Threadlinqs IntelligenceStart free

Daily debrief · Friday2026-07-17

Daily Intelligence Briefing — Friday, July 17, 2026

12 critical19 high4 medium

On 2026-07-17, Threadlinqs published 35 new threat reports, 12 rated critical and 19 high, spanning 270 MITRE ATT&CK techniques and 14 named threat actors. Coverage that day added 315 new detection rules and 812 extracted indicators.

New threats
3535 threat lines
Critical / high
3112 critical · 19 high
ATT&CK techniques
270Observed in the day’s reports
Threat actors
14Named in the reports
Indicators
812Count only · values are Red+
Detection rules
315New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Harvard/Meta Study Quantifies AI Voice-Phishing (Vishing) Persuasiveness Gap: 16.5% Compliance, 70.3% Detection, and Profitable Economics for Attackers. Armenia Detains Russian National Aleksandr Ermakov on US Extradition Request Tied to Sodinokibi/REvil Ransomware. HollowByte: OpenSSL Pre-Authentication TLS DoS Flaw Bloats Server Memory With 11-Byte Payload.

Highlights

  • TL-2026-1429 — Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattack
  • TL-2026-1430 — Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days (CVE-2026-56155 AD FS, CVE-2026-56164 SharePoint) Among Record 570+ Fixes
  • TL-2026-1435 — PolinRider DPRK Supply-Chain Campaign: Confirmed GitHub Footprint Grows 6.5x Since March (JADESNOW/Beavertail/InvisibleFerret Loaders, DEV#POPPER & OmniStealer Payloads)
  • TL-2026-1436 — CVE-2026-59208: Cross-Issuer Impersonation in n8n Enterprise Token Exchange
  • TL-2026-1439 — Ransomware Attack Halts Coca-Cola Fairlife U.S. Dairy Production

Theme of the day

Activity centered on 0ktapus, 2fa-reset-fraud, active-directory-federation-services.

  • privilege-escalation
  • remote-code-execution
  • financially-motivated
  • cisa-kev
  • known-exploited-vulnerabilities

Threats published

35 threat lines in the 2026-07-17 debrief, most severe first. Each links to its full profile.

Techniques observed

270 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

14 named threat actors across the reports.

Nation-state attribution

  • Russia
  • North Korea (DPRK)
  • North Korea
  • Iran
  • China

Threat categories

  • THREAT_INTEL
  • THREAT_ACTOR
  • VULNERABILITY
  • SUPPLY_CHAIN
  • RANSOMWARE
  • MALWARE
  • APT

Severity breakdown

  • critical12
  • high19
  • medium4
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

812 indicators of compromise · Red and above. Compare plans
  • behavioral 228
  • entity 116
  • network 98
  • file 84
  • tool 69
  • infrastructure 62
  • package 58
  • malware 45
  • technique 40
  • vulnerability 12
315 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans