Threadlinqs IntelligenceStart free

Daily debrief · Monday2026-08-10

Daily Intelligence Briefing — Monday, August 10, 2026

7 critical9 high4 medium

On 2026-08-10, Threadlinqs published 17 new threat reports and updated 3, 7 rated critical and 9 high, spanning 151 MITRE ATT&CK techniques and 4 named threat actors. Coverage that day added 180 new detection rules and 355 extracted indicators.

New threats
173 updated
Critical / high
167 critical · 9 high
ATT&CK techniques
151Observed in the day’s reports
Threat actors
4Named in the reports
Indicators
355Count only · values are Red+
Detection rules
180New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Claude-Powered OpenClaw AI Agent Autonomously Exploits Gym Booking API Authorization Flaw. Claude-Powered AI Agent (OpenClaw) Autonomously Exploits Broken Access Control Flaw in Gym Booking API. Royal Navy K3 Scout Drone Cameras Found Transmitting Heartbeat Signals to China-Based IP Address.

Highlights

  • TL-2026-1966 — WSUS NTLM Relay Attack Chain Enables Malicious Update Deployment via SUSDB Stored Procedures
  • TL-2026-1968 — CSS Bomb Attacks: CSS-Based Trust-Boundary Bypass Leaks Webmail Passwords and Tokens (Outlook, Gmail, Yahoo, AOL, Fastmail, Proton Mail)
  • TL-2026-1970 — Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromise
  • TL-2026-1971 — WordPress Supply Chain Attack via BdThemes Promotional API Feed Poisoning (Element Pack, Prime Slider, and 5 More Plugins)
  • TL-2026-1973 — UAC-0145 (Sandworm subcluster) trojanizes WireGuard VPN client "SopraVPN" in fake IT recruitment campaign impersonating Sopra Steria Bulgaria

Theme of the day

Activity centered on abc-news, active-directory, agentic-ai.

  • credential-theft
  • authentication-bypass
  • defense-evasion
  • privilege-escalation
  • active-exploitation

Threats published

20 threat lines in the 2026-08-10 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

151 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

4 named threat actors across the reports.

Nation-state attribution

  • Russia

Threat categories

  • VULNERABILITY
  • SUPPLY_CHAIN
  • PHISHING
  • MALWARE
  • RANSOMWARE

Severity breakdown

  • critical7
  • high9
  • medium4
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

355 indicators of compromise · Red and above. Compare plans
  • network 87
  • file 78
  • entity 69
  • infrastructure 44
  • tool 30
  • behavioral 28
  • malware 9
  • package 9
  • technique 1
180 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans