Threadlinqs IntelligenceStart free

Daily debrief · Wednesday2026-07-29

Daily Intelligence Briefing — Wednesday, July 29, 2026

11 critical10 high2 medium1 low

On 2026-07-29, Threadlinqs published 20 new threat reports and updated 4, 11 rated critical and 10 high, spanning 221 MITRE ATT&CK techniques and 6 named threat actors. Coverage that day added 216 new detection rules and 847 extracted indicators.

New threats
204 updated
Critical / high
2111 critical · 10 high
ATT&CK techniques
221Observed in the day’s reports
Threat actors
6Named in the reports
Indicators
847Count only · values are Red+
Detection rules
216New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groups. Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments. Research: Android ML Malware Detectors Collapse Without Context-Stage Analysis (PRAXIS vs. Drebin, MalScan, MsDroid, MaskDroid, LAMD, ForeDroid).

Highlights

  • TL-2026-1751 — US FCC Bans Imported Advanced Robots Over Supply-Chain Risk and UniPwn-Class Takeover Vulnerabilities (CVE-2025-35027)
  • TL-2026-1757 — Flying Eagle Android RAT: Leaked Source Code Powers 170 Active C2 Servers, Successor "Night Dragon" Emerges
  • TL-2026-1758 — Tengu: New Mirai-Variant Botnet Targeting Linux IoT and Android TV Devices via Telnet Brute-Force
  • TL-2026-1806 — GitLab Patches 13 Security Flaws (incl. CVE-2026-6267, CVE-2026-12436) Enabling Data Exposure, CI/CD Tampering, and DoS
  • TL-2026-1811 — AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session Theft

Theme of the day

  • remote-code-execution
  • patch-management
  • security-advisory
  • credential-theft
  • critical-severity

Threats published

24 threat lines in the 2026-07-29 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

221 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

6 named threat actors across the reports.

Nation-state attribution

  • China
  • Russia
  • North Korea (DPRK)
  • Iran

Threat categories

  • RANSOMWARE
  • FRAUD
  • THREAT_INTEL
  • SUPPLY_CHAIN
  • MALWARE
  • VULNERABILITY
  • PHISHING
  • DATA_BREACH

Severity breakdown

  • critical11
  • high10
  • medium2
  • low1

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

847 indicators of compromise · Red and above. Compare plans
  • behavioral 203
  • file 133
  • entity 131
  • network 121
  • tool 71
  • infrastructure 64
  • package 55
  • technique 42
  • malware 25
  • vulnerability 2
216 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans