# Daily Intelligence Briefing — Sunday, August 16, 2026

> On 2026-08-16, Threadlinqs published 12 new threat reports and updated 2, 3 rated critical and 9 high, spanning 125 MITRE ATT&CK techniques and 6 named threat actors. Coverage that day added 126 new detection rules and 242 extracted indicators.

- **Edition:** 2026-08-16 (Sunday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-08-16
- **Last updated:** 2026-08-22
- **New threats:** 12 (2 updated)
- **Critical / high:** 3 critical, 9 high, 2 medium, 0 low
- **ATT&CK techniques:** 125
- **Threat actors:** 6
- **Indicators (count only):** 242
- **New detection rules (count only):** 126

## Summary & highlights

SafePal Data Breach: Order-Tracking Plug-in Authorization Flaw Exposes 39,798 Crypto Wallet Customers' PII, Fuels Phishing Campaign. Expired-Domain Resale Abuse Fuels Malware Delivery: Sable Squirrel and Scavenger Threat Clusters (Quasar RAT, AsyncRAT, DCRat, Remcos RAT, SocGholish). ZeroBytes Breaches French Tax Authority (DGFiP): Stolen Credentials and MFA Bypass Expose Tax Data of 678,438 Taxpayers and Businesses.

- [TL-2026-2026](https://intel.threadlinqs.com/threat/TL-2026-2026) — ZeroBytes Breaches French Tax Authority (DGFiP): Stolen Credentials and MFA Bypass Expose Tax Data of 678,438 Taxpayers and Businesses
- [TL-2026-2027](https://intel.threadlinqs.com/threat/TL-2026-2027) — "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's, Vodafone, Kyndryl, TCS, HCL and Others
- [TL-2026-2028](https://intel.threadlinqs.com/threat/TL-2026-2028) — Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCS
- [TL-2026-2029](https://intel.threadlinqs.com/threat/TL-2026-2029) — AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Control
- [TL-2026-2030](https://intel.threadlinqs.com/threat/TL-2026-2030) — AI Agents Persist Through Failed Malware, Rewrite Tools Mid-Attack: SentinelLABS Documents Sandbox Escape, PyPI Supply-Chain Package, and Artifactory Zero-Day Abuse

## Theme of the day

Nightmare Eclipse's ShieldBreak zero-day bypasses Defender for SYSTEM access, while Akira exploits Safe Mode to disable EDR and PhaaS platforms scale AiTM MFA-bypass attacks.

credential-theft, cybercrime-forum, data-breach, dark-web-marketplace, social-engineering

## Threats published

- [TL-2026-2035](https://intel.threadlinqs.com/threat/TL-2026-2035) — CRITICAL — Unpatched GeoServer Zero-Day SQL Injection in jsonArrayContains (GHSA-mqjf-5f49-2fjh) Enables Unauthenticated RCE via PostGIS
- [TL-2026-2038](https://intel.threadlinqs.com/threat/TL-2026-2038) — CRITICAL — CVE-2026-43760: macOS Screen Sharing Logic Flaw Allows VNC-Authenticated Root Command Execution
- [TL-2026-2037](https://intel.threadlinqs.com/threat/TL-2026-2037) — CRITICAL — Unpatched GeoServer Zero-Day SQL Injection (jsonArrayContains, GHSA-mqjf-5f49-2fjh) Under Active Exploitation (update)
- [TL-2026-2026](https://intel.threadlinqs.com/threat/TL-2026-2026) — HIGH — ZeroBytes Breaches French Tax Authority (DGFiP): Stolen Credentials and MFA Bypass Expose Tax Data of 678,438 Taxpayers and Businesses
- [TL-2026-2027](https://intel.threadlinqs.com/threat/TL-2026-2027) — HIGH — "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's, Vodafone, Kyndryl, TCS, HCL and Others
- [TL-2026-2028](https://intel.threadlinqs.com/threat/TL-2026-2028) — HIGH — Azure Credential Theft Campaign Exposes Millions of Enterprise Records at McDonald's, Vodafone, TCS
- [TL-2026-2029](https://intel.threadlinqs.com/threat/TL-2026-2029) — HIGH — AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Control
- [TL-2026-2030](https://intel.threadlinqs.com/threat/TL-2026-2030) — HIGH — AI Agents Persist Through Failed Malware, Rewrite Tools Mid-Attack: SentinelLABS Documents Sandbox Escape, PyPI Supply-Chain Package, and Artifactory Zero-Day Abuse
- [TL-2026-2031](https://intel.threadlinqs.com/threat/TL-2026-2031) — HIGH — Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply Chain
- [TL-2026-2034](https://intel.threadlinqs.com/threat/TL-2026-2034) — HIGH — Apple Issues Mercenary Spyware Threat Notifications to Users in 110 Countries
- [TL-2026-2036](https://intel.threadlinqs.com/threat/TL-2026-2036) — HIGH — MessiahGPT: Uncensored Criminal AI Model Marketed on BreachForums for Malware, Phishing, and Fraud Generation
- [TL-2026-2006](https://intel.threadlinqs.com/threat/TL-2026-2006) — HIGH — PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure (APT36-linked) (update)
- [TL-2026-2032](https://intel.threadlinqs.com/threat/TL-2026-2032) — MEDIUM — SafePal Data Breach: Order-Tracking Plug-in Authorization Flaw Exposes 39,798 Crypto Wallet Customers' PII, Fuels Phishing Campaign
- [TL-2026-2033](https://intel.threadlinqs.com/threat/TL-2026-2033) — MEDIUM — Expired-Domain Resale Abuse Fuels Malware Delivery: Sable Squirrel and Scavenger Threat Clusters (Quasar RAT, AsyncRAT, DCRat, Remcos RAT, SocGholish)

## Techniques observed

[T1003](https://intel.threadlinqs.com/technique/T1003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.005](https://intel.threadlinqs.com/technique/T1021.005), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.004](https://intel.threadlinqs.com/technique/T1036.004), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.003](https://intel.threadlinqs.com/technique/T1053.003), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1056.002](https://intel.threadlinqs.com/technique/T1056.002), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.002](https://intel.threadlinqs.com/technique/T1059.002), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1069.003](https://intel.threadlinqs.com/technique/T1069.003), [T1070.003](https://intel.threadlinqs.com/technique/T1070.003), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.004](https://intel.threadlinqs.com/technique/T1087.004), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.003](https://intel.threadlinqs.com/technique/T1110.003), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), T1197, [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1204.004](https://intel.threadlinqs.com/technique/T1204.004), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1219](https://intel.threadlinqs.com/technique/T1219), T1221, [T1222.002](https://intel.threadlinqs.com/technique/T1222.002), [T1417](https://intel.threadlinqs.com/technique/T1417), [T1429](https://intel.threadlinqs.com/technique/T1429), [T1430](https://intel.threadlinqs.com/technique/T1430), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1512](https://intel.threadlinqs.com/technique/T1512), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543.004](https://intel.threadlinqs.com/technique/T1543.004), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1547.009](https://intel.threadlinqs.com/technique/T1547.009), [T1548.003](https://intel.threadlinqs.com/technique/T1548.003), T1548.004, T1548.006, [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.007](https://intel.threadlinqs.com/technique/T1552.007), [T1553.001](https://intel.threadlinqs.com/technique/T1553.001), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.001](https://intel.threadlinqs.com/technique/T1555.001), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556.006](https://intel.threadlinqs.com/technique/T1556.006), [T1560](https://intel.threadlinqs.com/technique/T1560), T1562.001, [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.004](https://intel.threadlinqs.com/technique/T1566.004), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1583.008](https://intel.threadlinqs.com/technique/T1583.008), [T1584.005](https://intel.threadlinqs.com/technique/T1584.005), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), T1587.003, [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1588.007](https://intel.threadlinqs.com/technique/T1588.007), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.001](https://intel.threadlinqs.com/technique/T1589.001), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), T1602.002, [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1622](https://intel.threadlinqs.com/technique/T1622), [T1650](https://intel.threadlinqs.com/technique/T1650), [T1657](https://intel.threadlinqs.com/technique/T1657), [T1665](https://intel.threadlinqs.com/technique/T1665), [T1684.001](https://intel.threadlinqs.com/technique/T1684.001)

## Threat actors

[Sable Squirrel](https://intel.threadlinqs.com/actor/Sable%20Squirrel), [ZeroBytes](https://intel.threadlinqs.com/actor/ZeroBytes), [TheHatman](https://intel.threadlinqs.com/actor/TheHatman), [Autonomous AI agents](https://intel.threadlinqs.com/actor/Autonomous%20AI%20agents), [GRU Unit 26165](https://intel.threadlinqs.com/actor/GRU%20Unit%2026165), [APT36](https://intel.threadlinqs.com/actor/APT36)

Nation-state attribution: Russia, Pakistan

Threat categories: DATA_BREACH, MALWARE, THREAT_INTEL, SUPPLY_CHAIN, VULNERABILITY

## Severity breakdown

- critical: 3
- high: 9
- medium: 2
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 242 (entity 73, network 46, infrastructure 35, file 30, tool 27, malware 23, behavioral 5, package 3)
- New detection rules: 126 (100% of the day’s threats covered)

## More editions

- Previous: [2026-08-13](https://intel.threadlinqs.com/debrief/2026-08-13)
- Next: [2026-08-17](https://intel.threadlinqs.com/debrief/2026-08-17)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-08-16
