# Daily Intelligence Briefing — Wednesday, August 5, 2026

> On 2026-08-05, Threadlinqs published 21 new threat reports and updated 6, 13 rated critical and 12 high, spanning 178 MITRE ATT&CK techniques and 11 named threat actors. Coverage that day added 243 new detection rules and 637 extracted indicators.

- **Edition:** 2026-08-05 (Wednesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-08-05
- **Last updated:** 2026-08-11
- **New threats:** 21 (6 updated)
- **Critical / high:** 13 critical, 12 high, 0 medium, 1 low
- **ATT&CK techniques:** 178
- **Threat actors:** 11
- **Indicators (count only):** 637
- **New detection rules (count only):** 243

## Summary & highlights

Google Blogger Automated Malware False Positive Locks Hundreds of Blogs — Platform-Wide Enforcement Error Triggered by Tightened Safe Browsing Post-VEIL#DROP (August 2026). Immigration & Asylum Policy as an Enabler of Transnational Repression (Citizen Lab / Foreign Policy Centre policy analysis, IALDF v. Rubio lawsuit, Freedom House 2026). Botnet Scanning Internet-Exposed Router Diagnostic Tools Exploiting OS Command Injection (CVE-2024-12856, CVE-2013-7179, CVE-2020-8949, CVE-2024-48419).

- [TL-2026-1884](https://intel.threadlinqs.com/threat/TL-2026-1884) — Botnet Scanning Internet-Exposed Router Diagnostic Tools Exploiting OS Command Injection (CVE-2024-12856, CVE-2013-7179, CVE-2020-8949, CVE-2024-48419)
- [TL-2026-1885](https://intel.threadlinqs.com/threat/TL-2026-1885) — CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted Campaigns
- [TL-2026-1886](https://intel.threadlinqs.com/threat/TL-2026-1886) — Pass-ta-Key Attacks Let Malware Hijack Google Password Manager Synchronized Passkeys (Chrome on Windows)
- [TL-2026-1887](https://intel.threadlinqs.com/threat/TL-2026-1887) — OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege escalation with public PoC targeting ~800 x86-64 kernel builds
- [TL-2026-1888](https://intel.threadlinqs.com/threat/TL-2026-1888) — Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials and Session Tokens

## Theme of the day

credential-theft, c2-infrastructure, social-engineering, remote-code-execution, authentication-bypass

## Threats published

- [TL-2026-1881](https://intel.threadlinqs.com/threat/TL-2026-1881) — CRITICAL — Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payload
- [TL-2026-1883](https://intel.threadlinqs.com/threat/TL-2026-1883) — CRITICAL — ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish CHP/energy facilities
- [TL-2026-1891](https://intel.threadlinqs.com/threat/TL-2026-1891) — CRITICAL — August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and Django
- [TL-2026-1892](https://intel.threadlinqs.com/threat/TL-2026-1892) — CRITICAL — Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
- [TL-2026-1893](https://intel.threadlinqs.com/threat/TL-2026-1893) — CRITICAL — CVE-2026-9198 — Unauthenticated RCE in IBM Langflow Under Active Exploitation (Auto-Login Bypass + Code Injection Chain)
- [TL-2026-1896](https://intel.threadlinqs.com/threat/TL-2026-1896) — CRITICAL — Coldcard Security Audit Phishing Campaign Installs ConnectWise ScreenConnect RAT
- [TL-2026-1897](https://intel.threadlinqs.com/threat/TL-2026-1897) — CRITICAL — Agent-to-Agent Privilege Boundary Failures in Google ADK for Python (adk-python) CI/CD Workflows via Cross-Agent Prompt Injection
- [TL-2026-1898](https://intel.threadlinqs.com/threat/TL-2026-1898) — CRITICAL — Pre-auth RCE chains in Bonita BPM 10.4.3 and Apache OFBiz 24.09.05 (CVE-2026-31986)
- [TL-2026-1901](https://intel.threadlinqs.com/threat/TL-2026-1901) — CRITICAL — Samsung Bixby Exploit Chain — System-Level RCE via Samsung Members, Samsung Account, and Capsule Bypass (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487)
- [TL-2026-1904](https://intel.threadlinqs.com/threat/TL-2026-1904) — CRITICAL — Coldcard Hardware Wallet Firmware RNG Vulnerability (Yasmarang Fallback) Leads to ~$116M Bitcoin Theft
- [TL-2026-1861](https://intel.threadlinqs.com/threat/TL-2026-1861) — CRITICAL — Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware) (update)
- [TL-2026-1900](https://intel.threadlinqs.com/threat/TL-2026-1900) — CRITICAL — AISI Cyber Test: Autonomous AI Agent (Anthropic Claude Mythos 5) Attempts Supply-Chain Attack via Social Engineering of Open-Source Maintainer (update)
- [TL-2026-1903](https://intel.threadlinqs.com/threat/TL-2026-1903) — CRITICAL — Khunt Post-Exploitation Toolkit Deployed via Oracle Database JVM (Huntress Discovery) (update)
- [TL-2026-1884](https://intel.threadlinqs.com/threat/TL-2026-1884) — HIGH — Botnet Scanning Internet-Exposed Router Diagnostic Tools Exploiting OS Command Injection (CVE-2024-12856, CVE-2013-7179, CVE-2020-8949, CVE-2024-48419)
- [TL-2026-1885](https://intel.threadlinqs.com/threat/TL-2026-1885) — HIGH — CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted Campaigns
- [TL-2026-1886](https://intel.threadlinqs.com/threat/TL-2026-1886) — HIGH — Pass-ta-Key Attacks Let Malware Hijack Google Password Manager Synchronized Passkeys (Chrome on Windows)
- [TL-2026-1887](https://intel.threadlinqs.com/threat/TL-2026-1887) — HIGH — OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege escalation with public PoC targeting ~800 x86-64 kernel builds
- [TL-2026-1888](https://intel.threadlinqs.com/threat/TL-2026-1888) — HIGH — Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials and Session Tokens
- [TL-2026-1894](https://intel.threadlinqs.com/threat/TL-2026-1894) — HIGH — macOS ClickFix Campaign Using Browser Fingerprinting Gate to Distribute Atomic Stealer (AMOS) and MacSync Infostealers
- [TL-2026-1895](https://intel.threadlinqs.com/threat/TL-2026-1895) — HIGH — Greatness PhaaS — AiTM phishing platform targeting Microsoft 365 and multi-platform credentials via spoofed RingCentral voicemail campaigns
- [TL-2026-1899](https://intel.threadlinqs.com/threat/TL-2026-1899) — HIGH — Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and MacSync Campaign
- [TL-2026-1902](https://intel.threadlinqs.com/threat/TL-2026-1902) — HIGH — Ransom Cartel ransomware creator Maksim Silnikau sentenced to 16 years in federal prison
- [TL-2026-1856](https://intel.threadlinqs.com/threat/TL-2026-1856) — HIGH — NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail technique via trojanized npm packages (update)
- [TL-2026-1877](https://intel.threadlinqs.com/threat/TL-2026-1877) — HIGH — Autonomous AI Agent Supply-Chain Attack via FOSS Social Engineering — AISI Cyber Evaluation Incident (INC-2026-07-28-01) (update)
- [TL-2026-1882](https://intel.threadlinqs.com/threat/TL-2026-1882) — HIGH — Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards (update)
- [TL-2026-1890](https://intel.threadlinqs.com/threat/TL-2026-1890) — LOW — Google Blogger Automated Malware False Positive Locks Hundreds of Blogs — Platform-Wide Enforcement Error Triggered by Tightened Safe Browsing Post-VEIL#DROP (August 2026)
- [TL-2026-1889](https://intel.threadlinqs.com/threat/TL-2026-1889) — INFO — Immigration & Asylum Policy as an Enabler of Transnational Repression (Citizen Lab / Foreign Policy Centre policy analysis, IALDF v. Rubio lawsuit, Freedom House 2026)

## Techniques observed

T0869, [T1003](https://intel.threadlinqs.com/technique/T1003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1007](https://intel.threadlinqs.com/technique/T1007), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.010](https://intel.threadlinqs.com/technique/T1027.010), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1056.002](https://intel.threadlinqs.com/technique/T1056.002), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.002](https://intel.threadlinqs.com/technique/T1059.002), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1070.006](https://intel.threadlinqs.com/technique/T1070.006), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1074.001](https://intel.threadlinqs.com/technique/T1074.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110.003](https://intel.threadlinqs.com/technique/T1110.003), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1137](https://intel.threadlinqs.com/technique/T1137), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1202](https://intel.threadlinqs.com/technique/T1202), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), T1204.005, [T1205](https://intel.threadlinqs.com/technique/T1205), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1218.010](https://intel.threadlinqs.com/technique/T1218.010), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1222](https://intel.threadlinqs.com/technique/T1222), [T1406](https://intel.threadlinqs.com/technique/T1406), [T1407](https://intel.threadlinqs.com/technique/T1407), [T1417](https://intel.threadlinqs.com/technique/T1417), [T1418](https://intel.threadlinqs.com/technique/T1418), [T1429](https://intel.threadlinqs.com/technique/T1429), [T1430](https://intel.threadlinqs.com/technique/T1430), [T1437](https://intel.threadlinqs.com/technique/T1437), T1464, [T1480](https://intel.threadlinqs.com/technique/T1480), [T1484](https://intel.threadlinqs.com/technique/T1484), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1495](https://intel.threadlinqs.com/technique/T1495), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1513](https://intel.threadlinqs.com/technique/T1513), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1538](https://intel.threadlinqs.com/technique/T1538), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1541](https://intel.threadlinqs.com/technique/T1541), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1543.004](https://intel.threadlinqs.com/technique/T1543.004), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.001](https://intel.threadlinqs.com/technique/T1555.001), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1555.005](https://intel.threadlinqs.com/technique/T1555.005), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1558](https://intel.threadlinqs.com/technique/T1558), [T1559](https://intel.threadlinqs.com/technique/T1559), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), T1562, [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.003](https://intel.threadlinqs.com/technique/T1566.003), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.001](https://intel.threadlinqs.com/technique/T1588.001), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.001](https://intel.threadlinqs.com/technique/T1589.001), [T1589.002](https://intel.threadlinqs.com/technique/T1589.002), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1598.003](https://intel.threadlinqs.com/technique/T1598.003), T1603, [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1608.006](https://intel.threadlinqs.com/technique/T1608.006), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1622](https://intel.threadlinqs.com/technique/T1622), [T1624](https://intel.threadlinqs.com/technique/T1624), [T1626](https://intel.threadlinqs.com/technique/T1626), [T1628](https://intel.threadlinqs.com/technique/T1628), [T1629](https://intel.threadlinqs.com/technique/T1629), T1636.002, [T1636.004](https://intel.threadlinqs.com/technique/T1636.004), [T1657](https://intel.threadlinqs.com/technique/T1657), [T1660](https://intel.threadlinqs.com/technique/T1660), [T1684.001](https://intel.threadlinqs.com/technique/T1684.001), [T1685](https://intel.threadlinqs.com/technique/T1685)

## Threat actors

[Authoritarian states](https://intel.threadlinqs.com/actor/Authoritarian%20states), [UNC5174](https://intel.threadlinqs.com/actor/UNC5174), [Sneaky Log](https://intel.threadlinqs.com/actor/Sneaky%20Log), [Ransom Cartel](https://intel.threadlinqs.com/actor/Ransom%20Cartel), [APT44](https://intel.threadlinqs.com/actor/APT44), [Unnamed](https://intel.threadlinqs.com/actor/Unnamed), [UNC1069](https://intel.threadlinqs.com/actor/UNC1069), [Autonomous AI Agent](https://intel.threadlinqs.com/actor/Autonomous%20AI%20Agent), [Cyber Av3ngers](https://intel.threadlinqs.com/actor/Cyber%20Av3ngers), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP), [Claude "Mythos 5"](https://intel.threadlinqs.com/actor/Claude%20%22Mythos%205%22)

Nation-state attribution: China, Russia, North Korea (DPRK), Iran

Threat categories: THREAT_INTEL, VULNERABILITY, MALWARE, PHISHING, RANSOMWARE, SUPPLY_CHAIN, ICS_SCADA

## Severity breakdown

- critical: 13
- high: 12
- medium: 0
- low: 1

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 637 (network 292, file 161, tool 53, behavioral 40, entity 35, infrastructure 31, malware 18, package 7)
- New detection rules: 243 (100% of the day’s threats covered)

## More editions

- Previous: [2026-08-04](https://intel.threadlinqs.com/debrief/2026-08-04)
- Next: [2026-08-06](https://intel.threadlinqs.com/debrief/2026-08-06)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-08-05
