Threadlinqs IntelligenceStart free

Daily debrief · Tuesday2026-08-04

Daily Intelligence Briefing — Tuesday, August 4, 2026

12 critical16 high3 medium

On 2026-08-04, Threadlinqs published 29 new threat reports and updated 2, 12 rated critical and 16 high, spanning 192 MITRE ATT&CK techniques and 15 named threat actors. Coverage that day added 279 new detection rules and 718 extracted indicators.

New threats
292 updated
Critical / high
2812 critical · 16 high
ATT&CK techniques
192Observed in the day’s reports
Threat actors
15Named in the reports
Indicators
718Count only · values are Red+
Detection rules
279New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

QuickFox Supply Chain Attack Deploys FDMTP Implant via Trojanized VPN Proxy/Game Accelerator. AWS Security Hub Extended Supply Chain Security — Open Source Malware Defense at Cloud Scale. Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026).

Highlights

  • TL-2026-1854 — CVE-2026-17583 — High-Severity Tampering Flaw in Thermo Fisher Applied Biosystems Forensic DNA Analysis Software
  • TL-2026-1856 — NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail technique via trojanized npm packages
  • TL-2026-1857 — CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive Portal Wi-Fi
  • TL-2026-1858 — BINDCLOAK: Previously Undocumented 64-bit Modular Windows Backdoor Stealing User/Process Tokens for Privilege Escalation
  • TL-2026-1859 — TroyDens — Fake AI Tool Campaign Delivers SmartLoader Info-Stealer via Trojanized GitHub Repos

Theme of the day

Critical hardware and software zero-days drove major financial theft and rapid APT exploitation, with Coldcard RNG flaws enabling $88.6M in Bitcoin theft and N-able, Linux kernel bugs actively weaponized.

  • supply-chain
  • credential-theft
  • npm
  • infostealer
  • preinstall-hook

Threats published

31 threat lines in the 2026-08-04 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

192 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

15 named threat actors across the reports.

Nation-state attribution

  • China
  • North Korea (DPRK)
  • Russia
  • East Asia
  • United Kingdom
  • Russia (GREYVIBE nexus)
  • Iran

Threat categories

  • SUPPLY_CHAIN
  • THREAT_INTEL
  • VULNERABILITY
  • MALWARE
  • RANSOMWARE
  • PHISHING
  • ICS_SCADA
  • APT

Severity breakdown

  • critical12
  • high16
  • medium3
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

718 indicators of compromise · Red and above. Compare plans
  • network 290
  • file 196
  • infrastructure 47
  • behavioral 45
  • tool 42
  • package 35
  • entity 31
  • malware 26
  • vulnerability 3
  • technique 2
  • exploit 1
279 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans