Ransomware Abuses DCSync (MS-DRSR) to Harvest AD Domain Credentials Including KRBTGT
- [TL-2026-1311](https://intel.threadlinqs.com/threat/TL-2026-1311) — HIGH — ShinyHunters/UNC6040 Abuse OAuth Connected-App Approvals for Persistent Salesforce Access
- [TL-2026-1313](https://intel.threadlinqs.com/threat/TL-2026-1313) — HIGH — Turkish Banking & Government-Portal Fraud Ecosystem: 8,400+ Phishing Domains, 6,700+ e-Devlet Lookalikes, and 6,600 Monthly Social Media Scam Ads (Group-IB)
- [TL-2026-1314](https://intel.threadlinqs.com/threat/TL-2026-1314) — HIGH — US/EU/UK Sanction Vitaly Kovalev ("Stern"), Trickbot/Conti Administrator Linked to $300M+ in Ransomware Payments
- [TL-2026-1316](https://intel.threadlinqs.com/threat/TL-2026-1316) — HIGH — US Treasury (OFAC) and UK Sanction First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Seller Yevgeniy Silayev for Enabling Anubis and Sinobi Ransomware Operations
- [TL-2026-1317](https://intel.threadlinqs.com/threat/TL-2026-1317) — HIGH — Progress ShareFile Zero-Day Path Traversal Flaw Forces Storage Zone Controller Shutdown
- [TL-2026-1319](https://intel.threadlinqs.com/threat/TL-2026-1319) — HIGH — FortiSandbox VNC Server Exposure Allows Unauthenticated Access to Scanning VMs (CVE-2026-59835)
- [TL-2026-1321](https://intel.threadlinqs.com/threat/TL-2026-1321) — HIGH — OAuth Client ID Spoofing Enables Stealthy Enumeration and Credential Validation Against Microsoft Entra ID (UNK_pyreq2323 / UNK_OutFlareAZ)
- [TL-2026-1322](https://intel.threadlinqs.com/threat/TL-2026-1322) — HIGH — LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Container Runtime to Backdoor Windows Hosts
- [TL-2026-1326](https://intel.threadlinqs.com/threat/TL-2026-1326) — HIGH — Windows 10 KB5099539 Extended Security Update Patches July 2026 Patch Tuesday Zero-Days — AD FS (CVE-2026-56155), SharePoint (CVE-2026-56164) Exploited; BitLocker (CVE-2026-50661) Publicly Disclosed
- [TL-2026-1330](https://intel.threadlinqs.com/threat/TL-2026-1330) — HIGH — Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Including Two Under Active Exploitation (CVE-2026-56155, CVE-2026-56164)
- [TL-2026-1332](https://intel.threadlinqs.com/threat/TL-2026-1332) — HIGH — The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payouts
- [TL-2026-1333](https://intel.threadlinqs.com/threat/TL-2026-1333) — HIGH — Scattered Spider (G1015): RMM-Based Persistence and Social-Engineering Intrusion Tradecraft
- [TL-2026-1337](https://intel.threadlinqs.com/threat/TL-2026-1337) — HIGH — Unlicensed 6 GHz Wi-Fi Devices (LPI/GVP) Verified to Cause Harmful Interference to Utility Fixed Microwave Links, Threatening Grid SCADA and Public-Safety Communications
- [TL-2026-1338](https://intel.threadlinqs.com/threat/TL-2026-1338) — HIGH — BoryptGrab Infostealer Campaign Abuses ~292 Fake GitHub Repos Impersonating Legitimate Software
- [TL-2026-1339](https://intel.threadlinqs.com/threat/TL-2026-1339) — HIGH — July 2026 Patch Tuesday: Two Actively Exploited Microsoft Zero-Days (SharePoint EoP CVE-2026-56164, AD FS EoP CVE-2026-56155) Plus SharePoint JWT Auth Bypass CVE-2026-55040
- [TL-2026-1340](https://intel.threadlinqs.com/threat/TL-2026-1340) — HIGH — 11-Year-Old Linux UEFI Shim Bootloader Flaws Enable Secure Boot Bypass (CVE-2026-8863, CVE-2026-10797)
- [TL-2026-1342](https://intel.threadlinqs.com/threat/TL-2026-1342) — HIGH — OAuth Client ID Spoofing Enables Silent Credential Validation Against Microsoft Entra ID — UNK_pyreq2323 & UNK_OutFlareAZ
- [TL-2026-1343](https://intel.threadlinqs.com/threat/TL-2026-1343) — HIGH — AtlasRAT: Memory-Only Multi-Stage Loader Chain Disguised as AGE Flash Player
- [TL-2026-1345](https://intel.threadlinqs.com/threat/TL-2026-1345) — HIGH — XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting Linux SSH Servers via SSH Brute-Force
- [TL-2026-1287](https://intel.threadlinqs.com/threat/TL-2026-1287) — MEDIUM — ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise
- [TL-2026-1290](https://intel.threadlinqs.com/threat/TL-2026-1290) — MEDIUM — US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB Center 16 Router Exploitation via CVE-2018-0171/CVE-2008-4128)
- [TL-2026-1291](https://intel.threadlinqs.com/threat/TL-2026-1291) — MEDIUM — OFAC Sanctions First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Vendor Yevgeniy Silayev for Enabling Ransomware Attacks on U.S. Critical Infrastructure
- [TL-2026-1295](https://intel.threadlinqs.com/threat/TL-2026-1295) — MEDIUM — US Treasury Sanctions VPN Provider 1VPNS and Crypter Seller for Enabling Ransomware Operations
- [TL-2026-1309](https://intel.threadlinqs.com/threat/TL-2026-1309) — MEDIUM — Pro-Iran Hacktivist Ecosystem Uses Telegram to Coordinate DDoS, Hack-and-Leak, and Credential-Theft Campaigns (Handala, 313 Team, Cyber Fattah, Dark Storm, Keymous+, and Affiliated Personas)
- [TL-2026-1315](https://intel.threadlinqs.com/threat/TL-2026-1315) — MEDIUM — Phishing Campaign Impersonates LastPass and Bitwarden Security Alerts to Deliver Fake DocuSign Pages

## Techniques observed

T0803, T0804, T0813, T0814, T0815, T0826, T0827, T0829, T0830, T0837, T0856, T0860, T0878, T0880, [T1003](https://intel.threadlinqs.com/technique/T1003), T1003.004, [T1005](https://intel.threadlinqs.com/technique/T1005), T1006, [T1008](https://intel.threadlinqs.com/technique/T1008), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), T1021.007, [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1027.003](https://intel.threadlinqs.com/technique/T1027.003), [T1027.010](https://intel.threadlinqs.com/technique/T1027.010), T1027.011, T1029, [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.001](https://intel.threadlinqs.com/technique/T1036.001), [T1036.004](https://intel.threadlinqs.com/technique/T1036.004), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1048.003](https://intel.threadlinqs.com/technique/T1048.003), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.001](https://intel.threadlinqs.com/technique/T1055.001), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1056.004](https://intel.threadlinqs.com/technique/T1056.004), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), T1059.008, [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1069.003](https://intel.threadlinqs.com/technique/T1069.003), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.001, T1070.002, [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.001](https://intel.threadlinqs.com/technique/T1078.001), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1087.004](https://intel.threadlinqs.com/technique/T1087.004), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1091](https://intel.threadlinqs.com/technique/T1091), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.003](https://intel.threadlinqs.com/technique/T1098.003), T1098.007, [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1104](https://intel.threadlinqs.com/technique/T1104), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.001](https://intel.threadlinqs.com/technique/T1110.001), [T1110.003](https://intel.threadlinqs.com/technique/T1110.003), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114.001](https://intel.threadlinqs.com/technique/T1114.001), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1127](https://intel.threadlinqs.com/technique/T1127), [T1129](https://intel.threadlinqs.com/technique/T1129), [T1132.001](https://intel.threadlinqs.com/technique/T1132.001), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1136.002](https://intel.threadlinqs.com/technique/T1136.002), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1200](https://intel.threadlinqs.com/technique/T1200), T1201, [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1205](https://intel.threadlinqs.com/technique/T1205), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1213.003](https://intel.threadlinqs.com/technique/T1213.003), [T1219](https://intel.threadlinqs.com/technique/T1219), T1219.002, [T1222](https://intel.threadlinqs.com/technique/T1222), [T1417.001](https://intel.threadlinqs.com/technique/T1417.001), [T1418](https://intel.threadlinqs.com/technique/T1418), T1437.001, [T1480](https://intel.threadlinqs.com/technique/T1480), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1484](https://intel.threadlinqs.com/technique/T1484), [T1484.001](https://intel.threadlinqs.com/technique/T1484.001), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1491.002](https://intel.threadlinqs.com/technique/T1491.002), [T1495](https://intel.threadlinqs.com/technique/T1495), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1498](https://intel.threadlinqs.com/technique/T1498), [T1498.001](https://intel.threadlinqs.com/technique/T1498.001), T1498.002, [T1499](https://intel.threadlinqs.com/technique/T1499), [T1499.002](https://intel.threadlinqs.com/technique/T1499.002), [T1499.003](https://intel.threadlinqs.com/technique/T1499.003), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1513](https://intel.threadlinqs.com/technique/T1513), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1525](https://intel.threadlinqs.com/technique/T1525), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1534](https://intel.threadlinqs.com/technique/T1534), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1542](https://intel.threadlinqs.com/technique/T1542), T1542.001, T1542.003, [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1546.015](https://intel.threadlinqs.com/technique/T1546.015), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1547.009](https://intel.threadlinqs.com/technique/T1547.009), [T1548](https://intel.threadlinqs.com/technique/T1548), T1548.004, [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1553.006](https://intel.threadlinqs.com/technique/T1553.006), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1555.005](https://intel.threadlinqs.com/technique/T1555.005), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1557.001](https://intel.threadlinqs.com/technique/T1557.001), [T1558](https://intel.threadlinqs.com/technique/T1558), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), T1562, T1562.001, T1562.004, T1562.008, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1565.002](https://intel.threadlinqs.com/technique/T1565.002), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.003](https://intel.threadlinqs.com/technique/T1566.003), [T1566.004](https://intel.threadlinqs.com/technique/T1566.004), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1569.002](https://intel.threadlinqs.com/technique/T1569.002), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574](https://intel.threadlinqs.com/technique/T1574), T1574.002, [T1580](https://intel.threadlinqs.com/technique/T1580), [T1582](https://intel.threadlinqs.com/technique/T1582), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.005](https://intel.threadlinqs.com/technique/T1583.005), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), T1583.007, [T1584](https://intel.threadlinqs.com/technique/T1584), [T1584.006](https://intel.threadlinqs.com/technique/T1584.006), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1585.002](https://intel.threadlinqs.com/technique/T1585.002), [T1585.003](https://intel.threadlinqs.com/technique/T1585.003), T1586.003, [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.001](https://intel.threadlinqs.com/technique/T1588.001), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.003](https://intel.threadlinqs.com/technique/T1588.003), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.001](https://intel.threadlinqs.com/technique/T1589.001), [T1589.002](https://intel.threadlinqs.com/technique/T1589.002), [T1590](https://intel.threadlinqs.com/technique/T1590), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1592](https://intel.threadlinqs.com/technique/T1592), T1593.002, [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.001](https://intel.threadlinqs.com/technique/T1595.001), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1598.003](https://intel.threadlinqs.com/technique/T1598.003), T1600, [T1601](https://intel.threadlinqs.com/technique/T1601), [T1601.001](https://intel.threadlinqs.com/technique/T1601.001), [T1602](https://intel.threadlinqs.com/technique/T1602), T1602.002, [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1608.006](https://intel.threadlinqs.com/technique/T1608.006), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1614.001](https://intel.threadlinqs.com/technique/T1614.001), T1615, [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), T1623.001, [T1624.001](https://intel.threadlinqs.com/technique/T1624.001), T1630.001, [T1636.003](https://intel.threadlinqs.com/technique/T1636.003), [T1636.004](https://intel.threadlinqs.com/technique/T1636.004), T1641, [T1646](https://intel.threadlinqs.com/technique/T1646), [T1649](https://intel.threadlinqs.com/technique/T1649), [T1655](https://intel.threadlinqs.com/technique/T1655), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657), [T1665](https://intel.threadlinqs.com/technique/T1665), [T1685](https://intel.threadlinqs.com/technique/T1685), T1692

## Threat actors

[FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016), [1VPNS](https://intel.threadlinqs.com/actor/1VPNS), [Handala Hack](https://intel.threadlinqs.com/actor/Handala%20Hack), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters), [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda), [Miasma npm worm operators](https://intel.threadlinqs.com/actor/Miasma%20npm%20worm%20operators), [BlackCat](https://intel.threadlinqs.com/actor/BlackCat), [APT36](https://intel.threadlinqs.com/actor/APT36), bandcampro, [Qilin](https://intel.threadlinqs.com/actor/Qilin), [Vitaly Kovalev](https://intel.threadlinqs.com/actor/Vitaly%20Kovalev), [Anubis Ransomware](https://intel.threadlinqs.com/actor/Anubis%20Ransomware), [UNK_pyreq2323](https://intel.threadlinqs.com/actor/UNK_pyreq2323), [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider), [M-RED-TEAM](https://intel.threadlinqs.com/actor/M-RED-TEAM), [APT27](https://intel.threadlinqs.com/actor/APT27)

Nation-state attribution: North Korea, China, Russia, Iran, Russia, Iran, China, Pakistan

Threat categories: CAMPAIGN, THREAT_INTEL, OTHER, PHISHING, DATA_BREACH, MALWARE, SUPPLY_CHAIN, RANSOMWARE, VULNERABILITY, THREAT_ACTOR, ICS_SCADA

## Severity breakdown

- critical: 19
- high: 33
- medium: 6
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 1310 (behavioral 242, entity 222, file 202, network 145, infrastructure 97, malware 96, technique 94, package 87, tool 78, vulnerability 36, financial 11)
- New detection rules: 522 (100% of the day’s threats covered)

## More editions

- Previous: [2026-07-13](https://intel.threadlinqs.com/debrief/2026-07-13)
- Next: [2026-07-15](https://intel.threadlinqs.com/debrief/2026-07-15)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-07-14
