Threadlinqs IntelligenceStart free

Daily debrief · Saturday2026-07-18

Daily Intelligence Briefing — Saturday, July 18, 2026

13 critical31 high11 medium

On 2026-07-18, Threadlinqs published 34 new threat reports and updated 21, 13 rated critical and 31 high, spanning 335 MITRE ATT&CK techniques and 17 named threat actors. Coverage that day added 495 new detection rules and 1524 extracted indicators.

New threats
3421 updated
Critical / high
4413 critical · 31 high
ATT&CK techniques
335Observed in the day’s reports
Threat actors
17Named in the reports
Indicators
1524Count only · values are Red+
Detection rules
495New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

CrashStealer: Novel macOS Information Stealer Disguised as Apple Crash Reporter (Jamf Threat Labs). OpenSSL "HollowByte" DoS Vulnerability — Memory Exhaustion via Malformed ClientHello (11-Byte Trigger). NanoCore RAT VBScript Loader Using Chr()/Math/Flow-Control Obfuscation to Evade Static Detection (CyberChef Analysis).

Highlights

  • TL-2026-1450 — Contagious Interview (DPRK) Uses SVG Steganography to Deliver OTTERCOOKIE/BEAVERTAIL Malware (REF9403)
  • TL-2026-1472 — xAI Grok Build CLI 0-Day: Trust-Boundary Bypass Chains Enable Arbitrary Code Execution via AGENTS.md/CLAUDE.md Prompt Injection (also affects Claude Code CLI)
  • TL-2026-1473 — Ransomware Attack Suspends Coca-Cola Fairlife U.S. Milk Production
  • TL-2026-1474 — Citrix Secure Access and Endpoint Analysis Client for Windows Privilege Escalation (CVE-2026-53565, CVE-2026-53566)
  • TL-2026-1475 — SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and Google-Masquerading LaunchAgent Backdoor

Theme of the day

  • credential-theft
  • privilege-escalation
  • detection-engineering
  • social-engineering
  • remote-code-execution

Threats published

55 threat lines in the 2026-07-18 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

335 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

17 named threat actors across the reports.

Nation-state attribution

  • Russia
  • North Korea (DPRK)
  • China
  • Iran

Threat categories

  • MALWARE
  • VULNERABILITY
  • THREAT_ACTOR
  • RANSOMWARE
  • PHISHING
  • SUPPLY_CHAIN
  • ESPIONAGE
  • APT

Severity breakdown

  • critical13
  • high31
  • medium11
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

1524 indicators of compromise · Red and above. Compare plans
  • behavioral 364
  • network 358
  • file 267
  • entity 133
  • tool 99
  • infrastructure 87
  • malware 82
  • technique 57
  • package 56
  • vulnerability 21
495 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans