Threadlinqs IntelligenceStart free

Daily debrief · Monday2026-08-17

Daily Intelligence Briefing — Monday, August 17, 2026

5 critical11 high4 medium

On 2026-08-17, Threadlinqs published 14 new threat reports and updated 6, 5 rated critical and 11 high, spanning 175 MITRE ATT&CK techniques and 6 named threat actors. Coverage that day added 180 new detection rules and 465 extracted indicators.

New threats
146 updated
Critical / high
165 critical · 11 high
ATT&CK techniques
175Observed in the day’s reports
Threat actors
6Named in the reports
Indicators
465Count only · values are Red+
Detection rules
180New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

"Download More RAM" Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing (CVE-2026-23670). AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub, Canva, Geek Squad, Temu, Target and the FTC. CVE-2026-40126: DOM-based XSS in OutSystems Service Center via malicious file upload filenames.

Highlights

  • TL-2026-2040 — Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor (QUICAgent)
  • TL-2026-2045 — Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)
  • TL-2026-2049 — Unisoc VoLTE Video-Call Exploit Chain Escalates Modem RCE to Full Android Kernel Access
  • TL-2026-2050 — Autonomous AI Agent Orchestration Powers Machine-Speed Social Engineering Attack Chains
  • TL-2026-2051 — GitHub Actions Workflow Injection in Snowflake .NET Connector Repo Exposed Jira Credentials

Theme of the day

Critical zero-day exploits (Metabase SQLi, Defender EDR bypass) and massive credential leaks dominate, with GRU-linked APT and unattributed actors driving active attacks.

  • credential-theft
  • social-engineering
  • infostealer
  • anti-analysis
  • cryptocurrency-theft

Threats published

20 threat lines in the 2026-08-17 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

175 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

6 named threat actors across the reports.

Nation-state attribution

  • China
  • Iran
  • Russia / China
  • Russia

Threat categories

  • VULNERABILITY
  • PHISHING
  • DATA_BREACH
  • MALWARE
  • RANSOMWARE
  • ZERO_DAY

Severity breakdown

  • critical5
  • high11
  • medium4
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

465 indicators of compromise · Red and above. Compare plans
  • network 139
  • file 112
  • entity 56
  • behavioral 46
  • infrastructure 44
  • tool 29
  • malware 22
  • package 15
  • technique 2
180 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans