Threadlinqs IntelligenceStart free

Daily debrief · Monday2026-07-20

Daily Intelligence Briefing — Monday, July 20, 2026

2 critical20 high6 medium1 low

On 2026-07-20, Threadlinqs published 29 new threat reports, 2 rated critical and 20 high, spanning 242 MITRE ATT&CK techniques and 12 named threat actors. Coverage that day added 261 new detection rules and 824 extracted indicators.

New threats
2929 threat lines
Critical / high
222 critical · 20 high
ATT&CK techniques
242Observed in the day’s reports
Threat actors
12Named in the reports
Indicators
824Count only · values are Red+
Detection rules
261New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS Vulnerability. NSFOCUS 2025 APT Group Research Annual Report: 662 Active APT Groups, 42 Newly Disclosed, AI-Weaponized Attacks Surge 89% YoY. Odyssey Piracy Scam Campaign: Malvertising and Icon-Spoofed Executables Targeting Movie Downloaders.

Highlights

  • TL-2026-1553 — HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to Cavern Manticore/Lyceum (Low Confidence)
  • TL-2026-1555 — HollowGraph Malware Abuses Microsoft 365 Calendars for Covert C2 via Graph API
  • TL-2026-1556 — CVE-2026-52824: Kimai Docker Image Hardcoded APP_SECRET Enables Account Takeover
  • TL-2026-1557 — TELEPUZ: Modular MaaS Banking WebInjector Distributed via ClickFix/VIDAR Chain
  • TL-2026-1558 — ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second Stage

Theme of the day

Unattributed threats dominated the landscape, with multiple active threat postures. New threats emerged, totaling 20 in the latest window.

  • social-engineering
  • anti-analysis
  • dll-sideloading
  • credential-theft
  • browser-credential-theft

Threats published

29 threat lines in the 2026-07-20 debrief, most severe first. Each links to its full profile.

Techniques observed

242 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

12 named threat actors across the reports.

Nation-state attribution

  • Iran / North Korea (Cleaver, Lazarus); TA505 is non-state financially motivated
  • Russia
  • Iran
  • North Korea (DPRK)
  • North Korea
  • North Korea (assessed, via PolinRider overlap)
  • China

Threat categories

  • VULNERABILITY
  • APT
  • SCAM
  • MALWARE
  • DATA_BREACH
  • SUPPLY_CHAIN
  • FRAUD
  • INTRUSION
  • CYBERCRIME

Severity breakdown

  • critical2
  • high20
  • medium6
  • low1

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

824 indicators of compromise · Red and above. Compare plans
  • network 187
  • file 172
  • behavioral 168
  • malware 82
  • package 58
  • entity 57
  • infrastructure 55
  • tool 30
  • technique 12
  • vulnerability 3
261 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans