Threadlinqs IntelligenceStart free

Daily debrief · Wednesday2026-07-15

Daily Intelligence Briefing — Wednesday, July 15, 2026

16 critical24 high7 medium

On 2026-07-15, Threadlinqs published 47 new threat reports, 16 rated critical and 24 high, spanning 265 MITRE ATT&CK techniques and 13 named threat actors. Coverage that day added 423 new detection rules and 1220 extracted indicators.

New threats
4747 threat lines
Critical / high
4016 critical · 24 high
ATT&CK techniques
265Observed in the day’s reports
Threat actors
13Named in the reports
Indicators
1220Count only · values are Red+
Detection rules
423New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-Day. Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection, Stack Buffer Overflow, and Zip Slip Path Traversal (CVE-2026-52886, CVE-2026-54758, CVE-2026-57233). June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and DLL Sideloading.

Highlights

  • TL-2026-1344 — AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver Fox Overlap)
  • TL-2026-1347 — Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns
  • TL-2026-1349 — CVE-2026-56155: Microsoft AD FS Elevation-of-Privilege Vulnerability Actively Exploited
  • TL-2026-1351 — LegacyHive: Windows 0-Day Allows Standard Users to Load Another User's Registry Hive via User Profile Service
  • TL-2026-1354 — China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations Against Government, Supply-Chain, and Financial Targets

Theme of the day

Active exploitation of multiple vulnerabilities by unattributed actors and APT groups dominates the threat landscape. Ransomware and lateral movement threats are prominent.

  • credential-theft
  • zero-day
  • financially-motivated
  • cisa-kev
  • patch-tuesday

Threats published

47 threat lines in the 2026-07-15 debrief, most severe first. Each links to its full profile.

Techniques observed

265 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

13 named threat actors across the reports.

Nation-state attribution

  • Russia
  • China
  • Iran

Threat categories

  • VULNERABILITY
  • MALWARE
  • THREAT_ACTOR
  • THREAT_INTEL
  • RANSOMWARE
  • APT
  • SUPPLY_CHAIN
  • PHISHING

Severity breakdown

  • critical16
  • high24
  • medium7
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

1220 indicators of compromise · Red and above. Compare plans
  • network 246
  • behavioral 217
  • file 217
  • entity 132
  • infrastructure 91
  • technique 85
  • tool 79
  • package 71
  • malware 67
  • vulnerability 15
423 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans