Threadlinqs IntelligenceStart free

Daily debrief · Sunday2026-07-19

Daily Intelligence Briefing — Sunday, July 19, 2026

16 critical28 high4 medium

On 2026-07-19, Threadlinqs published 29 new threat reports and updated 19, 16 rated critical and 28 high, spanning 253 MITRE ATT&CK techniques and 13 named threat actors. Coverage that day added 438 new detection rules and 1427 extracted indicators.

New threats
2919 updated
Critical / high
4416 critical · 28 high
ATT&CK techniques
253Observed in the day’s reports
Threat actors
13Named in the reports
Indicators
1427Count only · values are Red+
Detection rules
438New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

700+ Typosquatted/Lookalike Domains Targeting Oil and Gas Brands (Chevron, ExxonMobil, Shell) for Phishing, BEC, and Recruitment Fraud. Pokémon Brand-Spoofing Campaign: 1,352 Lookalike Domains Ahead of 30th Anniversary. ChatGPT Plus Billing Phishing Campaign Spoofs Stripe Checkout to Harvest Payment Card Data.

Highlights

  • TL-2026-1506 — Ransomware Attack on Coca-Cola's Fairlife Dairy Halts U.S. Production Systems
  • TL-2026-1507 — CVE-2025-12480: Triofox HTTP Host Header Authentication Bypass Exploited by UNC6485 for SYSTEM-Level Code Execution
  • TL-2026-1508 — GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, QUIETVAULT) Deployed by State Actors
  • TL-2026-1509 — UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to Deliver RATs and Steal Credentials
  • TL-2026-1510 — COLDRIVER (UNC4057/Star Blizzard) Re-Tools with NOROBOT/BAITSWITCH/YESROBOT/MAYBEROBOT/SIMPLEFIX Malware Chain After LOSTKEYS Disclosure

Theme of the day

  • social-engineering
  • remote-code-execution
  • credential-harvesting
  • unauthenticated-rce
  • phishing

Threats published

48 threat lines in the 2026-07-19 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

253 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

13 named threat actors across the reports.

Nation-state attribution

  • Russia
  • Vietnam
  • North Korea (DPRK)
  • North Korea
  • China (low-confidence, disputed/possible false flag)
  • Iran
  • China, Iran
  • China

Threat categories

  • PHISHING
  • RANSOMWARE
  • VULNERABILITY
  • MALWARE
  • SUPPLY_CHAIN
  • APT
  • THREAT_ACTOR
  • SOCIAL_ENGINEERING

Severity breakdown

  • critical16
  • high28
  • medium4
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

1427 indicators of compromise · Red and above. Compare plans
  • network 387
  • behavioral 293
  • file 257
  • entity 110
  • infrastructure 86
  • malware 86
  • technique 76
  • tool 75
  • package 36
  • vulnerability 17
  • host 3
  • software 1
438 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans