Threadlinqs IntelligenceStart free

Daily debrief · Thursday2026-08-13

Daily Intelligence Briefing — Thursday, August 13, 2026

6 critical7 high3 medium

On 2026-08-13, Threadlinqs published 12 new threat reports and updated 5, 6 rated critical and 7 high, spanning 207 MITRE ATT&CK techniques and 8 named threat actors. Coverage that day added 153 new detection rules and 485 extracted indicators.

New threats
125 updated
Critical / high
136 critical · 7 high
ATT&CK techniques
207Observed in the day’s reports
Threat actors
8Named in the reports
Indicators
485Count only · values are Red+
Detection rules
153New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customers. Personal GitHub Repositories Are a Major Blind Spot for Corporate Secret Leaks (Wiz Research). Mid-Tier AI Models Close the Gap on Frontier Systems for Offensive Exploitation Tasks (XBOW/Anthropic, Aug 2026).

Highlights

  • TL-2026-2002 — Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Side
  • TL-2026-2003 — WindRelay Android NFC Relay Malware Paired With SpyNote RAT Enables Real-Time Bank Card "Ghost Tapping" Fraud
  • TL-2026-2004 — Mass Phishing and Scam Campaign Abuses 450+ Compromised Google Workspace Accounts in the Education Sector
  • TL-2026-2005 — Kimsuky 'Operation GitPower' Integrates Local AI Tooling into AsyncRAT Espionage Campaign
  • TL-2026-2006 — PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure (APT36-linked)

Theme of the day

Patch Tuesday's 400 fixes included three zero-days, with Lazarus exploiting an AFD.sys flaw and a critical Metabase SQLi under active attack.

  • espionage
  • active-exploitation
  • data-breach
  • social-engineering
  • financial-fraud

Threats published

17 threat lines in the 2026-08-13 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

207 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

8 named threat actors across the reports.

Nation-state attribution

  • China
  • North Korea
  • Pakistan
  • Russia
  • Russia (suspected, unconfirmed)

Threat categories

  • DATA_BREACH
  • SUPPLY_CHAIN
  • THREAT_INTEL
  • MALWARE
  • PHISHING
  • APT
  • RANSOMWARE
  • VULNERABILITY

Severity breakdown

  • critical6
  • high7
  • medium3
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

485 indicators of compromise · Red and above. Compare plans
  • network 115
  • file 110
  • entity 66
  • infrastructure 59
  • behavioral 47
  • tool 38
  • malware 33
  • package 9
  • technique 6
  • host 1
  • vulnerability 1
153 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans