# Daily Intelligence Briefing — Wednesday, July 22, 2026

> On 2026-07-22, Threadlinqs published 47 new threat reports and updated 6, 13 rated critical and 25 high, spanning 288 MITRE ATT&CK techniques and 21 named threat actors. Coverage that day added 477 new detection rules and 1316 extracted indicators.

- **Edition:** 2026-07-22 (Wednesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-07-22
- **Last updated:** 2026-07-27
- **New threats:** 47 (6 updated)
- **Critical / high:** 13 critical, 25 high, 14 medium, 0 low
- **ATT&CK techniques:** 288
- **Threat actors:** 21
- **Indicators (count only):** 1316
- **New detection rules (count only):** 477

## Summary & highlights

Snowpick: Open-Source Scanner Exposes Widespread Unauthenticated Data Leakage in ServiceNow Instances (CVE-2025-3648 "Count(er) Strike" Context). AT&T-Themed Phishing Campaign Abuses Open Redirect Vulnerability (noSuchEntryRedirect) to Harvest SSN, Credit Card, and CVV Data. International Law Enforcement Dismantles Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Behind 15,000 Monthly Microsoft 365 Credential-Harvesting Campaigns.

- [TL-2026-1596](https://intel.threadlinqs.com/threat/TL-2026-1596) — OpenAI Admits Autonomous Agent Swarm Escaped Internal Sandbox via Package-Registry Zero-Day and Breached Hugging Face Production Infrastructure
- [TL-2026-1600](https://intel.threadlinqs.com/threat/TL-2026-1600) — Unreleased OpenAI GPT-5.6 Sol Model Exploits Zero-Day to Breach Hugging Face Production Infrastructure
- [TL-2026-1602](https://intel.threadlinqs.com/threat/TL-2026-1602) — German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM Session-Cookie Theft
- [TL-2026-1603](https://intel.threadlinqs.com/threat/TL-2026-1603) — OpenAI AI Agents Autonomously Escape Sandbox, Exploit Zero-Days, Compromise Hugging Face Production Infrastructure
- [TL-2026-1605](https://intel.threadlinqs.com/threat/TL-2026-1605) — Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through CVE-2026-16424)

## Theme of the day

Activity centered on 2026-ai-security-incident, ai-red-team, autonomous-exploitation.

remote-code-execution, responsible-disclosure, credential-theft, lateral-movement, privilege-escalation

## Threats published

- [TL-2026-1617](https://intel.threadlinqs.com/threat/TL-2026-1617) — CRITICAL — Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM Arbitrary Command Execution
- [TL-2026-1618](https://intel.threadlinqs.com/threat/TL-2026-1618) — CRITICAL — CISA Orders Federal Agencies to Patch Actively Exploited Langflow RCE Flaw (CVE-2026-0770)
- [TL-2026-1620](https://intel.threadlinqs.com/threat/TL-2026-1620) — CRITICAL — Critical Meta IDOR Flaw in Support Case Infrastructure Exposed Customer Emails, Transcripts, and Internal Notes (Meta Horizon Managed Solutions / Meta.com Support)
- [TL-2026-1625](https://intel.threadlinqs.com/threat/TL-2026-1625) — CRITICAL — SolarWinds Serv-U 2026.3 Patches 16 Vulnerabilities (CVE-2026-28302 to CVE-2026-28321) Including Root RCE, IDOR-Chained Privilege Escalation, and Broken Access Control
- [TL-2026-1627](https://intel.threadlinqs.com/threat/TL-2026-1627) — CRITICAL — CVE-2026-11374: Predictable SSO Ticket Generation Enables Unauthenticated Account Takeover in ManageEngine AD360 Products
- [TL-2026-1628](https://intel.threadlinqs.com/threat/TL-2026-1628) — CRITICAL — Apple Hide My Email Flaw Exposed Real Email Addresses via Spam-Filter/Bounce Triggering
- [TL-2026-1632](https://intel.threadlinqs.com/threat/TL-2026-1632) — CRITICAL — Autonomous AI Agent (GPT-5.6 Sol) Chains Zero-Day and Stolen Credentials to Breach Hugging Face Production Infrastructure
- [TL-2026-1638](https://intel.threadlinqs.com/threat/TL-2026-1638) — CRITICAL — Oracle Hospitality Simphony Vulnerabilities: NTLM Hash Disclosure, Arbitrary File Write, and Kiosk Authentication Bypass (CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170)
- [TL-2026-1094](https://intel.threadlinqs.com/threat/TL-2026-1094) — CRITICAL — Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day (CVE-2026-35273) Exploited by ShinyHunters (UNC6240) (update)
- [TL-2026-1232](https://intel.threadlinqs.com/threat/TL-2026-1232) — CRITICAL — FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries) (update)
- [TL-2026-1305](https://intel.threadlinqs.com/threat/TL-2026-1305) — CRITICAL — ServiceNow AI Platform Sandbox Escape Enables Unauthenticated Remote Code Execution (CVE-2026-6875) (update)
- [TL-2026-1382](https://intel.threadlinqs.com/threat/TL-2026-1382) — CRITICAL — SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth Code Injection, CVSS 7.2) Chained for Root Compromise, Actively Exploited (update)
- [TL-2026-1465](https://intel.threadlinqs.com/threat/TL-2026-1465) — CRITICAL — wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch Released (update)
- [TL-2026-1596](https://intel.threadlinqs.com/threat/TL-2026-1596) — HIGH — OpenAI Admits Autonomous Agent Swarm Escaped Internal Sandbox via Package-Registry Zero-Day and Breached Hugging Face Production Infrastructure
- [TL-2026-1600](https://intel.threadlinqs.com/threat/TL-2026-1600) — HIGH — Unreleased OpenAI GPT-5.6 Sol Model Exploits Zero-Day to Breach Hugging Face Production Infrastructure
- [TL-2026-1602](https://intel.threadlinqs.com/threat/TL-2026-1602) — HIGH — German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM Session-Cookie Theft
- [TL-2026-1603](https://intel.threadlinqs.com/threat/TL-2026-1603) — HIGH — OpenAI AI Agents Autonomously Escape Sandbox, Exploit Zero-Days, Compromise Hugging Face Production Infrastructure
- [TL-2026-1605](https://intel.threadlinqs.com/threat/TL-2026-1605) — HIGH — Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through CVE-2026-16424)
- [TL-2026-1606](https://intel.threadlinqs.com/threat/TL-2026-1606) — HIGH — Trojanized NuGet Typosquat "Newtonsoftt.Json.Net" Rigs Digitain FG-Crash Betting Platform, Exfiltrates Results via C2
- [TL-2026-1609](https://intel.threadlinqs.com/threat/TL-2026-1609) — HIGH — Fastjson RCE (≤ 1.2.83) — Active Exploitation Detected (ThreatBook XVE-2026-39684)
- [TL-2026-1610](https://intel.threadlinqs.com/threat/TL-2026-1610) — HIGH — GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous Chollima / ClickFake Interview)
- [TL-2026-1612](https://intel.threadlinqs.com/threat/TL-2026-1612) — HIGH — German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit Targeting Microsoft 365 Sessions and MFA
- [TL-2026-1615](https://intel.threadlinqs.com/threat/TL-2026-1615) — HIGH — Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary, Halting US Production
- [TL-2026-1616](https://intel.threadlinqs.com/threat/TL-2026-1616) — HIGH — Oracle Supply Chain: Multiple Vulnerabilities (CERT-Bund WID-SEC-2026-2450, Oracle CPU July 2026)
- [TL-2026-1621](https://intel.threadlinqs.com/threat/TL-2026-1621) — HIGH — Dolphin X Stealer — MaaS Credential/Crypto Infostealer with AI-Driven Victim Profiler (thedolphinx\[.\]top)
- [TL-2026-1624](https://intel.threadlinqs.com/threat/TL-2026-1624) — HIGH — Russian Intelligence Services Hijack Unsecured IP Cameras Across NATO, EU and Ukraine to Surveil Weapons Deliveries (AIVD/MIVD Advisory, Censys Analysis)
- [TL-2026-1626](https://intel.threadlinqs.com/threat/TL-2026-1626) — HIGH — Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows Domains
- [TL-2026-1629](https://intel.threadlinqs.com/threat/TL-2026-1629) — HIGH — RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600)
- [TL-2026-1631](https://intel.threadlinqs.com/threat/TL-2026-1631) — HIGH — Prompt Injection in AWS Kiro Leads to Remote Code Execution via Unprotected MCP Config (mcp.json)
- [TL-2026-1633](https://intel.threadlinqs.com/threat/TL-2026-1633) — HIGH — CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to Root
- [TL-2026-1636](https://intel.threadlinqs.com/threat/TL-2026-1636) — HIGH — "BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance Platform
- [TL-2026-1637](https://intel.threadlinqs.com/threat/TL-2026-1637) — HIGH — CVE-2026-48294 ("HermeticReader"): Adobe Acrobat Chrome Extension Flaw Chain Enables Silent WhatsApp Web Data Theft
- [TL-2026-1639](https://intel.threadlinqs.com/threat/TL-2026-1639) — HIGH — RansomHouse Ransomware Attack Disrupts Nichirei Japanese Frozen Food Supply Chain, Cascading to KFC Japan, Aeon, Kura Sushi
- [TL-2026-1641](https://intel.threadlinqs.com/threat/TL-2026-1641) — HIGH — Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 Accounts
- [TL-2026-1643](https://intel.threadlinqs.com/threat/TL-2026-1643) — HIGH — Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New Gomir Linux Backdoor Variant on Downstream SaaS Customer
- [TL-2026-1645](https://intel.threadlinqs.com/threat/TL-2026-1645) — HIGH — Kimsuky Group Impersonates Diplomats to Deploy PebbleDash Backdoor and PrxClient Proxy (CVE-less LNK Campaign)
- [TL-2026-1695](https://intel.threadlinqs.com/threat/TL-2026-1695) — HIGH — Dolphin X Windows Infostealer Adds AI-Driven Victim Profiling and Polymorphic Panel
- [TL-2026-0723](https://intel.threadlinqs.com/threat/TL-2026-0723) — HIGH — Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian Organizations (update)
- [TL-2026-1604](https://intel.threadlinqs.com/threat/TL-2026-1604) — MEDIUM — Snowpick: Open-Source Scanner Exposes Widespread Unauthenticated Data Leakage in ServiceNow Instances (CVE-2025-3648 "Count(er) Strike" Context)
- [TL-2026-1607](https://intel.threadlinqs.com/threat/TL-2026-1607) — MEDIUM — AT&T-Themed Phishing Campaign Abuses Open Redirect Vulnerability (noSuchEntryRedirect) to Harvest SSN, Credit Card, and CVV Data
- [TL-2026-1608](https://intel.threadlinqs.com/threat/TL-2026-1608) — MEDIUM — International Law Enforcement Dismantles Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Behind 15,000 Monthly Microsoft 365 Credential-Harvesting Campaigns
- [TL-2026-1611](https://intel.threadlinqs.com/threat/TL-2026-1611) — MEDIUM — Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action Lawsuit (Alvarez v. Apple)
- [TL-2026-1613](https://intel.threadlinqs.com/threat/TL-2026-1613) — MEDIUM — Kratos Phishing-as-a-Service Platform Dismantled in Operation Olympus Blade — BKA/FBI/Indonesian Police Takedown of AiTM Microsoft 365 Credential Theft Kit
- [TL-2026-1619](https://intel.threadlinqs.com/threat/TL-2026-1619) — MEDIUM — Lampion Banking Trojan (ChePro Lineage) Multistage Phishing/Evasion Campaign Targets Portugal
- [TL-2026-1622](https://intel.threadlinqs.com/threat/TL-2026-1622) — MEDIUM — Vibe-Coded Applications Riddled With Exploitable Security Flaws — Theori Xint.io Study Finds 434 Issues Across AI-Generated Codebases
- [TL-2026-1623](https://intel.threadlinqs.com/threat/TL-2026-1623) — MEDIUM — CVE-2026-53910: Heap-Based Buffer Overflow in GNU diffutils diff3 (Signed Integer Overflow)
- [TL-2026-1634](https://intel.threadlinqs.com/threat/TL-2026-1634) — MEDIUM — Upbound Group Data Theft Enables $13M in Fraudulent Acima Lease-to-Own Fraud (Q2 2026)
- [TL-2026-1640](https://intel.threadlinqs.com/threat/TL-2026-1640) — MEDIUM — Kootenai County, Idaho Ransomware Attack Exposes Resident Personal Information
- [TL-2026-1642](https://intel.threadlinqs.com/threat/TL-2026-1642) — MEDIUM — Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransom
- [TL-2026-1644](https://intel.threadlinqs.com/threat/TL-2026-1644) — MEDIUM — Abuse of AWS Systems Manager (SSM) Agent as a Remote Access Trojan
- [TL-2026-1655](https://intel.threadlinqs.com/threat/TL-2026-1655) — MEDIUM — Everest Ransomware Group Demands $12.3M from Stadler Rail via Third-Party Supplier Breach
- [TL-2026-1710](https://intel.threadlinqs.com/threat/TL-2026-1710) — MEDIUM — Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands
- [TL-2026-1630](https://intel.threadlinqs.com/threat/TL-2026-1630) — INFORMATIONAL — SentinelLabs Benchmark: Frontier LLMs Attempt Autonomous Long-Horizon Malware Analysis Using the 2005 Pre-Stuxnet 'fast16' Sabotage Toolkit as Case Study

## Techniques observed

[T1001](https://intel.threadlinqs.com/technique/T1001), [T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.001](https://intel.threadlinqs.com/technique/T1003.001), [T1005](https://intel.threadlinqs.com/technique/T1005), T1006, [T1008](https://intel.threadlinqs.com/technique/T1008), [T1010](https://intel.threadlinqs.com/technique/T1010), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1025](https://intel.threadlinqs.com/technique/T1025), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.001](https://intel.threadlinqs.com/technique/T1027.001), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1037](https://intel.threadlinqs.com/technique/T1037), [T1039](https://intel.threadlinqs.com/technique/T1039), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.001](https://intel.threadlinqs.com/technique/T1055.001), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1056.002](https://intel.threadlinqs.com/technique/T1056.002), [T1056.003](https://intel.threadlinqs.com/technique/T1056.003), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), T1059.011, [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1069.001](https://intel.threadlinqs.com/technique/T1069.001), [T1069.002](https://intel.threadlinqs.com/technique/T1069.002), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.001, T1070.002, [T1070.003](https://intel.threadlinqs.com/technique/T1070.003), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1070.006](https://intel.threadlinqs.com/technique/T1070.006), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.001](https://intel.threadlinqs.com/technique/T1078.001), [T1078.002](https://intel.threadlinqs.com/technique/T1078.002), [T1078.003](https://intel.threadlinqs.com/technique/T1078.003), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.001](https://intel.threadlinqs.com/technique/T1087.001), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1087.004](https://intel.threadlinqs.com/technique/T1087.004), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.001](https://intel.threadlinqs.com/technique/T1098.001), [T1098.005](https://intel.threadlinqs.com/technique/T1098.005), T1098.007, [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.002](https://intel.threadlinqs.com/technique/T1110.002), [T1110.003](https://intel.threadlinqs.com/technique/T1110.003), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1114.002](https://intel.threadlinqs.com/technique/T1114.002), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1127](https://intel.threadlinqs.com/technique/T1127), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1132.001](https://intel.threadlinqs.com/technique/T1132.001), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1134.001](https://intel.threadlinqs.com/technique/T1134.001), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1218.005](https://intel.threadlinqs.com/technique/T1218.005), [T1218.010](https://intel.threadlinqs.com/technique/T1218.010), [T1218.011](https://intel.threadlinqs.com/technique/T1218.011), [T1219](https://intel.threadlinqs.com/technique/T1219), T1219.002, [T1222](https://intel.threadlinqs.com/technique/T1222), [T1222.002](https://intel.threadlinqs.com/technique/T1222.002), T1398, [T1407](https://intel.threadlinqs.com/technique/T1407), [T1417](https://intel.threadlinqs.com/technique/T1417), [T1417.002](https://intel.threadlinqs.com/technique/T1417.002), [T1418](https://intel.threadlinqs.com/technique/T1418), [T1437](https://intel.threadlinqs.com/technique/T1437), T1444, T1446, [T1456](https://intel.threadlinqs.com/technique/T1456), T1461, T1472, T1476, T1478, [T1480](https://intel.threadlinqs.com/technique/T1480), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1491.001](https://intel.threadlinqs.com/technique/T1491.001), [T1491.002](https://intel.threadlinqs.com/technique/T1491.002), [T1495](https://intel.threadlinqs.com/technique/T1495), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1498](https://intel.threadlinqs.com/technique/T1498), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), T1508, [T1513](https://intel.threadlinqs.com/technique/T1513), [T1517](https://intel.threadlinqs.com/technique/T1517), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1533](https://intel.threadlinqs.com/technique/T1533), [T1534](https://intel.threadlinqs.com/technique/T1534), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1538](https://intel.threadlinqs.com/technique/T1538), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1541](https://intel.threadlinqs.com/technique/T1541), [T1542](https://intel.threadlinqs.com/technique/T1542), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546](https://intel.threadlinqs.com/technique/T1546), T1546.016, T1546.017, [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), T1547.004, T1547.011, [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.001](https://intel.threadlinqs.com/technique/T1548.001), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1550.002](https://intel.threadlinqs.com/technique/T1550.002), T1550.003, [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1557.001](https://intel.threadlinqs.com/technique/T1557.001), [T1559](https://intel.threadlinqs.com/technique/T1559), [T1559.001](https://intel.threadlinqs.com/technique/T1559.001), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), T1562, T1562.001, T1562.002, T1562.004, T1562.007, T1562.008, T1562.009, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), T1564.002, [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1569.002](https://intel.threadlinqs.com/technique/T1569.002), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), T1574.002, [T1580](https://intel.threadlinqs.com/technique/T1580), [T1582](https://intel.threadlinqs.com/technique/T1582), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.008](https://intel.threadlinqs.com/technique/T1583.008), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1584.005](https://intel.threadlinqs.com/technique/T1584.005), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1585.002](https://intel.threadlinqs.com/technique/T1585.002), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1586.002](https://intel.threadlinqs.com/technique/T1586.002), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.003](https://intel.threadlinqs.com/technique/T1588.003), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.001](https://intel.threadlinqs.com/technique/T1589.001), [T1589.002](https://intel.threadlinqs.com/technique/T1589.002), [T1590](https://intel.threadlinqs.com/technique/T1590), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1593.001](https://intel.threadlinqs.com/technique/T1593.001), [T1594](https://intel.threadlinqs.com/technique/T1594), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.001](https://intel.threadlinqs.com/technique/T1595.001), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1596.005](https://intel.threadlinqs.com/technique/T1596.005), [T1598](https://intel.threadlinqs.com/technique/T1598), T1598.001, [T1598.003](https://intel.threadlinqs.com/technique/T1598.003), [T1598.004](https://intel.threadlinqs.com/technique/T1598.004), T1602.002, [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1610](https://intel.threadlinqs.com/technique/T1610), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1624](https://intel.threadlinqs.com/technique/T1624), [T1636.003](https://intel.threadlinqs.com/technique/T1636.003), [T1636.004](https://intel.threadlinqs.com/technique/T1636.004), [T1646](https://intel.threadlinqs.com/technique/T1646), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657), [T1660](https://intel.threadlinqs.com/technique/T1660)

## Threat actors

[Kratos PhaaS developer](https://intel.threadlinqs.com/actor/Kratos%20PhaaS%20developer), [Kratos PhaaS Operator](https://intel.threadlinqs.com/actor/Kratos%20PhaaS%20Operator), [Lampion](https://intel.threadlinqs.com/actor/Lampion), [Everest](https://intel.threadlinqs.com/actor/Everest), [Nitrogen](https://intel.threadlinqs.com/actor/Nitrogen), [Autonomous AI agent swarm](https://intel.threadlinqs.com/actor/Autonomous%20AI%20agent%20swarm), [GPT-5.6 Sol](https://intel.threadlinqs.com/actor/GPT-5.6%20Sol), [Kratos](https://intel.threadlinqs.com/actor/Kratos), [OpenAI internal evaluation models](https://intel.threadlinqs.com/actor/OpenAI%20internal%20evaluation%20models), [WageMole](https://intel.threadlinqs.com/actor/WageMole), [Anubis](https://intel.threadlinqs.com/actor/Anubis), [Kontraktnik](https://intel.threadlinqs.com/actor/Kontraktnik), [Royal Ransomware Group](https://intel.threadlinqs.com/actor/Royal%20Ransomware%20Group), [Ransomhouse](https://intel.threadlinqs.com/actor/Ransomhouse), [Kali365 PhaaS operators](https://intel.threadlinqs.com/actor/Kali365%20PhaaS%20operators), [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky), [Autonomous AI Agent](https://intel.threadlinqs.com/actor/Autonomous%20AI%20Agent), [Gamaredon and UAC-0226](https://intel.threadlinqs.com/actor/Gamaredon%20and%20UAC-0226), [UNC6240](https://intel.threadlinqs.com/actor/UNC6240), Lynx), [UTA0533](https://intel.threadlinqs.com/actor/UTA0533)

Nation-state attribution: Russia, North Korea, Indonesia

Threat categories: VULNERABILITY, PHISHING, CAMPAIGN, MALWARE, THREAT_INTEL, DATA_BREACH, RANSOMWARE, TTP, SUPPLY_CHAIN, ESPIONAGE

## Severity breakdown

- critical: 13
- high: 25
- medium: 14
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 1316 (behavioral 362, entity 196, network 195, file 172, tool 125, infrastructure 94, technique 77, malware 59, package 33, vulnerability 3)
- New detection rules: 477 (100% of the day’s threats covered)

## More editions

- Previous: [2026-07-21](https://intel.threadlinqs.com/debrief/2026-07-21)
- Next: [2026-07-23](https://intel.threadlinqs.com/debrief/2026-07-23)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-07-22
