# Daily Intelligence Briefing — Wednesday, July 15, 2026

> On 2026-07-15, Threadlinqs published 47 new threat reports, 16 rated critical and 24 high, spanning 265 MITRE ATT&CK techniques and 13 named threat actors. Coverage that day added 423 new detection rules and 1220 extracted indicators.

- **Edition:** 2026-07-15 (Wednesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-07-15
- **Last updated:** 2026-07-21
- **New threats:** 47
- **Critical / high:** 16 critical, 24 high, 7 medium, 0 low
- **ATT&CK techniques:** 265
- **Threat actors:** 13
- **Indicators (count only):** 1220
- **New detection rules (count only):** 423

## Summary & highlights

CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-Day. Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection, Stack Buffer Overflow, and Zip Slip Path Traversal (CVE-2026-52886, CVE-2026-54758, CVE-2026-57233). June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and DLL Sideloading.

- [TL-2026-1344](https://intel.threadlinqs.com/threat/TL-2026-1344) — AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver Fox Overlap)
- [TL-2026-1347](https://intel.threadlinqs.com/threat/TL-2026-1347) — Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns
- [TL-2026-1349](https://intel.threadlinqs.com/threat/TL-2026-1349) — CVE-2026-56155: Microsoft AD FS Elevation-of-Privilege Vulnerability Actively Exploited
- [TL-2026-1351](https://intel.threadlinqs.com/threat/TL-2026-1351) — LegacyHive: Windows 0-Day Allows Standard Users to Load Another User's Registry Hive via User Profile Service
- [TL-2026-1354](https://intel.threadlinqs.com/threat/TL-2026-1354) — China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations Against Government, Supply-Chain, and Financial Targets

## Theme of the day

Active exploitation of multiple vulnerabilities by unattributed actors and APT groups dominates the threat landscape. Ransomware and lateral movement threats are prominent.

credential-theft, zero-day, financially-motivated, cisa-kev, patch-tuesday

## Threats published

- [TL-2026-1350](https://intel.threadlinqs.com/threat/TL-2026-1350) — CRITICAL — Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS (CVE-2026-56155) and SharePoint (CVE-2026-56164), Plus Unpatched BitLocker Bypass (CVE-2026-50661)
- [TL-2026-1352](https://intel.threadlinqs.com/threat/TL-2026-1352) — CRITICAL — Malicious NuGet Packages Disguised as Game Cheats Deploy Remote Access Malware (pepesoft.exe)
- [TL-2026-1357](https://intel.threadlinqs.com/threat/TL-2026-1357) — CRITICAL — SonicWall SMA1000 Zero-Day Vulnerabilities (CVE-2026-15409, CVE-2026-15410) Actively Exploited in Tandem
- [TL-2026-1360](https://intel.threadlinqs.com/threat/TL-2026-1360) — CRITICAL — AsyncAPI npm Supply Chain Attack: Pwn-Request GitHub Actions Compromise Deploys Miasma Tasking Framework
- [TL-2026-1361](https://intel.threadlinqs.com/threat/TL-2026-1361) — CRITICAL — CISA Warns of Active Exploitation of Three Microsoft SharePoint Server Vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)
- [TL-2026-1362](https://intel.threadlinqs.com/threat/TL-2026-1362) — CRITICAL — Daxin Returns: China-Linked Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Backdoor
- [TL-2026-1363](https://intel.threadlinqs.com/threat/TL-2026-1363) — CRITICAL — OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter)
- [TL-2026-1368](https://intel.threadlinqs.com/threat/TL-2026-1368) — CRITICAL — Chrome 150 Security Update Fixes 15 Vulnerabilities Including Two Critical Use-After-Free Flaws in Ozone (CVE-2026-15764, CVE-2026-15765)
- [TL-2026-1369](https://intel.threadlinqs.com/threat/TL-2026-1369) — CRITICAL — CVE-2026-56164: Microsoft SharePoint Server Missing-Authentication Vulnerability Actively Exploited, Added to CISA KEV
- [TL-2026-1371](https://intel.threadlinqs.com/threat/TL-2026-1371) — CRITICAL — Dell PowerProtect Data Domain Multiple Vulnerabilities: Improper Authentication (CVE-2026-53483) and Path Traversal (CVE-2026-53481) Allow Full Remote System Access
- [TL-2026-1372](https://intel.threadlinqs.com/threat/TL-2026-1372) — CRITICAL — July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP, CVE-2026-50661 BitLocker Bypass)
- [TL-2026-1378](https://intel.threadlinqs.com/threat/TL-2026-1378) — CRITICAL — CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)
- [TL-2026-1382](https://intel.threadlinqs.com/threat/TL-2026-1382) — CRITICAL — SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth Code Injection, CVSS 7.2) Chained for Root Compromise, Actively Exploited
- [TL-2026-1385](https://intel.threadlinqs.com/threat/TL-2026-1385) — CRITICAL — CVE-2026-15409 / CVE-2026-15410: SonicWall SMA 1000 Zero-Day SSRF and Code Injection Chained for Unauthenticated RCE
- [TL-2026-1390](https://intel.threadlinqs.com/threat/TL-2026-1390) — CRITICAL — SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day Exploitation
- [TL-2026-1391](https://intel.threadlinqs.com/threat/TL-2026-1391) — CRITICAL — F5 Patches Multiple NGINX Vulnerabilities: Heap Overflow, Memory Disclosure, and Use-After-Free (CVE-2026-42533, CVE-2026-60005, CVE-2026-56434)
- [TL-2026-1344](https://intel.threadlinqs.com/threat/TL-2026-1344) — HIGH — AtlasRAT: Four-Stage In-Memory Loader Chain Delivers Commercial RAT via Fake Flash Player Installer (Silver Fox Overlap)
- [TL-2026-1347](https://intel.threadlinqs.com/threat/TL-2026-1347) — HIGH — Check Point 2026 AI Security Report: Autonomous AI-Driven Exploitation, CLAUDE.md Jailbreaking, and Generative Identity Fraud Fuel Scattered Spider / ShinyHunters Campaigns
- [TL-2026-1349](https://intel.threadlinqs.com/threat/TL-2026-1349) — HIGH — CVE-2026-56155: Microsoft AD FS Elevation-of-Privilege Vulnerability Actively Exploited
- [TL-2026-1351](https://intel.threadlinqs.com/threat/TL-2026-1351) — HIGH — LegacyHive: Windows 0-Day Allows Standard Users to Load Another User's Registry Hive via User Profile Service
- [TL-2026-1354](https://intel.threadlinqs.com/threat/TL-2026-1354) — HIGH — China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations Against Government, Supply-Chain, and Financial Targets
- [TL-2026-1355](https://intel.threadlinqs.com/threat/TL-2026-1355) — HIGH — US Indicts Alleged Operators of Media Land Bulletproof Hosting Service Used by LockBit, BlackSuit, and Play Ransomware
- [TL-2026-1358](https://intel.threadlinqs.com/threat/TL-2026-1358) — HIGH — CrashStealer: Notarized Fake Apple CrashReporter App Steals macOS Keychain, Browser, and Crypto Wallet Credentials
- [TL-2026-1364](https://intel.threadlinqs.com/threat/TL-2026-1364) — HIGH — Actively Exploited SharePoint Server Elevation of Privilege Flaw (CVE-2026-56164) Patched Alongside Critical RCE Pair in July 2026 Patch Tuesday
- [TL-2026-1366](https://intel.threadlinqs.com/threat/TL-2026-1366) — HIGH — TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chain
- [TL-2026-1367](https://intel.threadlinqs.com/threat/TL-2026-1367) — HIGH — LabubaRAT: Rust-Based Windows Implant Masquerading as NVIDIA Container Runtime
- [TL-2026-1373](https://intel.threadlinqs.com/threat/TL-2026-1373) — HIGH — LegacyHive: Unpatched Windows User Profile Service (profsvc) Registry Hive Hijack Privilege Escalation 0-Day PoC Released by Nightmare-Eclipse
- [TL-2026-1374](https://intel.threadlinqs.com/threat/TL-2026-1374) — HIGH — 313 Team Iran-Aligned Hacktivists Weaponize Agentic AI, Mirai-Derived Botnets, and Prompt Injection Against E-Commerce APIs (CVE-2025-39391)
- [TL-2026-1375](https://intel.threadlinqs.com/threat/TL-2026-1375) — HIGH — Impersonated GitHub Brand Repositories Distribute BoryptGrab-Lineage Infostealer via DLL Side-Loading (Fake Arctic Wolf + 290+ Brands)
- [TL-2026-1376](https://intel.threadlinqs.com/threat/TL-2026-1376) — HIGH — CVE-2026-3985: Blind SQL Injection in Creative Mail WordPress Plugin, Discovered by Fully Automated AI Exploitation Pipeline
- [TL-2026-1377](https://intel.threadlinqs.com/threat/TL-2026-1377) — HIGH — Unpatched Cursor IDE 0-Day: Malicious git.exe in Repository Root Enables Arbitrary Code Execution on Windows (CWE-427)
- [TL-2026-1379](https://intel.threadlinqs.com/threat/TL-2026-1379) — HIGH — Jscrambler npm Package Compromised: IronWorm Cross-Platform Infostealer (Shai-Hulud Lineage) via Rust Native Binaries
- [TL-2026-1380](https://intel.threadlinqs.com/threat/TL-2026-1380) — HIGH — "PromptFiction" Claude Desktop Auto-Submit Flaw Chained With "Claudy Day" Claude.ai Exploit Chain Enables Silent Exfiltration and, via Filesystem Server MCP, Local RCE
- [TL-2026-1381](https://intel.threadlinqs.com/threat/TL-2026-1381) — HIGH — Compromised @injectivelabs/sdk-ts npm Package (v1.20.21) Exfiltrates Cryptocurrency Wallet Mnemonics and Private Keys via Fake Telemetry
- [TL-2026-1383](https://intel.threadlinqs.com/threat/TL-2026-1383) — HIGH — OkoBot Malware Framework Injects Seed-Phrase Phishing Pages Into Ledger and Trezor Wallet Apps
- [TL-2026-1384](https://intel.threadlinqs.com/threat/TL-2026-1384) — HIGH — MacSync Stealer: 'ClaudeFix' Malvertising Campaign Abuses Shared Claude Chat Links to Deploy macOS Infostealer
- [TL-2026-1387](https://intel.threadlinqs.com/threat/TL-2026-1387) — HIGH — AsyncAPI npm Supply Chain Compromise: Import-Time Payload Delivery via Miasma Loader
- [TL-2026-1388](https://intel.threadlinqs.com/threat/TL-2026-1388) — HIGH — Operation Fake KickOff: Recruiter-Impersonation AitM/BitB Toolkit Abuses Salesforce, SendGrid, Zoho and Render to Harvest Google Workspace Credentials and Bypass MFA
- [TL-2026-1389](https://intel.threadlinqs.com/threat/TL-2026-1389) — HIGH — QuimaRAT v2.0: Cross-Platform Java-Based RAT Sold via Malware-as-a-Service Model
- [TL-2026-1401](https://intel.threadlinqs.com/threat/TL-2026-1401) — HIGH — LabubaRAT: Rust-based RAT Disguised as NVIDIA Container Runtime Toolkit
- [TL-2026-1346](https://intel.threadlinqs.com/threat/TL-2026-1346) — MEDIUM — CVE-2026-50661: Windows BitLocker Security Feature Bypass 0-Day
- [TL-2026-1348](https://intel.threadlinqs.com/threat/TL-2026-1348) — MEDIUM — Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection, Stack Buffer Overflow, and Zip Slip Path Traversal (CVE-2026-52886, CVE-2026-54758, CVE-2026-57233)
- [TL-2026-1353](https://intel.threadlinqs.com/threat/TL-2026-1353) — MEDIUM — June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and DLL Sideloading
- [TL-2026-1356](https://intel.threadlinqs.com/threat/TL-2026-1356) — MEDIUM — "Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaign
- [TL-2026-1359](https://intel.threadlinqs.com/threat/TL-2026-1359) — MEDIUM — Extortion Actor Pivots from Blocked Remote-Access Tool to Fake IT-Support Social Engineering for Data Exfiltration
- [TL-2026-1365](https://intel.threadlinqs.com/threat/TL-2026-1365) — MEDIUM — Sophos State of Ransomware 2026: Payments Drop as Encryption Success Climbs, Identity-Based Attacks Now Dominant Vector
- [TL-2026-1370](https://intel.threadlinqs.com/threat/TL-2026-1370) — MEDIUM — Windows RDP Memory-Disclosure Vulnerabilities (CVE-2026-50445, CVE-2026-57982, CVE-2026-55003, CVE-2026-50497, CVE-2026-57979) — July 2026 Patch Tuesday

## Techniques observed

[T1001](https://intel.threadlinqs.com/technique/T1001), [T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.002](https://intel.threadlinqs.com/technique/T1003.002), T1003.004, [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.001](https://intel.threadlinqs.com/technique/T1036.001), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.008](https://intel.threadlinqs.com/technique/T1036.008), [T1037](https://intel.threadlinqs.com/technique/T1037), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1048.003](https://intel.threadlinqs.com/technique/T1048.003), [T1049](https://intel.threadlinqs.com/technique/T1049), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.003](https://intel.threadlinqs.com/technique/T1053.003), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.001](https://intel.threadlinqs.com/technique/T1055.001), T1055.003, [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1056.002](https://intel.threadlinqs.com/technique/T1056.002), [T1056.004](https://intel.threadlinqs.com/technique/T1056.004), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.002](https://intel.threadlinqs.com/technique/T1059.002), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1069.001](https://intel.threadlinqs.com/technique/T1069.001), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.002, [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1074.001](https://intel.threadlinqs.com/technique/T1074.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.001](https://intel.threadlinqs.com/technique/T1078.001), [T1078.003](https://intel.threadlinqs.com/technique/T1078.003), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.001](https://intel.threadlinqs.com/technique/T1087.001), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1090.004](https://intel.threadlinqs.com/technique/T1090.004), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), T1098.007, [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1104](https://intel.threadlinqs.com/technique/T1104), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.001](https://intel.threadlinqs.com/technique/T1110.001), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1120](https://intel.threadlinqs.com/technique/T1120), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1129](https://intel.threadlinqs.com/technique/T1129), [T1132.002](https://intel.threadlinqs.com/technique/T1132.002), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1134.002](https://intel.threadlinqs.com/technique/T1134.002), T1134.003, [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), T1179, [T1187](https://intel.threadlinqs.com/technique/T1187), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1200](https://intel.threadlinqs.com/technique/T1200), [T1202](https://intel.threadlinqs.com/technique/T1202), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1204.004](https://intel.threadlinqs.com/technique/T1204.004), [T1205](https://intel.threadlinqs.com/technique/T1205), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), T1215, [T1218](https://intel.threadlinqs.com/technique/T1218), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1484](https://intel.threadlinqs.com/technique/T1484), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1491.001](https://intel.threadlinqs.com/technique/T1491.001), [T1491.002](https://intel.threadlinqs.com/technique/T1491.002), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1498](https://intel.threadlinqs.com/technique/T1498), [T1498.001](https://intel.threadlinqs.com/technique/T1498.001), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1499.003](https://intel.threadlinqs.com/technique/T1499.003), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), T1542.001, T1542.005, [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546.004](https://intel.threadlinqs.com/technique/T1546.004), [T1546.015](https://intel.threadlinqs.com/technique/T1546.015), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1547.006](https://intel.threadlinqs.com/technique/T1547.006), T1547.015, [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1550.002](https://intel.threadlinqs.com/technique/T1550.002), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.002](https://intel.threadlinqs.com/technique/T1552.002), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), T1552.006, [T1553](https://intel.threadlinqs.com/technique/T1553), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1553.005](https://intel.threadlinqs.com/technique/T1553.005), [T1553.006](https://intel.threadlinqs.com/technique/T1553.006), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.001](https://intel.threadlinqs.com/technique/T1555.001), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1555.004](https://intel.threadlinqs.com/technique/T1555.004), [T1555.005](https://intel.threadlinqs.com/technique/T1555.005), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1556.006](https://intel.threadlinqs.com/technique/T1556.006), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), [T1561](https://intel.threadlinqs.com/technique/T1561), [T1561.001](https://intel.threadlinqs.com/technique/T1561.001), T1562, T1562.001, T1562.002, T1562.004, T1562.006, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1569.002](https://intel.threadlinqs.com/technique/T1569.002), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), T1574.002, [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.005](https://intel.threadlinqs.com/technique/T1583.005), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1583.008](https://intel.threadlinqs.com/technique/T1583.008), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1584.001](https://intel.threadlinqs.com/technique/T1584.001), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1585.003](https://intel.threadlinqs.com/technique/T1585.003), [T1586](https://intel.threadlinqs.com/technique/T1586), T1586.003, [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.001](https://intel.threadlinqs.com/technique/T1588.001), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.003](https://intel.threadlinqs.com/technique/T1588.003), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1588.007](https://intel.threadlinqs.com/technique/T1588.007), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1590](https://intel.threadlinqs.com/technique/T1590), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1596.005](https://intel.threadlinqs.com/technique/T1596.005), T1597.002, [T1598](https://intel.threadlinqs.com/technique/T1598), [T1598.004](https://intel.threadlinqs.com/technique/T1598.004), [T1601](https://intel.threadlinqs.com/technique/T1601), [T1601.001](https://intel.threadlinqs.com/technique/T1601.001), T1601.002, [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1608.006](https://intel.threadlinqs.com/technique/T1608.006), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1614.001](https://intel.threadlinqs.com/technique/T1614.001), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1648](https://intel.threadlinqs.com/technique/T1648), [T1649](https://intel.threadlinqs.com/technique/T1649), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657), [T1665](https://intel.threadlinqs.com/technique/T1665)

## Threat actors

bandcampro, [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider), [Nightmare-Eclipse](https://intel.threadlinqs.com/actor/Nightmare-Eclipse), [Media Land](https://intel.threadlinqs.com/actor/Media%20Land), Keksec (TuxBot/Kaitori/AISURU operator), [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse), [313 Team](https://intel.threadlinqs.com/actor/313%20Team), pepesoft, [M-Red-Team](https://intel.threadlinqs.com/actor/M-RED-TEAM), [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603), China-linked espionage group, [UTA0533](https://intel.threadlinqs.com/actor/UTA0533)

Nation-state attribution: Russia, China, Iran

Threat categories: VULNERABILITY, MALWARE, THREAT_ACTOR, THREAT_INTEL, RANSOMWARE, APT, SUPPLY_CHAIN, PHISHING

## Severity breakdown

- critical: 16
- high: 24
- medium: 7
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 1220 (network 246, behavioral 217, file 217, entity 132, infrastructure 91, technique 85, tool 79, package 71, malware 67, vulnerability 15)
- New detection rules: 423 (100% of the day’s threats covered)

## More editions

- Previous: [2026-07-14](https://intel.threadlinqs.com/debrief/2026-07-14)
- Next: [2026-07-16](https://intel.threadlinqs.com/debrief/2026-07-16)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-07-15
