Threadlinqs IntelligenceStart free

Daily debrief · Friday2026-07-31

Daily Intelligence Briefing — Friday, July 31, 2026

9 critical14 high4 medium

On 2026-07-31, Threadlinqs published 25 new threat reports and updated 3, 9 rated critical and 14 high, spanning 264 MITRE ATT&CK techniques and 10 named threat actors. Coverage that day added 252 new detection rules and 996 extracted indicators.

New threats
253 updated
Critical / high
239 critical · 14 high
ATT&CK techniques
264Observed in the day’s reports
Threat actors
10Named in the reports
Indicators
996Count only · values are Red+
Detection rules
252New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

ShutterGap: Ephemeral Public Exposure of AWS RDS/DocumentDB Snapshots, AMIs & SSM Documents Evades CSPM/CNAPP Scan Cycles. 1337_GWTK: Malware-as-a-Service C2 Platform Masquerading as Server Administration Tool (Markas Escobar). CVE-2026-17059: Keycloak Admin REST API Broken Object-Level Authorization Exposes User PII.

Highlights

  • TL-2026-1781 — Multiple Vulnerabilities in Citrix XenServer 8.4 and 9 Enable Guest-to-Host Escalation and Denial of Service (CVE-2026-42492, CVE-2026-62428, CVE-2026-62431, CVE-2026-62432, CVE-2026-62434, CVE-2026-62435, CVE-2026-62436)
  • TL-2026-1782 — Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52): Phar Symlink DoS, Bundled-libgd GIF Memory Corruption, pgsql SQL Injection, and BCMath Out-of-Bounds Write (CVE-2026-7260, CVE-2026-9672, CVE-2026-17543, CVE-2026-17544)
  • TL-2026-1783 — OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting Central Asian Government and Critical Infrastructure
  • TL-2026-1785 — Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign Self-Propagates Across Brazil
  • TL-2026-1786 — OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Theft

Theme of the day

Activity centered on active-exploitation, aes-encryption, agamemnon-downloader.

  • credential-theft
  • defense-evasion
  • remote-code-execution
  • data-exfiltration
  • c2-infrastructure

Threats published

28 threat lines in the 2026-07-31 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

264 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

10 named threat actors across the reports.

Nation-state attribution

  • Indonesia
  • China (assessed, medium confidence; unattributed to a known group)
  • China (assessed, medium confidence — not attributed to a named APT)
  • China
  • Russia (Storm-2372 attribution, medium confidence); criminal actors are not state-affiliated
  • North Korea (DPRK)
  • North Korea
  • Russia

Threat categories

  • VULNERABILITY
  • MALWARE
  • THREAT_INTEL
  • PHISHING
  • APT
  • SUPPLY_CHAIN
  • RANSOMWARE

Severity breakdown

  • critical9
  • high14
  • medium4
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

996 indicators of compromise · Red and above. Compare plans
  • network 253
  • file 204
  • behavioral 193
  • tool 77
  • entity 74
  • infrastructure 64
  • malware 60
  • package 34
  • technique 30
  • financial 7
252 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans