# Daily Intelligence Briefing — Sunday, August 9, 2026

> On 2026-08-09, Threadlinqs published 15 new threat reports and updated 11, 8 rated critical and 16 high, spanning 192 MITRE ATT&CK techniques and 6 named threat actors. Coverage that day added 234 new detection rules and 583 extracted indicators.

- **Edition:** 2026-08-09 (Sunday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-08-09
- **Last updated:** 2026-08-15
- **New threats:** 15 (11 updated)
- **Critical / high:** 8 critical, 16 high, 2 medium, 0 low
- **ATT&CK techniques:** 192
- **Threat actors:** 6
- **Indicators (count only):** 583
- **New detection rules (count only):** 234

## Summary & highlights

Ransomware Extortion Campaigns Shift Targeting to Mid-Level IT and Business Managers, Zscaler ThreatLabz Finds. BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detection. City of Coweta, Oklahoma Hit by Anubis Ransomware Attack.

- [TL-2026-1948](https://intel.threadlinqs.com/threat/TL-2026-1948) — City of Coweta, Oklahoma Hit by Anubis Ransomware Attack
- [TL-2026-1949](https://intel.threadlinqs.com/threat/TL-2026-1949) — SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local Privilege Escalation
- [TL-2026-1951](https://intel.threadlinqs.com/threat/TL-2026-1951) — Suspected Russian Actor Uses AI Slopsquatting to Publish 1,000+ Malicious npm Packages (WEL1DROPPER / "Flooding Dropper")
- [TL-2026-1952](https://intel.threadlinqs.com/threat/TL-2026-1952) — Malware Abuses Windows Hello for Business Key to Authenticate to Microsoft Entra ID
- [TL-2026-1953](https://intel.threadlinqs.com/threat/TL-2026-1953) — Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts

## Theme of the day

Unattributed threats dominated the day, with emerging actors like Head Mare and FirewallFalcon active alongside ransomware and CitrixBleed-related tags.

credential-theft, social-engineering, privilege-escalation, ransomware, mfa-bypass

## Threats published

- [TL-2026-1958](https://intel.threadlinqs.com/threat/TL-2026-1958) — CRITICAL — Metabase Unauthenticated SQL Injection 0-Day (GHSA-vwf4-m7j8-wcjf) Exploited in the Wild for Admin Takeover
- [TL-2026-1959](https://intel.threadlinqs.com/threat/TL-2026-1959) — CRITICAL — UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for Extortion
- [TL-2026-1378](https://intel.threadlinqs.com/threat/TL-2026-1378) — CRITICAL — CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) (update)
- [TL-2026-1747](https://intel.threadlinqs.com/threat/TL-2026-1747) — CRITICAL — CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol (update)
- [TL-2026-1872](https://intel.threadlinqs.com/threat/TL-2026-1872) — CRITICAL — ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account Hijack (update)
- [TL-2026-1898](https://intel.threadlinqs.com/threat/TL-2026-1898) — CRITICAL — Pre-auth RCE chains in Bonita BPM 10.4.3 and Apache OFBiz 24.09.05 (CVE-2026-31986) (update)
- [TL-2026-1906](https://intel.threadlinqs.com/threat/TL-2026-1906) — CRITICAL — ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ Models (update)
- [TL-2026-1931](https://intel.threadlinqs.com/threat/TL-2026-1931) — CRITICAL — Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws (update)
- [TL-2026-1948](https://intel.threadlinqs.com/threat/TL-2026-1948) — HIGH — City of Coweta, Oklahoma Hit by Anubis Ransomware Attack
- [TL-2026-1949](https://intel.threadlinqs.com/threat/TL-2026-1949) — HIGH — SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local Privilege Escalation
- [TL-2026-1951](https://intel.threadlinqs.com/threat/TL-2026-1951) — HIGH — Suspected Russian Actor Uses AI Slopsquatting to Publish 1,000+ Malicious npm Packages (WEL1DROPPER / "Flooding Dropper")
- [TL-2026-1952](https://intel.threadlinqs.com/threat/TL-2026-1952) — HIGH — Malware Abuses Windows Hello for Business Key to Authenticate to Microsoft Entra ID
- [TL-2026-1953](https://intel.threadlinqs.com/threat/TL-2026-1953) — HIGH — Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts
- [TL-2026-1955](https://intel.threadlinqs.com/threat/TL-2026-1955) — HIGH — Ransomware Gangs Shift Targeting from Executives to Mid-Level IT/Finance Managers (Zscaler ThreatLabz Research)
- [TL-2026-1956](https://intel.threadlinqs.com/threat/TL-2026-1956) — HIGH — CSS Bomb: JavaScript-Free CSS Keylogging and Token-Theft Attacks Against Gmail, Outlook, Yahoo Mail, AOL Mail, Fastmail, and ProtonMail
- [TL-2026-1960](https://intel.threadlinqs.com/threat/TL-2026-1960) — HIGH — U.S. Defense Manufacturer IEH Corporation Breached via Phishing, Potential Export-Controlled Data Exposure
- [TL-2026-1961](https://intel.threadlinqs.com/threat/TL-2026-1961) — HIGH — AI-Assisted "HTTP Terminator" Uncovers Novel HTTP Desync Techniques and Apache Traffic Server Zero-Day (CVE-2026-63078)
- [TL-2026-1962](https://intel.threadlinqs.com/threat/TL-2026-1962) — HIGH — UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data for Extortion
- [TL-2026-1963](https://intel.threadlinqs.com/threat/TL-2026-1963) — HIGH — AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671 (BlackFile/Redact) Extortion Group
- [TL-2026-1919](https://intel.threadlinqs.com/threat/TL-2026-1919) — HIGH — CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux Host (update)
- [TL-2026-1930](https://intel.threadlinqs.com/threat/TL-2026-1930) — HIGH — Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance Emails (update)
- [TL-2026-1933](https://intel.threadlinqs.com/threat/TL-2026-1933) — HIGH — WordPress Core XSS2Shell Vulnerability Chains Pre-Auth XSS to RCE (CVE-2026-64638) (update)
- [TL-2026-1950](https://intel.threadlinqs.com/threat/TL-2026-1950) — HIGH — Fake Zoom Installer Delivers Overlord RAT to macOS via .NET Downloader (ZoomMeetings) (update)
- [TL-2026-1954](https://intel.threadlinqs.com/threat/TL-2026-1954) — HIGH — TONTOU: Interrupt-Injection Attack Bypasses Spectre v2 (eIBRS/Safe RET) Defenses on Intel and AMD CPUs (update)
- [TL-2026-1957](https://intel.threadlinqs.com/threat/TL-2026-1957) — MEDIUM — Ransomware Extortion Campaigns Shift Targeting to Mid-Level IT and Business Managers, Zscaler ThreatLabz Finds
- [TL-2026-1964](https://intel.threadlinqs.com/threat/TL-2026-1964) — MEDIUM — BYU Study: AI-Generated Spear Phishing (GPT-4) Outperforms Human-Written Lures and Evades Human Detection

## Techniques observed

AML.T0011.001, [AML.T0051](https://intel.threadlinqs.com/technique/AML.T0051), [AML.T0051.001](https://intel.threadlinqs.com/technique/AML.T0051.001), AML.T0052.000, [AML.T0053](https://intel.threadlinqs.com/technique/AML.T0053), [AML.T0054](https://intel.threadlinqs.com/technique/AML.T0054), AML.T0091.001, [T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.001](https://intel.threadlinqs.com/technique/T1003.001), [T1003.008](https://intel.threadlinqs.com/technique/T1003.008), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), T1021.007, [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.010](https://intel.threadlinqs.com/technique/T1027.010), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.004](https://intel.threadlinqs.com/technique/T1036.004), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1037.004](https://intel.threadlinqs.com/technique/T1037.004), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.003](https://intel.threadlinqs.com/technique/T1078.003), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.004](https://intel.threadlinqs.com/technique/T1087.004), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.005](https://intel.threadlinqs.com/technique/T1098.005), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1114.002](https://intel.threadlinqs.com/technique/T1114.002), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1134.002](https://intel.threadlinqs.com/technique/T1134.002), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1195.003](https://intel.threadlinqs.com/technique/T1195.003), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1202](https://intel.threadlinqs.com/technique/T1202), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1205](https://intel.threadlinqs.com/technique/T1205), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1213.003](https://intel.threadlinqs.com/technique/T1213.003), [T1219](https://intel.threadlinqs.com/technique/T1219), T1475, [T1484](https://intel.threadlinqs.com/technique/T1484), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1538](https://intel.threadlinqs.com/technique/T1538), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1543.004](https://intel.threadlinqs.com/technique/T1543.004), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1556.006](https://intel.threadlinqs.com/technique/T1556.006), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), T1560.003, T1562, [T1564.008](https://intel.threadlinqs.com/technique/T1564.008), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1565.002](https://intel.threadlinqs.com/technique/T1565.002), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1583.008](https://intel.threadlinqs.com/technique/T1583.008), [T1585.002](https://intel.threadlinqs.com/technique/T1585.002), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1588.007](https://intel.threadlinqs.com/technique/T1588.007), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.002](https://intel.threadlinqs.com/technique/T1589.002), [T1589.003](https://intel.threadlinqs.com/technique/T1589.003), [T1590](https://intel.threadlinqs.com/technique/T1590), [T1591](https://intel.threadlinqs.com/technique/T1591), T1591.002, [T1591.004](https://intel.threadlinqs.com/technique/T1591.004), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1592.004](https://intel.threadlinqs.com/technique/T1592.004), [T1593.001](https://intel.threadlinqs.com/technique/T1593.001), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1601](https://intel.threadlinqs.com/technique/T1601), [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1608.005](https://intel.threadlinqs.com/technique/T1608.005), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1622](https://intel.threadlinqs.com/technique/T1622), [T1657](https://intel.threadlinqs.com/technique/T1657), [T1660](https://intel.threadlinqs.com/technique/T1660), [T1684.001](https://intel.threadlinqs.com/technique/T1684.001), [T1685](https://intel.threadlinqs.com/technique/T1685)

## Threat actors

[Anubis](https://intel.threadlinqs.com/actor/Anubis), [UNC6671](https://intel.threadlinqs.com/actor/UNC6671), [Storm-2755](https://intel.threadlinqs.com/actor/Storm-2755), [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603), [Shai-Hulud Campaign](https://intel.threadlinqs.com/actor/Shai-Hulud%20Campaign), [Shenzhen Zhibotong Electronics](https://intel.threadlinqs.com/actor/Shenzhen%20Zhibotong%20Electronics)

Nation-state attribution: Russia, North Korea, China

Threat categories: RANSOMWARE, PHISHING, VULNERABILITY, SUPPLY_CHAIN, DATA_BREACH, MALWARE

## Severity breakdown

- critical: 8
- high: 16
- medium: 2
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 583 (network 164, file 109, behavioral 77, entity 74, infrastructure 59, tool 48, package 27, malware 25)
- New detection rules: 234 (100% of the day’s threats covered)

## More editions

- Previous: [2026-08-07](https://intel.threadlinqs.com/debrief/2026-08-07)
- Next: [2026-08-10](https://intel.threadlinqs.com/debrief/2026-08-10)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-08-09
