# Daily Intelligence Briefing — Saturday, July 25, 2026

> On 2026-07-25, Threadlinqs published 20 new threat reports and updated 10, 8 rated critical and 18 high, spanning 213 MITRE ATT&CK techniques and 10 named threat actors. Coverage that day added 270 new detection rules and 841 extracted indicators.

- **Edition:** 2026-07-25 (Saturday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-07-25
- **Last updated:** 2026-07-30
- **New threats:** 20 (10 updated)
- **Critical / high:** 8 critical, 18 high, 3 medium, 1 low
- **ATT&CK techniques:** 213
- **Threat actors:** 10
- **Indicators (count only):** 841
- **New detection rules (count only):** 270

## Summary & highlights

Everest Ransomware Gang Extorts Stadler Rail via Compromised Supplier Credentials, CHF 10M Demand Refused. AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and AI-Driven EDR Evasion (STAC6994, UNC6395, NadMesh). Proofpoint 2026 AI-Era Ransomware Report: 65% of Victims Report AI Increased Attack Effectiveness.

- [TL-2026-1679](https://intel.threadlinqs.com/threat/TL-2026-1679) — InsureOTP Kit: Real-Time OTP Interception Phishing Campaign Targeting Insurance Providers (CTM360)
- [TL-2026-1687](https://intel.threadlinqs.com/threat/TL-2026-1687) — SourTrade Malvertising Campaign Assembles Windows Malware In-Browser via ServiceWorker/SharedWorker JavaScript Chain to Defeat Hash-Based Detection
- [TL-2026-1691](https://intel.threadlinqs.com/threat/TL-2026-1691) — GitLab RCE via Chained Oj JSON Parser Memory-Safety Flaws (Code Execution as 'git' User)
- [TL-2026-1692](https://intel.threadlinqs.com/threat/TL-2026-1692) — Exim Directory Traversal (CVE-2026-66140, CVSS 8.4) and .forward Privilege Escalation (CVE-2026-66141, CVSS 7.4) Enable Local Privilege Escalation via Queue-Name Argument and force_command Abuse
- [TL-2026-1693](https://intel.threadlinqs.com/threat/TL-2026-1693) — Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar 2.0, StealC, AMOS/MacSync/Poseidon/Odyssey)

## Theme of the day

Routine activity — no dominant theme emerged.

credential-theft, data-exfiltration, financially-motivated, coordinated-disclosure, privilege-escalation

## Threats published

- [TL-2026-1680](https://intel.threadlinqs.com/threat/TL-2026-1680) — CRITICAL — DevMan RaaS ("Funky Mantis") Centralizes Payload Builds, Victim Management, and Affiliate Payouts, Develops SCADA-Destructive Locker
- [TL-2026-1681](https://intel.threadlinqs.com/threat/TL-2026-1681) — CRITICAL — Compromised Packagist PHP Packages Weaponize GitHub Actions Runners to Target cPanel/WHM Servers (CVE-2026-41940)
- [TL-2026-1682](https://intel.threadlinqs.com/threat/TL-2026-1682) — CRITICAL — Fastjson 1.x RCE (CVE-2026-16723) — Gadget-Free Deserialization Bypass Actively Exploited in Spring Boot Fat-JAR Deployments
- [TL-2026-1689](https://intel.threadlinqs.com/threat/TL-2026-1689) — CRITICAL — Critical FreeRDP Clipboard Virtual Channel Heap Buffer Overflow (GHSA-cj9v-h4hq-29jr, CVSS 9.4)
- [TL-2026-1697](https://intel.threadlinqs.com/threat/TL-2026-1697) — CRITICAL — Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A)
- [TL-2026-1364](https://intel.threadlinqs.com/threat/TL-2026-1364) — CRITICAL — Actively Exploited SharePoint Server Elevation of Privilege Flaw (CVE-2026-56164) Patched Alongside Critical RCE Pair in July 2026 Patch Tuesday (update)
- [TL-2026-1390](https://intel.threadlinqs.com/threat/TL-2026-1390) — CRITICAL — SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day Exploitation (update)
- [TL-2026-1688](https://intel.threadlinqs.com/threat/TL-2026-1688) — CRITICAL — Critical FreePBX Flaws Enable Unauthenticated RCE (UCP Socket.IO Auth Bypass) and SQL Injection Leading to Admin Takeover (update)
- [TL-2026-1679](https://intel.threadlinqs.com/threat/TL-2026-1679) — HIGH — InsureOTP Kit: Real-Time OTP Interception Phishing Campaign Targeting Insurance Providers (CTM360)
- [TL-2026-1687](https://intel.threadlinqs.com/threat/TL-2026-1687) — HIGH — SourTrade Malvertising Campaign Assembles Windows Malware In-Browser via ServiceWorker/SharedWorker JavaScript Chain to Defeat Hash-Based Detection
- [TL-2026-1691](https://intel.threadlinqs.com/threat/TL-2026-1691) — HIGH — GitLab RCE via Chained Oj JSON Parser Memory-Safety Flaws (Code Execution as 'git' User)
- [TL-2026-1692](https://intel.threadlinqs.com/threat/TL-2026-1692) — HIGH — Exim Directory Traversal (CVE-2026-66140, CVSS 8.4) and .forward Privilege Escalation (CVE-2026-66141, CVSS 7.4) Enable Local Privilege Escalation via Queue-Name Argument and force_command Abuse
- [TL-2026-1693](https://intel.threadlinqs.com/threat/TL-2026-1693) — HIGH — Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar 2.0, StealC, AMOS/MacSync/Poseidon/Odyssey)
- [TL-2026-1694](https://intel.threadlinqs.com/threat/TL-2026-1694) — HIGH — msaRAT: Rust-based RAT Hides C2 in Browser Process, Tied to Chaos Ransomware RaaS
- [TL-2026-1696](https://intel.threadlinqs.com/threat/TL-2026-1696) — HIGH — SourTrade Malvertising: ServiceWorker-Orchestrated In-Browser Assembly Builds a Unique Windows Executable Per Victim
- [TL-2026-1698](https://intel.threadlinqs.com/threat/TL-2026-1698) — HIGH — Dolphin X Stealer: AI-Profiled Windows Infostealer/RAT Targeting 300+ Applications
- [TL-2026-1699](https://intel.threadlinqs.com/threat/TL-2026-1699) — HIGH — KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars
- [TL-2026-1701](https://intel.threadlinqs.com/threat/TL-2026-1701) — HIGH — KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and Immobilization
- [TL-2026-1754](https://intel.threadlinqs.com/threat/TL-2026-1754) — HIGH — Larva-26009 MS-SQL Server Intrusion Campaign Deploys XMRig, VShell, SoftEther VPN via Multi-Tool Toolkit
- [TL-2026-1629](https://intel.threadlinqs.com/threat/TL-2026-1629) — HIGH — RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600) (update)
- [TL-2026-1633](https://intel.threadlinqs.com/threat/TL-2026-1633) — HIGH — CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to Root (update)
- [TL-2026-1637](https://intel.threadlinqs.com/threat/TL-2026-1637) — HIGH — CVE-2026-48294 ("HermeticReader"): Adobe Acrobat Chrome Extension Flaw Chain Enables Silent WhatsApp Web Data Theft (update)
- [TL-2026-1663](https://intel.threadlinqs.com/threat/TL-2026-1663) — HIGH — Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge (update)
- [TL-2026-1684](https://intel.threadlinqs.com/threat/TL-2026-1684) — HIGH — TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2 (update)
- [TL-2026-1690](https://intel.threadlinqs.com/threat/TL-2026-1690) — HIGH — Redis Streams Shared-NACK Double-Free (CVE-2026-25243) & RedisBloom RESTORE/TDigest Heap Overflow (CVE-2026-25589) — Authenticated RCE, Public PoC, Patch Bypass (update)
- [TL-2026-1695](https://intel.threadlinqs.com/threat/TL-2026-1695) — HIGH — Dolphin X Windows Infostealer Adds AI-Driven Victim Profiling and Polymorphic Panel (update)
- [TL-2026-1683](https://intel.threadlinqs.com/threat/TL-2026-1683) — MEDIUM — Everest Ransomware Gang Extorts Stadler Rail via Compromised Supplier Credentials, CHF 10M Demand Refused
- [TL-2026-1686](https://intel.threadlinqs.com/threat/TL-2026-1686) — MEDIUM — AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and AI-Driven EDR Evasion (STAC6994, UNC6395, NadMesh)
- [TL-2026-1702](https://intel.threadlinqs.com/threat/TL-2026-1702) — MEDIUM — Proofpoint 2026 AI-Era Ransomware Report: 65% of Victims Report AI Increased Attack Effectiveness
- [TL-2026-1685](https://intel.threadlinqs.com/threat/TL-2026-1685) — LOW — ShinyHunters-Impersonation Sextortion Scam Abuses Emails From 8 Prior Data Leaks, Demands $2,000

## Techniques observed

[T1001](https://intel.threadlinqs.com/technique/T1001), [T1003](https://intel.threadlinqs.com/technique/T1003), [T1005](https://intel.threadlinqs.com/technique/T1005), T1006, [T1008](https://intel.threadlinqs.com/technique/T1008), [T1010](https://intel.threadlinqs.com/technique/T1010), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.004](https://intel.threadlinqs.com/technique/T1021.004), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.008](https://intel.threadlinqs.com/technique/T1036.008), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), T1059.010, [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.001, [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1074.001](https://intel.threadlinqs.com/technique/T1074.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.002](https://intel.threadlinqs.com/technique/T1078.002), [T1078.003](https://intel.threadlinqs.com/technique/T1078.003), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1120](https://intel.threadlinqs.com/technique/T1120), [T1129](https://intel.threadlinqs.com/technique/T1129), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1132.001](https://intel.threadlinqs.com/technique/T1132.001), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), T1197, [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1205](https://intel.threadlinqs.com/technique/T1205), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1213.002](https://intel.threadlinqs.com/technique/T1213.002), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1218.005](https://intel.threadlinqs.com/technique/T1218.005), [T1218.007](https://intel.threadlinqs.com/technique/T1218.007), T1218.015, [T1219](https://intel.threadlinqs.com/technique/T1219), [T1222](https://intel.threadlinqs.com/technique/T1222), [T1222.002](https://intel.threadlinqs.com/technique/T1222.002), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1484](https://intel.threadlinqs.com/technique/T1484), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1498](https://intel.threadlinqs.com/technique/T1498), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1546](https://intel.threadlinqs.com/technique/T1546), T1546.016, T1546.017, [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.001](https://intel.threadlinqs.com/technique/T1548.001), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1555.004](https://intel.threadlinqs.com/technique/T1555.004), [T1555.005](https://intel.threadlinqs.com/technique/T1555.005), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1559](https://intel.threadlinqs.com/technique/T1559), [T1560](https://intel.threadlinqs.com/technique/T1560), T1562, T1562.001, T1562.004, T1562.007, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1564.003](https://intel.threadlinqs.com/technique/T1564.003), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.004](https://intel.threadlinqs.com/technique/T1566.004), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), T1574.002, [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.008](https://intel.threadlinqs.com/technique/T1583.008), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1584.001](https://intel.threadlinqs.com/technique/T1584.001), [T1584.004](https://intel.threadlinqs.com/technique/T1584.004), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1592](https://intel.threadlinqs.com/technique/T1592), T1592.001, [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1592.004](https://intel.threadlinqs.com/technique/T1592.004), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1596.005](https://intel.threadlinqs.com/technique/T1596.005), T1597, [T1598](https://intel.threadlinqs.com/technique/T1598), [T1598.003](https://intel.threadlinqs.com/technique/T1598.003), [T1606](https://intel.threadlinqs.com/technique/T1606), T1606.002, [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1622](https://intel.threadlinqs.com/technique/T1622), [T1650](https://intel.threadlinqs.com/technique/T1650), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657)

## Threat actors

[Everest](https://intel.threadlinqs.com/actor/Everest), [Infostealer MaaS Operators](https://intel.threadlinqs.com/actor/Infostealer%20MaaS%20Operators), [Chaos Ransomware-as-a-Service Group](https://intel.threadlinqs.com/actor/Chaos%20Ransomware-as-a-Service%20Group), [Kontraktnik](https://intel.threadlinqs.com/actor/Kontraktnik), [Larva-26009](https://intel.threadlinqs.com/actor/Larva-26009), [DevMan](https://intel.threadlinqs.com/actor/DevMan), [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers), [Chaos](https://intel.threadlinqs.com/actor/Chaos), [Periwinkle Tempest](https://intel.threadlinqs.com/actor/Periwinkle%20Tempest), [UTA0533](https://intel.threadlinqs.com/actor/UTA0533)

Nation-state attribution: Russia, Iran

Threat categories: RANSOMWARE, THREAT_INTEL, PHISHING, MALWARE, VULNERABILITY, SUPPLY_CHAIN, ICS_SCADA

## Severity breakdown

- critical: 8
- high: 18
- medium: 3
- low: 1

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 841 (behavioral 238, entity 129, file 113, network 100, tool 92, infrastructure 55, malware 45, package 43, technique 25, vulnerability 1)
- New detection rules: 270 (100% of the day’s threats covered)

## More editions

- Previous: [2026-07-24](https://intel.threadlinqs.com/debrief/2026-07-24)
- Next: [2026-07-27](https://intel.threadlinqs.com/debrief/2026-07-27)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-07-25
