# Daily Intelligence Briefing — Sunday, July 19, 2026

> On 2026-07-19, Threadlinqs published 29 new threat reports and updated 19, 16 rated critical and 28 high, spanning 253 MITRE ATT&CK techniques and 13 named threat actors. Coverage that day added 438 new detection rules and 1427 extracted indicators.

- **Edition:** 2026-07-19 (Sunday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-07-19
- **Last updated:** 2026-07-25
- **New threats:** 29 (19 updated)
- **Critical / high:** 16 critical, 28 high, 4 medium, 0 low
- **ATT&CK techniques:** 253
- **Threat actors:** 13
- **Indicators (count only):** 1427
- **New detection rules (count only):** 438

## Summary & highlights

700+ Typosquatted/Lookalike Domains Targeting Oil and Gas Brands (Chevron, ExxonMobil, Shell) for Phishing, BEC, and Recruitment Fraud. Pokémon Brand-Spoofing Campaign: 1,352 Lookalike Domains Ahead of 30th Anniversary. ChatGPT Plus Billing Phishing Campaign Spoofs Stripe Checkout to Harvest Payment Card Data.

- [TL-2026-1506](https://intel.threadlinqs.com/threat/TL-2026-1506) — Ransomware Attack on Coca-Cola's Fairlife Dairy Halts U.S. Production Systems
- [TL-2026-1507](https://intel.threadlinqs.com/threat/TL-2026-1507) — CVE-2025-12480: Triofox HTTP Host Header Authentication Bypass Exploited by UNC6485 for SYSTEM-Level Code Execution
- [TL-2026-1508](https://intel.threadlinqs.com/threat/TL-2026-1508) — GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, QUIETVAULT) Deployed by State Actors
- [TL-2026-1509](https://intel.threadlinqs.com/threat/TL-2026-1509) — UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to Deliver RATs and Steal Credentials
- [TL-2026-1510](https://intel.threadlinqs.com/threat/TL-2026-1510) — COLDRIVER (UNC4057/Star Blizzard) Re-Tools with NOROBOT/BAITSWITCH/YESROBOT/MAYBEROBOT/SIMPLEFIX Malware Chain After LOSTKEYS Disclosure

## Theme of the day

social-engineering, remote-code-execution, credential-harvesting, unauthenticated-rce, phishing

## Threats published

- [TL-2026-1540](https://intel.threadlinqs.com/threat/TL-2026-1540) — CRITICAL — Four Chained Exploit Paths in LiteLLM Proxy (Pre-Auth RCE to Master Key Exfiltration) — STAR Labs Pwn2Own Research
- [TL-2026-1544](https://intel.threadlinqs.com/threat/TL-2026-1544) — CRITICAL — Pixel 10 VPU Driver mmap Boundary-Check Flaw Enables Root Exploit Chain (CVE-2025-54957)
- [TL-2026-1545](https://intel.threadlinqs.com/threat/TL-2026-1545) — CRITICAL — CVE-2026-47291: Remote Code Execution in Windows HTTP.sys (Kernel-Mode Integer Overflow)
- [TL-2026-0080](https://intel.threadlinqs.com/threat/TL-2026-0080) — CRITICAL — React2Shell CVE-2025-55182 — Multiple Threat Actors Actively Exploiting React Server Components RCE (CVSS 10.0) (update)
- [TL-2026-0121](https://intel.threadlinqs.com/threat/TL-2026-0121) — CRITICAL — Ivanti EPMM Dual-CVE Unauthenticated RCE Chain (CVE-2026-1281 + CVE-2026-1340) — CVSS 9.8, CISA KEV, Dutch Government Breached, Bulletproof Hosting IAB, Sleeper Webshells, 28K+ Attacking IPs (update)
- [TL-2026-0269](https://intel.threadlinqs.com/threat/TL-2026-0269) — CRITICAL — CVE-2026-21902: Juniper PTX Series Junos OS Evolved Unauthenticated Remote Code Execution as Root via On-Box Anomaly Detection Framework (CVSS 9.8) (update)
- [TL-2026-0294](https://intel.threadlinqs.com/threat/TL-2026-0294) — CRITICAL — CVE-2026-3055 & CVE-2026-4368: Citrix NetScaler ADC/Gateway Pre-Auth Memory Overread and Session Mixup (update)
- [TL-2026-0365](https://intel.threadlinqs.com/threat/TL-2026-0365) — CRITICAL — CVE-2026-33824: Windows IKE Extensions Unauthenticated RCE via Double Free (update)
- [TL-2026-0449](https://intel.threadlinqs.com/threat/TL-2026-0449) — CRITICAL — Sorry Ransomware Mass Exploitation of cPanel/WHM Authentication Bypass CVE-2026-41940 (44,000+ Servers Compromised) (update)
- [TL-2026-0758](https://intel.threadlinqs.com/threat/TL-2026-0758) — CRITICAL — Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation (update)
- [TL-2026-1045](https://intel.threadlinqs.com/threat/TL-2026-1045) — CRITICAL — CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap escape_quotes() Flaw on /accessv2 (update)
- [TL-2026-1103](https://intel.threadlinqs.com/threat/TL-2026-1103) — CRITICAL — CVE-2026-20253: Critical Unauthenticated Remote Code Execution in Splunk Enterprise via PostgreSQL Sidecar Service (update)
- [TL-2026-1140](https://intel.threadlinqs.com/threat/TL-2026-1140) — CRITICAL — CitrixBleed 2.0: CVE-2026-8451 NetScaler SAML IDP Memory Overread Under Active Exploitation (update)
- [TL-2026-1391](https://intel.threadlinqs.com/threat/TL-2026-1391) — CRITICAL — F5 Patches Multiple NGINX Vulnerabilities: Heap Overflow, Memory Disclosure, and Use-After-Free (CVE-2026-42533, CVE-2026-60005, CVE-2026-56434) (update)
- [TL-2026-1464](https://intel.threadlinqs.com/threat/TL-2026-1464) — CRITICAL — CVE-2026-63030 (wp2shell): Unauthenticated Remote Code Execution in WordPress Core REST API Batch Endpoint via Chained SQL Injection (CVE-2026-60137) (update)
- [TL-2026-1513](https://intel.threadlinqs.com/threat/TL-2026-1513) — CRITICAL — Progress ShareFile Pre-Auth RCE Chain via Auth Bypass (CVE-2026-2699, CVE-2026-2701) (update)
- [TL-2026-1506](https://intel.threadlinqs.com/threat/TL-2026-1506) — HIGH — Ransomware Attack on Coca-Cola's Fairlife Dairy Halts U.S. Production Systems
- [TL-2026-1507](https://intel.threadlinqs.com/threat/TL-2026-1507) — HIGH — CVE-2025-12480: Triofox HTTP Host Header Authentication Bypass Exploited by UNC6485 for SYSTEM-Level Code Execution
- [TL-2026-1508](https://intel.threadlinqs.com/threat/TL-2026-1508) — HIGH — GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, QUIETVAULT) Deployed by State Actors
- [TL-2026-1509](https://intel.threadlinqs.com/threat/TL-2026-1509) — HIGH — UNC6229: Vietnamese Actors Use Fake Job Posting Campaigns to Deliver RATs and Steal Credentials
- [TL-2026-1510](https://intel.threadlinqs.com/threat/TL-2026-1510) — HIGH — COLDRIVER (UNC4057/Star Blizzard) Re-Tools with NOROBOT/BAITSWITCH/YESROBOT/MAYBEROBOT/SIMPLEFIX Malware Chain After LOSTKEYS Disclosure
- [TL-2026-1511](https://intel.threadlinqs.com/threat/TL-2026-1511) — HIGH — DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and INVISIBLEFERRET via Blockchain Smart Contracts
- [TL-2026-1514](https://intel.threadlinqs.com/threat/TL-2026-1514) — HIGH — SleeperGem: RubyGems Supply Chain Attack via Compromised Dormant Maintainer Accounts
- [TL-2026-1515](https://intel.threadlinqs.com/threat/TL-2026-1515) — HIGH — CVE-2026-32746: Pre-Auth BSS Buffer Overflow in GNU inetutils telnetd LINEMODE SLC Handling
- [TL-2026-1518](https://intel.threadlinqs.com/threat/TL-2026-1518) — HIGH — Coordinated Domain Impersonation Campaign Exploits Fable 5/Mythos 5 AI Model Export-Control Ban — 117+ Malicious Domains Targeting Anthropic, Claude, and Fable Brands
- [TL-2026-1521](https://intel.threadlinqs.com/threat/TL-2026-1521) — HIGH — Mass Phishing/Fraud Campaign Impersonating Anthropic Claude and Mythos Brands (3,188 Malicious Domains)
- [TL-2026-1522](https://intel.threadlinqs.com/threat/TL-2026-1522) — HIGH — MetaChat Brand Impersonation Phishing Campaign Targets AI API Keys and Credentials via EdgeOne Pages
- [TL-2026-1526](https://intel.threadlinqs.com/threat/TL-2026-1526) — HIGH — APT37 Pretexting Campaign: Facebook Social Engineering Delivers RokRAT via Tampered PDFelement Installer
- [TL-2026-1527](https://intel.threadlinqs.com/threat/TL-2026-1527) — HIGH — UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA Lures and EtherHiding to Deploy Multi-Stage GHETTOVIBE/SCOUTCURL/FLUIDLEECH/FREAKYPOLL/COWARDDUCK Toolset Against Ukraine
- [TL-2026-1528](https://intel.threadlinqs.com/threat/TL-2026-1528) — HIGH — HelloNet Campaign Abuses ViPNet Update Mechanism to Deploy HelloInjector/HelloProxy/HelloBackdoor Toolset Against Russian Government Agencies
- [TL-2026-1530](https://intel.threadlinqs.com/threat/TL-2026-1530) — HIGH — MuddyWater APT (Iran MOIS-linked, G0069) abuses legitimate RMM tools, VBA macro loaders, and Rust-compiled payloads in ongoing global espionage campaign
- [TL-2026-1532](https://intel.threadlinqs.com/threat/TL-2026-1532) — HIGH — SleeperGem: Compromised RubyGems Packages (git_credential_manager, Dendreo, fastlane-plugin-run_tests_firebase_testlab) Drop Persistent Multi-Stage Backdoor via Dormant Maintainer Accounts
- [TL-2026-1533](https://intel.threadlinqs.com/threat/TL-2026-1533) — HIGH — Lumma Infostealer (LummaC2): MaaS Credential Theft via NSIS/AutoIt/ClickFix Evasion Chain
- [TL-2026-1537](https://intel.threadlinqs.com/threat/TL-2026-1537) — HIGH — CVE-2025-62507: Unauthenticated Stack-Based Buffer Overflow RCE in Redis XACKDEL Command
- [TL-2026-1542](https://intel.threadlinqs.com/threat/TL-2026-1542) — HIGH — Pre-Auth Remote Code Execution in Enterprise Network Printer Firmware via Fuzzed Management Protocol (STAR Labs Research)
- [TL-2026-1546](https://intel.threadlinqs.com/threat/TL-2026-1546) — HIGH — Pwn2Own Berlin 2026 Day Three: Zero-Days Demonstrated in VMware ESXi, Microsoft SharePoint, Windows 11, Red Hat Linux, and Anthropic Claude Code
- [TL-2026-1550](https://intel.threadlinqs.com/threat/TL-2026-1550) — HIGH — CVE-2025-6978: Authenticated Diagnostics Command Injection Leading to Root RCE in Arista NG Firewall
- [TL-2026-1551](https://intel.threadlinqs.com/threat/TL-2026-1551) — HIGH — ClickFix, CrashFix, InstallFix, FileFix & GhostClaw: Growing Family of Copy-and-Paste Social Engineering Attacks
- [TL-2026-1552](https://intel.threadlinqs.com/threat/TL-2026-1552) — HIGH — Infostealer-Enabled ClickFix Campaign Compromises Artlist via EtherHiding C2 and DLL Side-Loaded RAT
- [TL-2026-0906](https://intel.threadlinqs.com/threat/TL-2026-0906) — HIGH — CVE-2026-8461 (PixelSmash): Heap Out-of-Bounds Write in FFmpeg libavcodec MagicYUV Decoder (update)
- [TL-2026-1173](https://intel.threadlinqs.com/threat/TL-2026-1173) — HIGH — Google Chrome 150.0.7871.114/.115 Patches 27 Vulnerabilities Including Two Critical Use-After-Free Flaws (CVE-2026-15112, CVE-2026-15129) (update)
- [TL-2026-1477](https://intel.threadlinqs.com/threat/TL-2026-1477) — HIGH — IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499 "GhostLock") Demonstrated Against Android 17 (update)
- [TL-2026-1505](https://intel.threadlinqs.com/threat/TL-2026-1505) — HIGH — Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability (CVE-2026-58525) (update)
- [TL-2026-1538](https://intel.threadlinqs.com/threat/TL-2026-1538) — HIGH — CVE-2026-26133: Cross-Prompt Injection in Microsoft Copilot Email/Teams Summarization Enables AI-Mediated Phishing (update)
- [TL-2026-1519](https://intel.threadlinqs.com/threat/TL-2026-1519) — MEDIUM — 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas Brands (Chevron, ExxonMobil, Shell) for Phishing, BEC, and Recruitment Fraud
- [TL-2026-1520](https://intel.threadlinqs.com/threat/TL-2026-1520) — MEDIUM — Pokémon Brand-Spoofing Campaign: 1,352 Lookalike Domains Ahead of 30th Anniversary
- [TL-2026-1534](https://intel.threadlinqs.com/threat/TL-2026-1534) — MEDIUM — ChatGPT Plus Billing Phishing Campaign Spoofs Stripe Checkout to Harvest Payment Card Data
- [TL-2026-1523](https://intel.threadlinqs.com/threat/TL-2026-1523) — MEDIUM — Winter Olympics 2026 Domain Impersonation and Phishing Infrastructure Campaign (update)

## Techniques observed

[T1003](https://intel.threadlinqs.com/technique/T1003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1007](https://intel.threadlinqs.com/technique/T1007), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.004](https://intel.threadlinqs.com/technique/T1021.004), [T1025](https://intel.threadlinqs.com/technique/T1025), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1027.007](https://intel.threadlinqs.com/technique/T1027.007), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.003](https://intel.threadlinqs.com/technique/T1036.003), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.008](https://intel.threadlinqs.com/technique/T1036.008), T1037.001, [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1049](https://intel.threadlinqs.com/technique/T1049), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.003](https://intel.threadlinqs.com/technique/T1053.003), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.012](https://intel.threadlinqs.com/technique/T1055.012), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1056.003](https://intel.threadlinqs.com/technique/T1056.003), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), T1059.011, [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.001, [T1070.003](https://intel.threadlinqs.com/technique/T1070.003), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1074.001](https://intel.threadlinqs.com/technique/T1074.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.003](https://intel.threadlinqs.com/technique/T1078.003), [T1080](https://intel.threadlinqs.com/technique/T1080), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.001](https://intel.threadlinqs.com/technique/T1087.001), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1090.004](https://intel.threadlinqs.com/technique/T1090.004), [T1091](https://intel.threadlinqs.com/technique/T1091), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), T1098.007, [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1104](https://intel.threadlinqs.com/technique/T1104), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.002](https://intel.threadlinqs.com/technique/T1110.002), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1120](https://intel.threadlinqs.com/technique/T1120), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1129](https://intel.threadlinqs.com/technique/T1129), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), T1134.003, T1134.005, [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1137](https://intel.threadlinqs.com/technique/T1137), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1204.004](https://intel.threadlinqs.com/technique/T1204.004), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1218.011](https://intel.threadlinqs.com/technique/T1218.011), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1222](https://intel.threadlinqs.com/technique/T1222), [T1417](https://intel.threadlinqs.com/technique/T1417), [T1480](https://intel.threadlinqs.com/technique/T1480), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1491.002](https://intel.threadlinqs.com/technique/T1491.002), [T1495](https://intel.threadlinqs.com/technique/T1495), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1498](https://intel.threadlinqs.com/technique/T1498), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1517](https://intel.threadlinqs.com/technique/T1517), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1525](https://intel.threadlinqs.com/technique/T1525), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1534](https://intel.threadlinqs.com/technique/T1534), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1546.004](https://intel.threadlinqs.com/technique/T1546.004), T1546.016, [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), T1547.011, [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.001](https://intel.threadlinqs.com/technique/T1548.001), [T1548.003](https://intel.threadlinqs.com/technique/T1548.003), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.001](https://intel.threadlinqs.com/technique/T1555.001), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), T1562, T1562.001, T1562.004, T1563, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.003](https://intel.threadlinqs.com/technique/T1564.003), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.003](https://intel.threadlinqs.com/technique/T1566.003), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.001](https://intel.threadlinqs.com/technique/T1567.001), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1569.002](https://intel.threadlinqs.com/technique/T1569.002), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), T1574.002, [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.005](https://intel.threadlinqs.com/technique/T1583.005), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1583.008](https://intel.threadlinqs.com/technique/T1583.008), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1584.004](https://intel.threadlinqs.com/technique/T1584.004), [T1584.006](https://intel.threadlinqs.com/technique/T1584.006), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1585.002](https://intel.threadlinqs.com/technique/T1585.002), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1586.002](https://intel.threadlinqs.com/technique/T1586.002), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), T1587.003, [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.001](https://intel.threadlinqs.com/technique/T1588.001), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.001](https://intel.threadlinqs.com/technique/T1589.001), [T1590](https://intel.threadlinqs.com/technique/T1590), T1590.005, [T1591](https://intel.threadlinqs.com/technique/T1591), T1591.003, [T1592](https://intel.threadlinqs.com/technique/T1592), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1594](https://intel.threadlinqs.com/technique/T1594), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.001](https://intel.threadlinqs.com/technique/T1595.001), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1596.005](https://intel.threadlinqs.com/technique/T1596.005), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1598.003](https://intel.threadlinqs.com/technique/T1598.003), [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1610](https://intel.threadlinqs.com/technique/T1610), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657), [T1685](https://intel.threadlinqs.com/technique/T1685)

## Threat actors

[UNC6485](https://intel.threadlinqs.com/actor/UNC6485), [APT28](https://intel.threadlinqs.com/actor/APT28), [UNC6229](https://intel.threadlinqs.com/actor/UNC6229), [Cold River](https://intel.threadlinqs.com/actor/Cold%20River), [UNC5342](https://intel.threadlinqs.com/actor/UNC5342), [APT37](https://intel.threadlinqs.com/actor/APT37), [UAC-0145](https://intel.threadlinqs.com/actor/UAC-0145), [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater), [Shamel](https://intel.threadlinqs.com/actor/Shamel), [Earth Lamia](https://intel.threadlinqs.com/actor/Earth%20Lamia), [UNC5221](https://intel.threadlinqs.com/actor/UNC5221), [Mr_Rot13](https://intel.threadlinqs.com/actor/Mr_Rot13), [Qilin](https://intel.threadlinqs.com/actor/Qilin)

Nation-state attribution: Russia, Vietnam, North Korea (DPRK), North Korea, China (low-confidence, disputed/possible false flag), Iran, China, Iran, China

Threat categories: PHISHING, RANSOMWARE, VULNERABILITY, MALWARE, SUPPLY_CHAIN, APT, THREAT_ACTOR, SOCIAL_ENGINEERING

## Severity breakdown

- critical: 16
- high: 28
- medium: 4
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 1427 (network 387, behavioral 293, file 257, entity 110, infrastructure 86, malware 86, technique 76, tool 75, package 36, vulnerability 17, host 3, software 1)
- New detection rules: 438 (100% of the day’s threats covered)

## More editions

- Previous: [2026-07-18](https://intel.threadlinqs.com/debrief/2026-07-18)
- Next: [2026-07-20](https://intel.threadlinqs.com/debrief/2026-07-20)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-07-19
