Threadlinqs IntelligenceStart free

Daily debrief · Monday2026-07-27

Daily Intelligence Briefing — Monday, July 27, 2026

7 critical13 high6 medium1 low

On 2026-07-27, Threadlinqs published 22 new threat reports and updated 6, 7 rated critical and 13 high, spanning 288 MITRE ATT&CK techniques and 10 named threat actors. Coverage that day added 252 new detection rules and 964 extracted indicators.

New threats
226 updated
Critical / high
207 critical · 13 high
ATT&CK techniques
288Observed in the day’s reports
Threat actors
10Named in the reports
Indicators
964Count only · values are Red+
Detection rules
252New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Claude Code Symlink Flaw in Startup Memory Loader Enables Silent File Exfiltration via CLAUDE.md Imports. Aftercall: Android Adware Campaign Abuses Overlay/Full-Screen Permissions to Bombard Users with Post-Call Ads. UK Supreme Court Rejects Bahrain's State Immunity Claim in FinSpy/FinFisher Spyware Surveillance Case (Shehabi v Kingdom of Bahrain).

Highlights

  • TL-2026-1714 — npm Supply-Chain Compromise (chalk/debug + 17 packages, Sept 2025) — Motivates GitHub Dependabot 'Cooldown' Mitigation
  • TL-2026-1716 — MCBS Ransomware Data Breach: PEAR Extortion Group Exposes PII and Health Records of 1.26 Million Individuals Across Seven Healthcare Clients
  • TL-2026-1717 — SparkKitty: Cross-Platform iOS/Android Stealer Using OCR to Harvest Crypto Wallet Seed Phrases from App Store and Google Play
  • TL-2026-1719 — BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency Credentials via ClickFix and AI Deepfake Social Engineering
  • TL-2026-1720 — BlueNoroff Hijacks Trusted Telegram Accounts to Deliver ClickFix Malware via Deepfake Zoom/Teams Calls

Theme of the day

Financially motivated threat actors, including ShinyHunters, were active today. Social engineering and financial theft tactics were prominent.

  • data-exfiltration
  • social-engineering
  • financially-motivated
  • ransomware
  • credential-theft

Threats published

28 threat lines in the 2026-07-27 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

288 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

10 named threat actors across the reports.

Nation-state attribution

  • Bahrain
  • China / Russia (primary, per Wyden letter); Iran (documented in earlier exploitation of CVE-2019-11510)
  • Russia
  • North Korea (DPRK)
  • North Korea
  • North Korea (DPRK), China, Palestine, Pakistan
  • Russia (suspected, unconfirmed)
  • Nigeria
  • Iran

Threat categories

  • VULNERABILITY
  • MALWARE
  • THREAT_INTEL
  • PHISHING
  • SUPPLY_CHAIN
  • DATA_BREACH
  • RANSOMWARE
  • APT

Severity breakdown

  • critical7
  • high13
  • medium6
  • low1

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

964 indicators of compromise · Red and above. Compare plans
  • network 207
  • file 186
  • behavioral 179
  • entity 121
  • tool 75
  • malware 70
  • infrastructure 61
  • package 42
  • technique 21
  • financial 1
  • vulnerability 1
252 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans