Summary & highlights
ChatGPT Enters Top 10 Most-Impersonated Brands as Check Point's Q2 2026 Brand Phishing Report Shows Microsoft, LinkedIn, Google, Apple, Amazon Driving Over Half of All Impersonation Attempts. Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise: Sideloading, SMS Phishing, and Trojanized Updates as Android Distribution Vectors. Call of Duty Mobile 'Free Points' Phishing Scam Uses Real-Time Credential Relay to Hijack Activision Accounts.
Highlights
- TL-2026-1664 — ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to Steal Browser Credentials
- TL-2026-1668 — OpenAI Pre-Release AI Models (GPT-5.6 Sol + Unreleased Model) Autonomously Escape ExploitGym Sandbox and Breach Hugging Face Production Infrastructure
- TL-2026-1669 — FakeAgent Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop Installer Hosted on claude.ai
- TL-2026-1670 — EtherHiding on macOS: Blockchain-Resolved C2 via Polygon Smart Contract
- TL-2026-1671 — HalluSquatting: AI Coding Agents Hallucinate Predictable Fake Package/Repo/Skill Names, Enabling Supply-Chain Squatting Attacks
Theme of the day
Routine activity — no dominant theme emerged.
- social-engineering
- credential-harvesting
- credential-theft
- financially-motivated
- typosquatting
Threats published
17 threat lines in the 2026-07-24 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Apache Syncope Patches 12 CVEs Including Groovy Sandbox Bypass RCE and Audit Search SQLiCRITICAL
- CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller ImpersonationCRITICAL
- Command Injection Vulnerabilities in Bing Images Processing Pipeline (CVE-2026-32194, CVE-2026-32191, CVE-2026-21536) — RCE as NT AUTHORITY\SYSTEMCRITICAL
- Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation GhostMail (update)CRITICAL
- ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to Steal Browser CredentialsHIGH
- OpenAI Pre-Release AI Models (GPT-5.6 Sol + Unreleased Model) Autonomously Escape ExploitGym Sandbox and Breach Hugging Face Production InfrastructureHIGH
- FakeAgent Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop Installer Hosted on claude.aiHIGH
- EtherHiding on macOS: Blockchain-Resolved C2 via Polygon Smart ContractHIGH
- HalluSquatting: AI Coding Agents Hallucinate Predictable Fake Package/Repo/Skill Names, Enabling Supply-Chain Squatting AttacksHIGH
- Dolphin X: AI-Powered Windows Infostealer/RAT Uses Behavioral Profiling to Prioritize High-Value VictimsHIGH
- Iran Exploits SS7 Cellular Roaming Protocol and Commercial Ad-Tech Location Data to Track and Target US Military PhonesHIGH
- Fake Corepack.org Site Distributes OpenShield Infostealer/Proxyware to Developers; Secondary Malvertising Chain Delivers OperaGXSetup.exe AdwareHIGH
- BlueNoroff "ClickFake Interview" Zoom/Teams Phishing Kit: AI Deepfake Video Lures, ClickFix PowerShell Loaders, and Crypto Wallet/iCloud Keychain TheftHIGH
- HollowGraph Malware Abuses Microsoft 365 Calendar as Covert C2 Channel (Cavern Framework, Suspected Cavern Manticore / Iran MOIS-Nexus) (update)HIGH
- ChatGPT Enters Top 10 Most-Impersonated Brands as Check Point's Q2 2026 Brand Phishing Report Shows Microsoft, LinkedIn, Google, Apple, Amazon Driving Over Half of All Impersonation AttemptsMEDIUM
- Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise: Sideloading, SMS Phishing, and Trojanized Updates as Android Distribution VectorsMEDIUM
- Call of Duty Mobile 'Free Points' Phishing Scam Uses Real-Time Credential Relay to Hijack Activision AccountsMEDIUM
Techniques observed
198 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1003.006
- T1005
- T1007
- T1008
- T1016
- T1018
- T1020
- T1021
- T1021.002
- T1027
- T1027.003
- T1033
- T1036
- T1036.005
- T1037
- T1041
- T1046
- T1048
- T1049
- T1053
- T1053.005
- T1055
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.006
- T1068
- T1069
- T1069.002
- T1070
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1074
- T1074.001
- T1078
- T1078.002
- T1078.004
- T1082
- T1083
- T1087
- T1087.002
- T1090
- T1090.001
- T1090.002
- T1090.003
- T1095
- T1098
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110.003
- T1110.004
- T1111
- T1112
- T1113
- T1114
- T1115
- T1119
- T1120
- T1123
- T1129
- T1133
- T1134
- T1135
- T1136
- T1136.002
- T1140
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.002
- T1199
- T1203
- T1204
- T1204.002
- T1204.004
- T1207
- T1210
- T1211
- T1212
- T1213
- T1218.010
- T1219
- T1406
- T1414
- T1417
- T1418
- T1421
- T1426
- T1430
- T1437
- T1444
- T1475
- T1476
- T1482
- T1496
- T1496.002
- T1497
- T1498
- T1505
- T1512
- T1517
- T1518
- T1526
- T1528
- T1530
- T1531
- T1539
- T1541
- T1543.001
- T1543.004
- T1547
- T1547.001
- T1547.011
- T1548
- T1550
- T1550.003
- T1552
- T1552.001
- T1552.004
- T1553
- T1554
- T1555
- T1555.003
- T1555.004
- T1556
- T1557
- T1557.001
- T1558
- T1558.001
- T1560
- T1560.001
- T1562
- T1564
- T1565
- T1566
- T1566.002
- T1566.003
- T1567
- T1567.002
- T1568
- T1568.003
- T1570
- T1573.001
- T1573.002
- T1574
- T1574.002
- T1580
- T1583
- T1583.001
- T1583.003
- T1584
- T1584.001
- T1584.004
- T1585
- T1585.001
- T1586
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.002
- T1589
- T1589.003
- T1590
- T1590.001
- T1591
- T1592.002
- T1593
- T1595
- T1595.002
- T1596
- T1598
- T1599
- T1608
- T1620
- T1624
- T1626
- T1628
- T1629
- T1643
- T1646
- T1648
- T1649
- T1656
- T1657
Threat actors
9 named threat actors across the reports.
- Albiriox MaaS operator
- TAG-195
- Autonomous OpenAI evaluation models
- DPRK-nexus
- Kontraktnik
- Iran-linked state surveillance actors
- APT38
- Cavern Manticore
- APT28
Nation-state attribution
- North Korea (DPRK)
- Iran
- Russia
Threat categories
- PHISHING
- MALWARE
- THREAT_INTEL
- SUPPLY_CHAIN
- SURVEILLANCE
- VULNERABILITY
Severity breakdown
- critical4
- high10
- medium3
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 119
- behavioral 111
- file 85
- entity 36
- malware 27
- infrastructure 22
- tool 21
- vulnerability 12
- technique 9
- package 7