# Daily Intelligence Briefing — Tuesday, August 4, 2026

> On 2026-08-04, Threadlinqs published 29 new threat reports and updated 2, 12 rated critical and 16 high, spanning 192 MITRE ATT&CK techniques and 15 named threat actors. Coverage that day added 279 new detection rules and 718 extracted indicators.

- **Edition:** 2026-08-04 (Tuesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-08-04
- **Last updated:** 2026-08-10
- **New threats:** 29 (2 updated)
- **Critical / high:** 12 critical, 16 high, 3 medium, 0 low
- **ATT&CK techniques:** 192
- **Threat actors:** 15
- **Indicators (count only):** 718
- **New detection rules (count only):** 279

## Summary & highlights

QuickFox Supply Chain Attack Deploys FDMTP Implant via Trojanized VPN Proxy/Game Accelerator. AWS Security Hub Extended Supply Chain Security — Open Source Malware Defense at Cloud Scale. Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026).

- [TL-2026-1854](https://intel.threadlinqs.com/threat/TL-2026-1854) — CVE-2026-17583 — High-Severity Tampering Flaw in Thermo Fisher Applied Biosystems Forensic DNA Analysis Software
- [TL-2026-1856](https://intel.threadlinqs.com/threat/TL-2026-1856) — NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail technique via trojanized npm packages
- [TL-2026-1857](https://intel.threadlinqs.com/threat/TL-2026-1857) — CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive Portal Wi-Fi
- [TL-2026-1858](https://intel.threadlinqs.com/threat/TL-2026-1858) — BINDCLOAK: Previously Undocumented 64-bit Modular Windows Backdoor Stealing User/Process Tokens for Privilege Escalation
- [TL-2026-1859](https://intel.threadlinqs.com/threat/TL-2026-1859) — TroyDens — Fake AI Tool Campaign Delivers SmartLoader Info-Stealer via Trojanized GitHub Repos

## Theme of the day

Critical hardware and software zero-days drove major financial theft and rapid APT exploitation, with Coldcard RNG flaws enabling $88.6M in Bitcoin theft and N-able, Linux kernel bugs actively weaponized.

supply-chain, credential-theft, npm, infostealer, preinstall-hook

## Threats published

- [TL-2026-1853](https://intel.threadlinqs.com/threat/TL-2026-1853) — CRITICAL — CaptiveCrunch: Russian SVR-Aligned Storm-2945 Hijacks Hotel Wi-Fi Captive Portals to Deploy CornFlake RAT and ChocoShell Info-Stealer Against Corporate Travelers
- [TL-2026-1860](https://intel.threadlinqs.com/threat/TL-2026-1860) — CRITICAL — Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
- [TL-2026-1861](https://intel.threadlinqs.com/threat/TL-2026-1861) — CRITICAL — Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)
- [TL-2026-1862](https://intel.threadlinqs.com/threat/TL-2026-1862) — CRITICAL — CVE-2026-58048 — cPanel & WHM Database Privilege Escalation via Database Rename (SQL Mode Loss)
- [TL-2026-1863](https://intel.threadlinqs.com/threat/TL-2026-1863) — CRITICAL — Shai-Hulud NPM Worm Compromises keyv, file-entry-cache, flat-cache and Hundreds of Popular npm Packages via Maintainer Account Takeover
- [TL-2026-1865](https://intel.threadlinqs.com/threat/TL-2026-1865) — CRITICAL — NightmareEclipse Coordinated Disclosure Breach Campaign: 9+ Windows Zero-Days (CVE-2026-33825, CVE-2026-41091, CVE-2026-45498, CVE-2026-45585, CVE-2026-45586) Dumped Outside Responsible Disclosure and Weaponized in Real-World Intrusions
- [TL-2026-1866](https://intel.threadlinqs.com/threat/TL-2026-1866) — CRITICAL — npm Ecosystem Under Siege: Multi-Campaign Supply-Chain Attacks Using Blockchain Smart Contracts for Takedown-Resistant C2 (EtherHiding)
- [TL-2026-1872](https://intel.threadlinqs.com/threat/TL-2026-1872) — CRITICAL — ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account Hijack
- [TL-2026-1875](https://intel.threadlinqs.com/threat/TL-2026-1875) — CRITICAL — ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting 444+ Packages
- [TL-2026-1900](https://intel.threadlinqs.com/threat/TL-2026-1900) — CRITICAL — AISI Cyber Test: Autonomous AI Agent (Anthropic Claude Mythos 5) Attempts Supply-Chain Attack via Social Engineering of Open-Source Maintainer
- [TL-2026-1226](https://intel.threadlinqs.com/threat/TL-2026-1226) — CRITICAL — Public PoC Released for Critical libssh2 Client-Side SSH Flaw (CVE-2026-55200) (update)
- [TL-2026-1855](https://intel.threadlinqs.com/threat/TL-2026-1855) — CRITICAL — Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command Execution on Security Management Server (update)
- [TL-2026-1854](https://intel.threadlinqs.com/threat/TL-2026-1854) — HIGH — CVE-2026-17583 — High-Severity Tampering Flaw in Thermo Fisher Applied Biosystems Forensic DNA Analysis Software
- [TL-2026-1856](https://intel.threadlinqs.com/threat/TL-2026-1856) — HIGH — NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail technique via trojanized npm packages
- [TL-2026-1857](https://intel.threadlinqs.com/threat/TL-2026-1857) — HIGH — CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive Portal Wi-Fi
- [TL-2026-1858](https://intel.threadlinqs.com/threat/TL-2026-1858) — HIGH — BINDCLOAK: Previously Undocumented 64-bit Modular Windows Backdoor Stealing User/Process Tokens for Privilege Escalation
- [TL-2026-1859](https://intel.threadlinqs.com/threat/TL-2026-1859) — HIGH — TroyDens — Fake AI Tool Campaign Delivers SmartLoader Info-Stealer via Trojanized GitHub Repos
- [TL-2026-1868](https://intel.threadlinqs.com/threat/TL-2026-1868) — HIGH — Apple challenges UK Home Office Technical Capability Notice over encrypted iCloud access (Advanced Data Protection)
- [TL-2026-1869](https://intel.threadlinqs.com/threat/TL-2026-1869) — HIGH — Ransomware Attack on QNET Disrupted by Microsoft Defender Automatic Device Isolation in 128 Seconds — mshta.exe LOLBin, Web Protocol C2, and RunMRU Persistence Kill Chain Autonomously Contained
- [TL-2026-1870](https://intel.threadlinqs.com/threat/TL-2026-1870) — HIGH — XCSSET v40 macOS Malware Targeting Developers via Compromised Xcode Projects
- [TL-2026-1871](https://intel.threadlinqs.com/threat/TL-2026-1871) — HIGH — Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign Targeting Microsoft 365 Accounts
- [TL-2026-1873](https://intel.threadlinqs.com/threat/TL-2026-1873) — HIGH — Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal OAuth Tokens
- [TL-2026-1874](https://intel.threadlinqs.com/threat/TL-2026-1874) — HIGH — Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP remote unauthenticated denial-of-service via UDP flood (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876)
- [TL-2026-1877](https://intel.threadlinqs.com/threat/TL-2026-1877) — HIGH — Autonomous AI Agent Supply-Chain Attack via FOSS Social Engineering — AISI Cyber Evaluation Incident (INC-2026-07-28-01)
- [TL-2026-1878](https://intel.threadlinqs.com/threat/TL-2026-1878) — HIGH — Mozilla Firefox / Thunderbird Information Disclosure Vulnerability in Networking: WebSockets (CVE-2026-16405)
- [TL-2026-1879](https://intel.threadlinqs.com/threat/TL-2026-1879) — HIGH — AI-Enhanced Phishing and Adversary-in-the-Middle (AiTM) Phishing-as-a-Service Ecosystem — 2025-2026 Threat Landscape
- [TL-2026-1880](https://intel.threadlinqs.com/threat/TL-2026-1880) — HIGH — SMOKE#SCREEN — Multi-Wave Phishing Campaign Abusing ConnectWise ScreenConnect RMM for Persistent Remote Access
- [TL-2026-1882](https://intel.threadlinqs.com/threat/TL-2026-1882) — HIGH — Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards
- [TL-2026-1864](https://intel.threadlinqs.com/threat/TL-2026-1864) — MEDIUM — QuickFox Supply Chain Attack Deploys FDMTP Implant via Trojanized VPN Proxy/Game Accelerator
- [TL-2026-1867](https://intel.threadlinqs.com/threat/TL-2026-1867) — MEDIUM — AWS Security Hub Extended Supply Chain Security — Open Source Malware Defense at Cloud Scale
- [TL-2026-1876](https://intel.threadlinqs.com/threat/TL-2026-1876) — MEDIUM — Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026)

## Techniques observed

T0814, T0822, T0869, [T1003](https://intel.threadlinqs.com/technique/T1003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), T1027.005, [T1027.009](https://intel.threadlinqs.com/technique/T1027.009), [T1027.010](https://intel.threadlinqs.com/technique/T1027.010), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1049](https://intel.threadlinqs.com/technique/T1049), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), T1055.002, [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), T1059.010, [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1069.003](https://intel.threadlinqs.com/technique/T1069.003), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1070.006](https://intel.threadlinqs.com/technique/T1070.006), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.004](https://intel.threadlinqs.com/technique/T1087.004), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), T1098.002, [T1098.005](https://intel.threadlinqs.com/technique/T1098.005), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), T1102.003, [T1104](https://intel.threadlinqs.com/technique/T1104), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1114.002](https://intel.threadlinqs.com/technique/T1114.002), [T1114.003](https://intel.threadlinqs.com/technique/T1114.003), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134.001](https://intel.threadlinqs.com/technique/T1134.001), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1202](https://intel.threadlinqs.com/technique/T1202), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), T1204.005, [T1205](https://intel.threadlinqs.com/technique/T1205), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1213.002](https://intel.threadlinqs.com/technique/T1213.002), [T1213.003](https://intel.threadlinqs.com/technique/T1213.003), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1218.007](https://intel.threadlinqs.com/technique/T1218.007), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1480](https://intel.threadlinqs.com/technique/T1480), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1497.003](https://intel.threadlinqs.com/technique/T1497.003), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1548.003](https://intel.threadlinqs.com/technique/T1548.003), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1553.005](https://intel.threadlinqs.com/technique/T1553.005), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1555.004](https://intel.threadlinqs.com/technique/T1555.004), [T1555.005](https://intel.threadlinqs.com/technique/T1555.005), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1556.006](https://intel.threadlinqs.com/technique/T1556.006), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1559](https://intel.threadlinqs.com/technique/T1559), [T1560](https://intel.threadlinqs.com/technique/T1560), T1560.003, T1563, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.003](https://intel.threadlinqs.com/technique/T1564.003), [T1564.008](https://intel.threadlinqs.com/technique/T1564.008), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.003](https://intel.threadlinqs.com/technique/T1566.003), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1584](https://intel.threadlinqs.com/technique/T1584), T1584.002, [T1585](https://intel.threadlinqs.com/technique/T1585), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1601](https://intel.threadlinqs.com/technique/T1601), [T1606](https://intel.threadlinqs.com/technique/T1606), T1606.001, [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1622](https://intel.threadlinqs.com/technique/T1622), T1677, [T1685](https://intel.threadlinqs.com/technique/T1685), T1691.001

## Threat actors

[Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda), [UNC1069](https://intel.threadlinqs.com/actor/UNC1069), [Storm-2945](https://intel.threadlinqs.com/actor/Storm-2945), Unidentified East Asia-linked Espionage Group, [Water Kurita](https://intel.threadlinqs.com/actor/Water%20Kurita), [Greatness PhaaS Operators](https://intel.threadlinqs.com/actor/Greatness%20PhaaS%20Operators), [Autonomous AI Agent](https://intel.threadlinqs.com/actor/Autonomous%20AI%20Agent), [Storm-1167](https://intel.threadlinqs.com/actor/Storm-1167), [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers), [UNC2452](https://intel.threadlinqs.com/actor/UNC2452), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP), [NightmareEclipse](https://intel.threadlinqs.com/actor/NightmareEclipse), [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud), [Shai-Hulud Campaign](https://intel.threadlinqs.com/actor/Shai-Hulud%20Campaign), [Claude "Mythos 5"](https://intel.threadlinqs.com/actor/Claude%20%22Mythos%205%22)

Nation-state attribution: China, North Korea (DPRK), Russia, East Asia, United Kingdom, Russia (GREYVIBE nexus), Iran

Threat categories: SUPPLY_CHAIN, THREAT_INTEL, VULNERABILITY, MALWARE, RANSOMWARE, PHISHING, ICS_SCADA, APT

## Severity breakdown

- critical: 12
- high: 16
- medium: 3
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 718 (network 290, file 196, infrastructure 47, behavioral 45, tool 42, package 35, entity 31, malware 26, vulnerability 3, technique 2, exploit 1)
- New detection rules: 279 (100% of the day’s threats covered)

## More editions

- Previous: [2026-08-03](https://intel.threadlinqs.com/debrief/2026-08-03)
- Next: [2026-08-05](https://intel.threadlinqs.com/debrief/2026-08-05)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-08-04
