Threadlinqs IntelligenceStart free

Daily debrief · Saturday2026-07-25

Daily Intelligence Briefing — Saturday, July 25, 2026

8 critical18 high3 medium1 low

On 2026-07-25, Threadlinqs published 20 new threat reports and updated 10, 8 rated critical and 18 high, spanning 213 MITRE ATT&CK techniques and 10 named threat actors. Coverage that day added 270 new detection rules and 841 extracted indicators.

New threats
2010 updated
Critical / high
268 critical · 18 high
ATT&CK techniques
213Observed in the day’s reports
Threat actors
10Named in the reports
Indicators
841Count only · values are Red+
Detection rules
270New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Everest Ransomware Gang Extorts Stadler Rail via Compromised Supplier Credentials, CHF 10M Demand Refused. AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and AI-Driven EDR Evasion (STAC6994, UNC6395, NadMesh). Proofpoint 2026 AI-Era Ransomware Report: 65% of Victims Report AI Increased Attack Effectiveness.

Highlights

  • TL-2026-1679 — InsureOTP Kit: Real-Time OTP Interception Phishing Campaign Targeting Insurance Providers (CTM360)
  • TL-2026-1687 — SourTrade Malvertising Campaign Assembles Windows Malware In-Browser via ServiceWorker/SharedWorker JavaScript Chain to Defeat Hash-Based Detection
  • TL-2026-1691 — GitLab RCE via Chained Oj JSON Parser Memory-Safety Flaws (Code Execution as 'git' User)
  • TL-2026-1692 — Exim Directory Traversal (CVE-2026-66140, CVSS 8.4) and .forward Privilege Escalation (CVE-2026-66141, CVSS 7.4) Enable Local Privilege Escalation via Queue-Name Argument and force_command Abuse
  • TL-2026-1693 — Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar 2.0, StealC, AMOS/MacSync/Poseidon/Odyssey)

Theme of the day

Routine activity — no dominant theme emerged.

  • credential-theft
  • data-exfiltration
  • financially-motivated
  • coordinated-disclosure
  • privilege-escalation

Threats published

30 threat lines in the 2026-07-25 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

213 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

10 named threat actors across the reports.

Nation-state attribution

  • Russia
  • Iran

Threat categories

  • RANSOMWARE
  • THREAT_INTEL
  • PHISHING
  • MALWARE
  • VULNERABILITY
  • SUPPLY_CHAIN
  • ICS_SCADA

Severity breakdown

  • critical8
  • high18
  • medium3
  • low1

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

841 indicators of compromise · Red and above. Compare plans
  • behavioral 238
  • entity 129
  • file 113
  • network 100
  • tool 92
  • infrastructure 55
  • malware 45
  • package 43
  • technique 25
  • vulnerability 1
270 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans