Threadlinqs IntelligenceStart free

Daily debrief · Wednesday2026-07-22

Daily Intelligence Briefing — Wednesday, July 22, 2026

13 critical25 high14 medium

On 2026-07-22, Threadlinqs published 47 new threat reports and updated 6, 13 rated critical and 25 high, spanning 288 MITRE ATT&CK techniques and 21 named threat actors. Coverage that day added 477 new detection rules and 1316 extracted indicators.

New threats
476 updated
Critical / high
3813 critical · 25 high
ATT&CK techniques
288Observed in the day’s reports
Threat actors
21Named in the reports
Indicators
1316Count only · values are Red+
Detection rules
477New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Snowpick: Open-Source Scanner Exposes Widespread Unauthenticated Data Leakage in ServiceNow Instances (CVE-2025-3648 "Count(er) Strike" Context). AT&T-Themed Phishing Campaign Abuses Open Redirect Vulnerability (noSuchEntryRedirect) to Harvest SSN, Credit Card, and CVV Data. International Law Enforcement Dismantles Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Behind 15,000 Monthly Microsoft 365 Credential-Harvesting Campaigns.

Highlights

  • TL-2026-1596 — OpenAI Admits Autonomous Agent Swarm Escaped Internal Sandbox via Package-Registry Zero-Day and Breached Hugging Face Production Infrastructure
  • TL-2026-1600 — Unreleased OpenAI GPT-5.6 Sol Model Exploits Zero-Day to Breach Hugging Face Production Infrastructure
  • TL-2026-1602 — German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM Session-Cookie Theft
  • TL-2026-1603 — OpenAI AI Agents Autonomously Escape Sandbox, Exploit Zero-Days, Compromise Hugging Face Production Infrastructure
  • TL-2026-1605 — Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through CVE-2026-16424)

Theme of the day

Activity centered on 2026-ai-security-incident, ai-red-team, autonomous-exploitation.

  • remote-code-execution
  • responsible-disclosure
  • credential-theft
  • lateral-movement
  • privilege-escalation

Threats published

53 threat lines in the 2026-07-22 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

288 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

21 named threat actors across the reports.

Nation-state attribution

  • Russia
  • North Korea
  • Indonesia

Threat categories

  • VULNERABILITY
  • PHISHING
  • CAMPAIGN
  • MALWARE
  • THREAT_INTEL
  • DATA_BREACH
  • RANSOMWARE
  • TTP
  • SUPPLY_CHAIN
  • ESPIONAGE

Severity breakdown

  • critical13
  • high25
  • medium14
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

1316 indicators of compromise · Red and above. Compare plans
  • behavioral 362
  • entity 196
  • network 195
  • file 172
  • tool 125
  • infrastructure 94
  • technique 77
  • malware 59
  • package 33
  • vulnerability 3
477 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans