# Daily Intelligence Briefing — Monday, August 3, 2026

> On 2026-08-03, Threadlinqs published 28 new threat reports and updated 7, 14 rated critical and 16 high, spanning 290 MITRE ATT&CK techniques and 14 named threat actors. Coverage that day added 315 new detection rules and 1002 extracted indicators.

- **Edition:** 2026-08-03 (Monday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-08-03
- **Last updated:** 2026-08-09
- **New threats:** 28 (7 updated)
- **Critical / high:** 14 critical, 16 high, 3 medium, 2 low
- **ATT&CK techniques:** 290
- **Threat actors:** 14
- **Indicators (count only):** 1002
- **New detection rules (count only):** 315

## Summary & highlights

GovCERT.HK Security Alert A26-08-01: Multiple Vulnerabilities in Microsoft Edge, Office 2019/LTSC 2021/LTSC 2024, Excel 2016, and Microsoft 365 Apps for Enterprise. ModernStealer: Cross-Platform Dark Web/Telegram Broker Network Claims Sale of Government and Defense Data. EU AI Act Article 50 Enforcement — Regulatory Transparency Obligations and Documented Cybersecurity Attack Surface from AI Content Provenance Bypass Techniques.

- [TL-2026-1825](https://intel.threadlinqs.com/threat/TL-2026-1825) — CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligence
- [TL-2026-1831](https://intel.threadlinqs.com/threat/TL-2026-1831) — CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of Disclosure
- [TL-2026-1832](https://intel.threadlinqs.com/threat/TL-2026-1832) — Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal Credentials, SMS/OTPs, and Banking Data
- [TL-2026-1833](https://intel.threadlinqs.com/threat/TL-2026-1833) — Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoor
- [TL-2026-1834](https://intel.threadlinqs.com/threat/TL-2026-1834) — Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000

## Theme of the day

Activity centered on 2fa-bypass, access-control-violation, account-discovery-risk.

credential-theft, cisa-kev, social-engineering, authentication-bypass, active-exploitation

## Threats published

- [TL-2026-1829](https://intel.threadlinqs.com/threat/TL-2026-1829) — CRITICAL — Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addresses
- [TL-2026-1830](https://intel.threadlinqs.com/threat/TL-2026-1830) — CRITICAL — N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeover
- [TL-2026-1835](https://intel.threadlinqs.com/threat/TL-2026-1835) — CRITICAL — Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) Linked to $88.6M Multi-Wave Bitcoin Theft
- [TL-2026-1838](https://intel.threadlinqs.com/threat/TL-2026-1838) — CRITICAL — CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29) compromises hotel WiFi gateways globally for credential theft and malware delivery
- [TL-2026-1839](https://intel.threadlinqs.com/threat/TL-2026-1839) — CRITICAL — XCSSET v40 — macOS Developer Supply-Chain Malware Infecting Xcode Projects with Chrome CDP Hijacking and Telegram Trojanization
- [TL-2026-1840](https://intel.threadlinqs.com/threat/TL-2026-1840) — CRITICAL — Coldcard Firmware RNG Flaw Enables Coordinated Bitcoin Wallet Theft ($70.2M Drained)
- [TL-2026-1848](https://intel.threadlinqs.com/threat/TL-2026-1848) — CRITICAL — Coldcard/Coinkite Hardware Wallet RNG Vulnerability Exploited — $88M+ Bitcoin Stolen
- [TL-2026-1851](https://intel.threadlinqs.com/threat/TL-2026-1851) — CRITICAL — CVE-2026-16812 — Critical Unauthenticated OS Command Injection in Arista VeloCloud Orchestrator Actively Exploited
- [TL-2026-1855](https://intel.threadlinqs.com/threat/TL-2026-1855) — CRITICAL — Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command Execution on Security Management Server
- [TL-2026-0245](https://intel.threadlinqs.com/threat/TL-2026-0245) — CRITICAL — DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors (CVE-2026-20700, CVE-2025-43529, CVE-2025-31277) (update)
- [TL-2026-0335](https://intel.threadlinqs.com/threat/TL-2026-0335) — CRITICAL — Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A) (update)
- [TL-2026-0718](https://intel.threadlinqs.com/threat/TL-2026-0718) — CRITICAL — Check Point Remote Access & Mobile Access VPN IKEv1 Authentication Bypass (CVE-2026-50751) Exploited by Qilin Ransomware Affiliate (update)
- [TL-2026-1755](https://intel.threadlinqs.com/threat/TL-2026-1755) — CRITICAL — CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated Arbitrary File Read / RCE via libvips Image Processing (update)
- [TL-2026-1759](https://intel.threadlinqs.com/threat/TL-2026-1759) — CRITICAL — CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV (update)
- [TL-2026-1825](https://intel.threadlinqs.com/threat/TL-2026-1825) — HIGH — CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligence
- [TL-2026-1831](https://intel.threadlinqs.com/threat/TL-2026-1831) — HIGH — CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of Disclosure
- [TL-2026-1832](https://intel.threadlinqs.com/threat/TL-2026-1832) — HIGH — Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal Credentials, SMS/OTPs, and Banking Data
- [TL-2026-1833](https://intel.threadlinqs.com/threat/TL-2026-1833) — HIGH — Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoor
- [TL-2026-1834](https://intel.threadlinqs.com/threat/TL-2026-1834) — HIGH — Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000
- [TL-2026-1837](https://intel.threadlinqs.com/threat/TL-2026-1837) — HIGH — 1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)
- [TL-2026-1841](https://intel.threadlinqs.com/threat/TL-2026-1841) — HIGH — Inside the Underground Business of the BTMOB Android RAT Malware-as-a-Service
- [TL-2026-1842](https://intel.threadlinqs.com/threat/TL-2026-1842) — HIGH — Pass-ta-key: Novel Attack Surface in Google Password Manager Synced Passkey Authentication
- [TL-2026-1843](https://intel.threadlinqs.com/threat/TL-2026-1843) — HIGH — Google Password Manager — Three Post-Compromise Attack Paths Against Chrome Cloud Authenticator (Pass-ta-key / Silver Pass-ta-key / Golden Pass-ta-key)
- [TL-2026-1844](https://intel.threadlinqs.com/threat/TL-2026-1844) — HIGH — BINDCLOAK Backdoor Campaign Targeting Middle East Government Entities
- [TL-2026-1845](https://intel.threadlinqs.com/threat/TL-2026-1845) — HIGH — Fake AI Developer Tool Installers Delivering Infostealer via SEO Poisoning and Typosquatting
- [TL-2026-1846](https://intel.threadlinqs.com/threat/TL-2026-1846) — HIGH — Fake Roblox Xeno Script Launcher Pushes Multi-Stage Java-Based Infostealer and RAT Malware (Powercat Campaign)
- [TL-2026-1847](https://intel.threadlinqs.com/threat/TL-2026-1847) — HIGH — DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via Steganography
- [TL-2026-1852](https://intel.threadlinqs.com/threat/TL-2026-1852) — HIGH — Pass-ta-key Attacks Enable Malware to Hijack Google-Synced Passkeys via Chrome/TPM/Google Cloud Authenticator Weaknesses
- [TL-2026-1808](https://intel.threadlinqs.com/threat/TL-2026-1808) — HIGH — CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver CornFlake RAT and Steal Microsoft 365 Tokens (update)
- [TL-2026-1849](https://intel.threadlinqs.com/threat/TL-2026-1849) — HIGH — 18 Malicious npm Packages Deliver Cross-Platform RAT Targeting Alibaba Developer Tool Users (update)
- [TL-2026-1827](https://intel.threadlinqs.com/threat/TL-2026-1827) — MEDIUM — GovCERT.HK Security Alert A26-08-01: Multiple Vulnerabilities in Microsoft Edge, Office 2019/LTSC 2021/LTSC 2024, Excel 2016, and Microsoft 365 Apps for Enterprise
- [TL-2026-1836](https://intel.threadlinqs.com/threat/TL-2026-1836) — MEDIUM — ModernStealer: Cross-Platform Dark Web/Telegram Broker Network Claims Sale of Government and Defense Data
- [TL-2026-1850](https://intel.threadlinqs.com/threat/TL-2026-1850) — MEDIUM — EU AI Act Article 50 Enforcement — Regulatory Transparency Obligations and Documented Cybersecurity Attack Surface from AI Content Provenance Bypass Techniques
- [TL-2026-1826](https://intel.threadlinqs.com/threat/TL-2026-1826) — LOW — Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraud
- [TL-2026-1828](https://intel.threadlinqs.com/threat/TL-2026-1828) — LOW — NVIDIA Releases SkillSpector: Open-Source Security Scanner for AI Agent Skills

## Techniques observed

T0806, T0807, T0809, T0811, T0813, T0814, T0819, T0821, T0822, T0826, T0828, T0829, [T0831](https://intel.threadlinqs.com/technique/T0831), T0835, T0836, T0837, T0838, T0843, T0846, T0853, T0858, T0859, T0861, T0866, T0868, T0869, T0878, T0880, T0883, T0884, T0885, T0886, T0888, T0889, [T1003](https://intel.threadlinqs.com/technique/T1003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1007](https://intel.threadlinqs.com/technique/T1007), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1010](https://intel.threadlinqs.com/technique/T1010), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1021.004](https://intel.threadlinqs.com/technique/T1021.004), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.003](https://intel.threadlinqs.com/technique/T1027.003), T1029, [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.003](https://intel.threadlinqs.com/technique/T1036.003), [T1036.004](https://intel.threadlinqs.com/technique/T1036.004), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1037](https://intel.threadlinqs.com/technique/T1037), [T1039](https://intel.threadlinqs.com/technique/T1039), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1049](https://intel.threadlinqs.com/technique/T1049), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), T1055.009, [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1072](https://intel.threadlinqs.com/technique/T1072), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.003](https://intel.threadlinqs.com/technique/T1078.003), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.001](https://intel.threadlinqs.com/technique/T1087.001), [T1087.004](https://intel.threadlinqs.com/technique/T1087.004), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.001](https://intel.threadlinqs.com/technique/T1098.001), [T1098.005](https://intel.threadlinqs.com/technique/T1098.005), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.002](https://intel.threadlinqs.com/technique/T1110.002), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1120](https://intel.threadlinqs.com/technique/T1120), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1132.001](https://intel.threadlinqs.com/technique/T1132.001), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), T1134.003, [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.003](https://intel.threadlinqs.com/technique/T1195.003), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), T1218.003, [T1218.005](https://intel.threadlinqs.com/technique/T1218.005), [T1218.007](https://intel.threadlinqs.com/technique/T1218.007), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1222.002](https://intel.threadlinqs.com/technique/T1222.002), T1398, [T1406](https://intel.threadlinqs.com/technique/T1406), [T1407](https://intel.threadlinqs.com/technique/T1407), [T1414](https://intel.threadlinqs.com/technique/T1414), [T1417](https://intel.threadlinqs.com/technique/T1417), [T1418](https://intel.threadlinqs.com/technique/T1418), [T1420](https://intel.threadlinqs.com/technique/T1420), [T1422](https://intel.threadlinqs.com/technique/T1422), T1424, [T1426](https://intel.threadlinqs.com/technique/T1426), [T1429](https://intel.threadlinqs.com/technique/T1429), [T1437](https://intel.threadlinqs.com/technique/T1437), [T1453](https://intel.threadlinqs.com/technique/T1453), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1505](https://intel.threadlinqs.com/technique/T1505), T1509, [T1513](https://intel.threadlinqs.com/technique/T1513), [T1516](https://intel.threadlinqs.com/technique/T1516), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1521](https://intel.threadlinqs.com/technique/T1521), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1533](https://intel.threadlinqs.com/technique/T1533), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1541](https://intel.threadlinqs.com/technique/T1541), [T1542](https://intel.threadlinqs.com/technique/T1542), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), T1544, [T1546](https://intel.threadlinqs.com/technique/T1546), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), T1547.004, [T1547.006](https://intel.threadlinqs.com/technique/T1547.006), T1547.014, [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.001](https://intel.threadlinqs.com/technique/T1548.001), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.002](https://intel.threadlinqs.com/technique/T1552.002), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1564.003](https://intel.threadlinqs.com/technique/T1564.003), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.004](https://intel.threadlinqs.com/technique/T1566.004), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1584.004](https://intel.threadlinqs.com/technique/T1584.004), [T1584.006](https://intel.threadlinqs.com/technique/T1584.006), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), T1586.001, [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.001](https://intel.threadlinqs.com/technique/T1588.001), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1590](https://intel.threadlinqs.com/technique/T1590), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1592.004](https://intel.threadlinqs.com/technique/T1592.004), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1593.001](https://intel.threadlinqs.com/technique/T1593.001), [T1593.003](https://intel.threadlinqs.com/technique/T1593.003), [T1594](https://intel.threadlinqs.com/technique/T1594), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1596.005](https://intel.threadlinqs.com/technique/T1596.005), [T1598.003](https://intel.threadlinqs.com/technique/T1598.003), T1600.001, T1600.002, [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.005](https://intel.threadlinqs.com/technique/T1608.005), [T1608.006](https://intel.threadlinqs.com/technique/T1608.006), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1614.001](https://intel.threadlinqs.com/technique/T1614.001), [T1619](https://intel.threadlinqs.com/technique/T1619), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1622](https://intel.threadlinqs.com/technique/T1622), [T1624](https://intel.threadlinqs.com/technique/T1624), [T1626](https://intel.threadlinqs.com/technique/T1626), [T1628](https://intel.threadlinqs.com/technique/T1628), [T1630](https://intel.threadlinqs.com/technique/T1630), T1632, [T1636](https://intel.threadlinqs.com/technique/T1636), [T1646](https://intel.threadlinqs.com/technique/T1646), [T1649](https://intel.threadlinqs.com/technique/T1649), [T1650](https://intel.threadlinqs.com/technique/T1650), [T1655](https://intel.threadlinqs.com/technique/T1655), [T1657](https://intel.threadlinqs.com/technique/T1657), [T1660](https://intel.threadlinqs.com/technique/T1660), T1663, [T1665](https://intel.threadlinqs.com/technique/T1665), [T1684.001](https://intel.threadlinqs.com/technique/T1684.001), [T1685](https://intel.threadlinqs.com/technique/T1685), [T1686](https://intel.threadlinqs.com/technique/T1686), T1692.001, T1692.002, T1694.001

## Threat actors

[ModernStealer](https://intel.threadlinqs.com/actor/ModernStealer), [Criminal AI Abuse Ecosystem](https://intel.threadlinqs.com/actor/Criminal%20AI%20Abuse%20Ecosystem), [DuckTail](https://intel.threadlinqs.com/actor/DuckTail), [UMBRAL BISON](https://intel.threadlinqs.com/actor/UMBRAL%20BISON), [Larva-24009](https://intel.threadlinqs.com/actor/Larva-24009), [Markas Escobar](https://intel.threadlinqs.com/actor/Markas%20Escobar), [EVLF](https://intel.threadlinqs.com/actor/EVLF), Unidentified East Asia-Linked Threat Actor, [DOUBLECUP Operation](https://intel.threadlinqs.com/actor/DOUBLECUP%20Operation), [Midnight Blizzard](https://intel.threadlinqs.com/actor/Midnight%20Blizzard), [Storm-2945](https://intel.threadlinqs.com/actor/Storm-2945), [UNC6353](https://intel.threadlinqs.com/actor/UNC6353), [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers), [Qilin ransomware affiliate](https://intel.threadlinqs.com/actor/Qilin%20ransomware%20affiliate)

Nation-state attribution: Vietnam, Belarus, Indonesia, Unidentified (assessed East Asia), Russia, Iran

Threat categories: VULNERABILITY, THREAT_INTEL, FRAUD, MALWARE, DATA_BREACH, APT, ZERO_DAY

## Severity breakdown

- critical: 14
- high: 16
- medium: 3
- low: 2

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 1002 (network 316, file 179, behavioral 147, entity 92, infrastructure 72, tool 57, technique 54, package 45, malware 40)
- New detection rules: 315 (100% of the day’s threats covered)

## More editions

- Previous: [2026-08-02](https://intel.threadlinqs.com/debrief/2026-08-02)
- Next: [2026-08-04](https://intel.threadlinqs.com/debrief/2026-08-04)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-08-03
