# Daily Intelligence Briefing — Saturday, July 18, 2026

> On 2026-07-18, Threadlinqs published 34 new threat reports and updated 21, 13 rated critical and 31 high, spanning 335 MITRE ATT&CK techniques and 17 named threat actors. Coverage that day added 495 new detection rules and 1524 extracted indicators.

- **Edition:** 2026-07-18 (Saturday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-07-18
- **Last updated:** 2026-07-24
- **New threats:** 34 (21 updated)
- **Critical / high:** 13 critical, 31 high, 11 medium, 0 low
- **ATT&CK techniques:** 335
- **Threat actors:** 17
- **Indicators (count only):** 1524
- **New detection rules (count only):** 495

## Summary & highlights

CrashStealer: Novel macOS Information Stealer Disguised as Apple Crash Reporter (Jamf Threat Labs). OpenSSL "HollowByte" DoS Vulnerability — Memory Exhaustion via Malformed ClientHello (11-Byte Trigger). NanoCore RAT VBScript Loader Using Chr()/Math/Flow-Control Obfuscation to Evade Static Detection (CyberChef Analysis).

- [TL-2026-1450](https://intel.threadlinqs.com/threat/TL-2026-1450) — Contagious Interview (DPRK) Uses SVG Steganography to Deliver OTTERCOOKIE/BEAVERTAIL Malware (REF9403)
- [TL-2026-1472](https://intel.threadlinqs.com/threat/TL-2026-1472) — xAI Grok Build CLI 0-Day: Trust-Boundary Bypass Chains Enable Arbitrary Code Execution via AGENTS.md/CLAUDE.md Prompt Injection (also affects Claude Code CLI)
- [TL-2026-1473](https://intel.threadlinqs.com/threat/TL-2026-1473) — Ransomware Attack Suspends Coca-Cola Fairlife U.S. Milk Production
- [TL-2026-1474](https://intel.threadlinqs.com/threat/TL-2026-1474) — Citrix Secure Access and Endpoint Analysis Client for Windows Privilege Escalation (CVE-2026-53565, CVE-2026-53566)
- [TL-2026-1475](https://intel.threadlinqs.com/threat/TL-2026-1475) — SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and Google-Masquerading LaunchAgent Backdoor

## Theme of the day

credential-theft, privilege-escalation, detection-engineering, social-engineering, remote-code-execution

## Threats published

- [TL-2026-1465](https://intel.threadlinqs.com/threat/TL-2026-1465) — CRITICAL — wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch Released
- [TL-2026-1481](https://intel.threadlinqs.com/threat/TL-2026-1481) — CRITICAL — Spirals Ransomware — New Rust-Based Family Breaches Internet-Facing IIS Server, Encrypts Entire Domain Within 24 Hours
- [TL-2026-0205](https://intel.threadlinqs.com/threat/TL-2026-0205) — CRITICAL — FortiGate SSO Authentication Bypass Campaign (CVE-2025-59718, CVE-2025-59719, CVE-2026-24858) (update)
- [TL-2026-1117](https://intel.threadlinqs.com/threat/TL-2026-1117) — CRITICAL — JADEPUFFER: AI Agent Exploits Langflow RCE (CVE-2025-3248) to Automate Database Ransomware/Extortion Attack (update)
- [TL-2026-1159](https://intel.threadlinqs.com/threat/TL-2026-1159) — CRITICAL — CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0) (update)
- [TL-2026-1325](https://intel.threadlinqs.com/threat/TL-2026-1325) — CRITICAL — Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155) (update)
- [TL-2026-1336](https://intel.threadlinqs.com/threat/TL-2026-1336) — CRITICAL — Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164) (update)
- [TL-2026-1395](https://intel.threadlinqs.com/threat/TL-2026-1395) — CRITICAL — CISA Adds CVE-2026-46817 (Oracle E-Business Suite Payments Unauthenticated Takeover) and CVE-2023-4346 (KNX Protocol Account-Lockout) to KEV Catalog (update)
- [TL-2026-1403](https://intel.threadlinqs.com/threat/TL-2026-1403) — CRITICAL — Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM (APSB26-68/73/74), and VMware Avi Load Balancer (VMSA-2026-0005) (update)
- [TL-2026-1405](https://intel.threadlinqs.com/threat/TL-2026-1405) — CRITICAL — Zoom Patches Critical Windows Client Flaw (CVE-2026-53412, CVSS 9.8) Enabling Unauthenticated Account Takeover (update)
- [TL-2026-1432](https://intel.threadlinqs.com/threat/TL-2026-1432) — CRITICAL — CISA KEV: Fortinet FortiSandbox OS Command Injection Vulnerabilities Exploited (CVE-2026-39808, CVE-2026-25089) (update)
- [TL-2026-1434](https://intel.threadlinqs.com/threat/TL-2026-1434) — CRITICAL — CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalog (update)
- [TL-2026-1493](https://intel.threadlinqs.com/threat/TL-2026-1493) — CRITICAL — CVE-2026-7473: Arista EOS Tunnel Decapsulation Protocol-Confusion Bypass — No Vendor Patch, Actively Exploited (update)
- [TL-2026-1450](https://intel.threadlinqs.com/threat/TL-2026-1450) — HIGH — Contagious Interview (DPRK) Uses SVG Steganography to Deliver OTTERCOOKIE/BEAVERTAIL Malware (REF9403)
- [TL-2026-1472](https://intel.threadlinqs.com/threat/TL-2026-1472) — HIGH — xAI Grok Build CLI 0-Day: Trust-Boundary Bypass Chains Enable Arbitrary Code Execution via AGENTS.md/CLAUDE.md Prompt Injection (also affects Claude Code CLI)
- [TL-2026-1473](https://intel.threadlinqs.com/threat/TL-2026-1473) — HIGH — Ransomware Attack Suspends Coca-Cola Fairlife U.S. Milk Production
- [TL-2026-1474](https://intel.threadlinqs.com/threat/TL-2026-1474) — HIGH — Citrix Secure Access and Endpoint Analysis Client for Windows Privilege Escalation (CVE-2026-53565, CVE-2026-53566)
- [TL-2026-1475](https://intel.threadlinqs.com/threat/TL-2026-1475) — HIGH — SHub Stealer "Reaper" — macOS Infostealer Using applescript:// URL-Scheme Delivery, Filegrabber Module, and Google-Masquerading LaunchAgent Backdoor
- [TL-2026-1476](https://intel.threadlinqs.com/threat/TL-2026-1476) — HIGH — Ransomware Negotiation Tactics: ShinyHunters/Scattered LAPSUS$ Hunters Instructure Canvas Breach (280M Records, May 2026) and Historical Ragnar Locker (CWT Global) / NetWalker (UCSF) Extortion Payments
- [TL-2026-1477](https://intel.threadlinqs.com/threat/TL-2026-1477) — HIGH — IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499 "GhostLock") Demonstrated Against Android 17
- [TL-2026-1478](https://intel.threadlinqs.com/threat/TL-2026-1478) — HIGH — RedWing: Android Malware-as-a-Service Spyware Operation Targeting Russian Financial Institutions
- [TL-2026-1479](https://intel.threadlinqs.com/threat/TL-2026-1479) — HIGH — Massive Smishing Campaign Abuses Gemini AI to Target Mobile Users with Fake Toll and Delivery Texts (Outsider Enterprise / Google v. Does 1-25)
- [TL-2026-1483](https://intel.threadlinqs.com/threat/TL-2026-1483) — HIGH — Latrodectus Phishing Campaign Delivering LummaStealer via 302-Redirect Domain Infrastructure (lufyfeo\[.\]org, 36-domain cluster)
- [TL-2026-1489](https://intel.threadlinqs.com/threat/TL-2026-1489) — HIGH — Daxin Rootkit Resurfaces After 13 Years: China-Linked Kernel Backdoor Found Alongside New Pre-Auth 'Stupig' DLL on Taiwan Manufacturer's Network
- [TL-2026-1491](https://intel.threadlinqs.com/threat/TL-2026-1491) — HIGH — "Download Pumping" — npm Supply-Chain Trust-Signal Abuse via Mass Version Uploads (ambar-src / reverse_ssh / Apfell)
- [TL-2026-1492](https://intel.threadlinqs.com/threat/TL-2026-1492) — HIGH — Device Code Phishing Campaign Targets Microsoft 365 via OAuth Device Authorization Grant Abuse
- [TL-2026-1495](https://intel.threadlinqs.com/threat/TL-2026-1495) — HIGH — Google Sites Phishing Campaign Delivers AMOS-Variant macOS Stealer (unix32385485) to Web3 Users
- [TL-2026-1496](https://intel.threadlinqs.com/threat/TL-2026-1496) — HIGH — Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2 Campaign
- [TL-2026-1497](https://intel.threadlinqs.com/threat/TL-2026-1497) — HIGH — Forest Blizzard (Russian GRU Unit 26165) SOHO Router DNS-Hijacking Campaign Enables AitM Credential Theft Against Outlook Web Access — Operation Masquerade
- [TL-2026-1498](https://intel.threadlinqs.com/threat/TL-2026-1498) — HIGH — Atomic Arch: Supply Chain Attack on 1,619 Arch Linux AUR Packages Deploys Rust Infostealer and eBPF Rootkit
- [TL-2026-1501](https://intel.threadlinqs.com/threat/TL-2026-1501) — HIGH — Multiple Vulnerabilities in Google Chrome Enable Remote Code Execution and Information Disclosure (CVE-2026-15899 through CVE-2026-15905)
- [TL-2026-1502](https://intel.threadlinqs.com/threat/TL-2026-1502) — HIGH — LegacyHive: Public PoC for Unpatched Windows User Profile Service (ProfSvc) Arbitrary Hive Load Elevation of Privilege (No CVE Assigned)
- [TL-2026-1503](https://intel.threadlinqs.com/threat/TL-2026-1503) — HIGH — F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)
- [TL-2026-1504](https://intel.threadlinqs.com/threat/TL-2026-1504) — HIGH — CVE-2026-46215: Linux Kernel DRM GEM_CHANGE_HANDLE Use-After-Free Local Root Privilege Escalation
- [TL-2026-0336](https://intel.threadlinqs.com/threat/TL-2026-0336) — HIGH — Atomic Stealer (AMOS) macOS Campaign via ClickFix Script Editor Abuse (update)
- [TL-2026-0526](https://intel.threadlinqs.com/threat/TL-2026-0526) — HIGH — SHub Reaper - macOS Stealer Variant Bypasses Tahoe 26.4 Terminal Mitigation via applescript:// URL Scheme, Spoofs Apple/Google/Microsoft (SentinelOne) (update)
- [TL-2026-0724](https://intel.threadlinqs.com/threat/TL-2026-0724) — HIGH — DriveSurge: Initial Access Broker Hijacks Thousands of Trusted Websites for ClickFix and FakeUpdate Malware Delivery via zTDS (update)
- [TL-2026-1200](https://intel.threadlinqs.com/threat/TL-2026-1200) — HIGH — Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flash (update)
- [TL-2026-1277](https://intel.threadlinqs.com/threat/TL-2026-1277) — HIGH — Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint NSA/FBI/13-Nation Advisory (update)
- [TL-2026-1354](https://intel.threadlinqs.com/threat/TL-2026-1354) — HIGH — China-Linked Threat Actor Integrates Claude Code and DeepSeek-v4-pro into Active Espionage Operations Against Government, Supply-Chain, and Financial Targets (update)
- [TL-2026-1366](https://intel.threadlinqs.com/threat/TL-2026-1366) — HIGH — TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chain (update)
- [TL-2026-1411](https://intel.threadlinqs.com/threat/TL-2026-1411) — HIGH — UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and Bespoke WLDR C2 Implant (update)
- [TL-2026-1455](https://intel.threadlinqs.com/threat/TL-2026-1455) — HIGH — NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for Credentials and MCP Tool Access (update)
- [TL-2026-1494](https://intel.threadlinqs.com/threat/TL-2026-1494) — HIGH — macOS Info-Stealer Chains Fake Password Prompt, Telegram Session Theft, and Crypto Wallet App Replacement (update)
- [TL-2026-1470](https://intel.threadlinqs.com/threat/TL-2026-1470) — MEDIUM — CrashStealer: Novel macOS Information Stealer Disguised as Apple Crash Reporter (Jamf Threat Labs)
- [TL-2026-1471](https://intel.threadlinqs.com/threat/TL-2026-1471) — MEDIUM — OpenSSL "HollowByte" DoS Vulnerability — Memory Exhaustion via Malformed ClientHello (11-Byte Trigger)
- [TL-2026-1480](https://intel.threadlinqs.com/threat/TL-2026-1480) — MEDIUM — NanoCore RAT VBScript Loader Using Chr()/Math/Flow-Control Obfuscation to Evade Static Detection (CyberChef Analysis)
- [TL-2026-1482](https://intel.threadlinqs.com/threat/TL-2026-1482) — MEDIUM — HTA-Based Cobalt Strike Downloader Script Analysis (CyberChef Deobfuscation)
- [TL-2026-1484](https://intel.threadlinqs.com/threat/TL-2026-1484) — MEDIUM — Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains
- [TL-2026-1485](https://intel.threadlinqs.com/threat/TL-2026-1485) — MEDIUM — DNS Pivoting Reveals Shared Infrastructure Across LokiBot, Bagle, Xworm, and Remcos Campaigns
- [TL-2026-1486](https://intel.threadlinqs.com/threat/TL-2026-1486) — MEDIUM — Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload (sokingscrosshotel\[.\]com)
- [TL-2026-1487](https://intel.threadlinqs.com/threat/TL-2026-1487) — MEDIUM — Multi-Stage NetSupport RAT Loader Using Layered Obfuscation (Decimal Arrays, AES, GZIP)
- [TL-2026-1488](https://intel.threadlinqs.com/threat/TL-2026-1488) — MEDIUM — W32/SkyAI (Skynet/Topozuy) — Windows Malware with Embedded LLM Prompt-Injection AV-Evasion Attempt, Six-Function Sandbox Detection, and Tor-Based C2 Proxy
- [TL-2026-1499](https://intel.threadlinqs.com/threat/TL-2026-1499) — MEDIUM — LegacyHive: Local Privilege Escalation PoC via Windows User Profile Service (ProfSvc) Registry Hive Mounting
- [TL-2026-1500](https://intel.threadlinqs.com/threat/TL-2026-1500) — MEDIUM — Multiple Vulnerabilities in Cisco Identity Services Engine, ISE Passive Identity Connector, and RoomOS (GovCERT.HK A26-07-32)

## Techniques observed

T0813, T0814, [T0831](https://intel.threadlinqs.com/technique/T0831), [T1001](https://intel.threadlinqs.com/technique/T1001), T1001.002, [T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.001](https://intel.threadlinqs.com/technique/T1003.001), [T1003.002](https://intel.threadlinqs.com/technique/T1003.002), [T1003.003](https://intel.threadlinqs.com/technique/T1003.003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1010](https://intel.threadlinqs.com/technique/T1010), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1016](https://intel.threadlinqs.com/technique/T1016), T1016.001, [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1021.004](https://intel.threadlinqs.com/technique/T1021.004), [T1021.005](https://intel.threadlinqs.com/technique/T1021.005), [T1025](https://intel.threadlinqs.com/technique/T1025), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.001](https://intel.threadlinqs.com/technique/T1027.001), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1027.004](https://intel.threadlinqs.com/technique/T1027.004), [T1027.007](https://intel.threadlinqs.com/technique/T1027.007), [T1027.010](https://intel.threadlinqs.com/technique/T1027.010), T1027.012, [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), T1027.015, T1027.016, [T1030](https://intel.threadlinqs.com/technique/T1030), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.008](https://intel.threadlinqs.com/technique/T1036.008), [T1037](https://intel.threadlinqs.com/technique/T1037), [T1039](https://intel.threadlinqs.com/technique/T1039), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1049](https://intel.threadlinqs.com/technique/T1049), T1052, [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.003](https://intel.threadlinqs.com/technique/T1053.003), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.001](https://intel.threadlinqs.com/technique/T1055.001), [T1055.004](https://intel.threadlinqs.com/technique/T1055.004), [T1055.012](https://intel.threadlinqs.com/technique/T1055.012), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1056.002](https://intel.threadlinqs.com/technique/T1056.002), [T1056.003](https://intel.threadlinqs.com/technique/T1056.003), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.002](https://intel.threadlinqs.com/technique/T1059.002), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), T1059.008, T1059.011, [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1069.002](https://intel.threadlinqs.com/technique/T1069.002), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1070.003](https://intel.threadlinqs.com/technique/T1070.003), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), T1070.007, [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1072](https://intel.threadlinqs.com/technique/T1072), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1074.001](https://intel.threadlinqs.com/technique/T1074.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.001](https://intel.threadlinqs.com/technique/T1078.001), [T1078.003](https://intel.threadlinqs.com/technique/T1078.003), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1080](https://intel.threadlinqs.com/technique/T1080), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.001](https://intel.threadlinqs.com/technique/T1087.001), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1091](https://intel.threadlinqs.com/technique/T1091), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.004](https://intel.threadlinqs.com/technique/T1098.004), [T1098.005](https://intel.threadlinqs.com/technique/T1098.005), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), T1102.003, [T1104](https://intel.threadlinqs.com/technique/T1104), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.001](https://intel.threadlinqs.com/technique/T1110.001), [T1110.002](https://intel.threadlinqs.com/technique/T1110.002), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1120](https://intel.threadlinqs.com/technique/T1120), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1132.001](https://intel.threadlinqs.com/technique/T1132.001), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1137](https://intel.threadlinqs.com/technique/T1137), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1200](https://intel.threadlinqs.com/technique/T1200), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1205](https://intel.threadlinqs.com/technique/T1205), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1218.005](https://intel.threadlinqs.com/technique/T1218.005), [T1218.007](https://intel.threadlinqs.com/technique/T1218.007), [T1218.011](https://intel.threadlinqs.com/technique/T1218.011), [T1219](https://intel.threadlinqs.com/technique/T1219), T1221, [T1406](https://intel.threadlinqs.com/technique/T1406), [T1417](https://intel.threadlinqs.com/technique/T1417), [T1418](https://intel.threadlinqs.com/technique/T1418), [T1426](https://intel.threadlinqs.com/technique/T1426), [T1429](https://intel.threadlinqs.com/technique/T1429), [T1430](https://intel.threadlinqs.com/technique/T1430), [T1437](https://intel.threadlinqs.com/technique/T1437), T1474, [T1480](https://intel.threadlinqs.com/technique/T1480), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1484.001](https://intel.threadlinqs.com/technique/T1484.001), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1491.001](https://intel.threadlinqs.com/technique/T1491.001), [T1491.002](https://intel.threadlinqs.com/technique/T1491.002), [T1495](https://intel.threadlinqs.com/technique/T1495), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1497.003](https://intel.threadlinqs.com/technique/T1497.003), [T1498](https://intel.threadlinqs.com/technique/T1498), [T1498.001](https://intel.threadlinqs.com/technique/T1498.001), [T1499](https://intel.threadlinqs.com/technique/T1499), T1499.001, [T1499.003](https://intel.threadlinqs.com/technique/T1499.003), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1512](https://intel.threadlinqs.com/technique/T1512), [T1513](https://intel.threadlinqs.com/technique/T1513), [T1516](https://intel.threadlinqs.com/technique/T1516), [T1517](https://intel.threadlinqs.com/technique/T1517), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1533](https://intel.threadlinqs.com/technique/T1533), [T1534](https://intel.threadlinqs.com/technique/T1534), T1535, [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1541](https://intel.threadlinqs.com/technique/T1541), [T1542](https://intel.threadlinqs.com/technique/T1542), T1542.001, [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546](https://intel.threadlinqs.com/technique/T1546), T1546.001, [T1546.004](https://intel.threadlinqs.com/technique/T1546.004), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1547.006](https://intel.threadlinqs.com/technique/T1547.006), T1547.011, [T1547.013](https://intel.threadlinqs.com/technique/T1547.013), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.002](https://intel.threadlinqs.com/technique/T1552.002), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1553.001](https://intel.threadlinqs.com/technique/T1553.001), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.001](https://intel.threadlinqs.com/technique/T1555.001), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1555.005](https://intel.threadlinqs.com/technique/T1555.005), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1559](https://intel.threadlinqs.com/technique/T1559), [T1559.001](https://intel.threadlinqs.com/technique/T1559.001), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), [T1561](https://intel.threadlinqs.com/technique/T1561), [T1561.001](https://intel.threadlinqs.com/technique/T1561.001), T1562, T1562.001, T1562.004, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1564.003](https://intel.threadlinqs.com/technique/T1564.003), [T1564.004](https://intel.threadlinqs.com/technique/T1564.004), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1568](https://intel.threadlinqs.com/technique/T1568), T1568.001, [T1568.002](https://intel.threadlinqs.com/technique/T1568.002), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1569.002](https://intel.threadlinqs.com/technique/T1569.002), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574](https://intel.threadlinqs.com/technique/T1574), T1574.012, [T1582](https://intel.threadlinqs.com/technique/T1582), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1584.001](https://intel.threadlinqs.com/technique/T1584.001), [T1584.006](https://intel.threadlinqs.com/technique/T1584.006), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1585.003](https://intel.threadlinqs.com/technique/T1585.003), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), T1587.003, [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1588.007](https://intel.threadlinqs.com/technique/T1588.007), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.002](https://intel.threadlinqs.com/technique/T1589.002), [T1589.003](https://intel.threadlinqs.com/technique/T1589.003), [T1590](https://intel.threadlinqs.com/technique/T1590), T1590.004, T1590.005, [T1591](https://intel.threadlinqs.com/technique/T1591), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1592.004](https://intel.threadlinqs.com/technique/T1592.004), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.001](https://intel.threadlinqs.com/technique/T1595.001), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1599](https://intel.threadlinqs.com/technique/T1599), T1600, [T1601](https://intel.threadlinqs.com/technique/T1601), [T1602](https://intel.threadlinqs.com/technique/T1602), T1602.001, T1602.002, [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1608.005](https://intel.threadlinqs.com/technique/T1608.005), [T1609](https://intel.threadlinqs.com/technique/T1609), [T1610](https://intel.threadlinqs.com/technique/T1610), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1614](https://intel.threadlinqs.com/technique/T1614), T1616, [T1619](https://intel.threadlinqs.com/technique/T1619), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1622](https://intel.threadlinqs.com/technique/T1622), [T1624](https://intel.threadlinqs.com/technique/T1624), [T1628](https://intel.threadlinqs.com/technique/T1628), [T1630](https://intel.threadlinqs.com/technique/T1630), [T1636](https://intel.threadlinqs.com/technique/T1636), T1641, T1642, [T1648](https://intel.threadlinqs.com/technique/T1648), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657), [T1660](https://intel.threadlinqs.com/technique/T1660), T1663, [T1685](https://intel.threadlinqs.com/technique/T1685)

## Threat actors

[Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group), [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038), [SmartApeSG](https://intel.threadlinqs.com/actor/SmartApeSG), [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview), [SHub Stealer operators](https://intel.threadlinqs.com/actor/SHub%20Stealer%20operators), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters), [Outsider Enterprise](https://intel.threadlinqs.com/actor/Outsider%20Enterprise), [Forbidden Hyena](https://intel.threadlinqs.com/actor/Forbidden%20Hyena), [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard), [AMOS MaaS Operators](https://intel.threadlinqs.com/actor/AMOS%20MaaS%20Operators), [DriveSurge](https://intel.threadlinqs.com/actor/DriveSurge), [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra), Keksec (TuxBot/Kaitori/AISURU operator), [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795), [JADEPUFFER](https://intel.threadlinqs.com/actor/JADEPUFFER), [APT27](https://intel.threadlinqs.com/actor/APT27)

Nation-state attribution: Russia, North Korea (DPRK), China, Iran

Threat categories: MALWARE, VULNERABILITY, THREAT_ACTOR, RANSOMWARE, PHISHING, SUPPLY_CHAIN, ESPIONAGE, APT

## Severity breakdown

- critical: 13
- high: 31
- medium: 11
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 1524 (behavioral 364, network 358, file 267, entity 133, tool 99, infrastructure 87, malware 82, technique 57, package 56, vulnerability 21)
- New detection rules: 495 (100% of the day’s threats covered)

## More editions

- Previous: [2026-07-17](https://intel.threadlinqs.com/debrief/2026-07-17)
- Next: [2026-07-19](https://intel.threadlinqs.com/debrief/2026-07-19)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-07-18
