Threadlinqs IntelligenceStart free

Daily debrief · Friday2026-08-21

Daily Intelligence Briefing — Friday, August 21, 2026

4 critical11 high1 medium

On 2026-08-21, Threadlinqs published 15 new threat reports and updated 1, 4 rated critical and 11 high, spanning 157 MITRE ATT&CK techniques and 9 named threat actors. Coverage that day added 144 new detection rules and 352 extracted indicators.

New threats
151 updated
Critical / high
154 critical · 11 high
ATT&CK techniques
157Observed in the day’s reports
Threat actors
9Named in the reports
Indicators
352Count only · values are Red+
Detection rules
144New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Hospital for Sick Children (SickKids) Data Breach Exposes Employee Information via Third-Party Software Vulnerability. Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and captive portal compromise targeting academia, defense, and government across Europe and the US. LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp).

Highlights

  • TL-2026-2091 — Russian APT29-linked clusters (UNC6293, UNC7005) and UNC5976 — OAuth phishing, device-code phishing, and captive portal compromise targeting academia, defense, and government across Europe and the US
  • TL-2026-2094 — LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)
  • TL-2026-2095 — iAuthFlow V2 Phishing Toolkit Enrolls Attacker-Controlled Passkeys That Survive Password Resets
  • TL-2026-2096 — Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web servers
  • TL-2026-2098 — SynkLoader: New Multi-Module Malware Family Distributed via Microsoft Teams Phishing Campaign Targeting Enterprise Active Directory Environments

Theme of the day

AI-powered attacks and autonomous agents drove today's threat landscape, targeting critical infrastructure and crypto wallets, while APT groups like APT38 and APT29 remained active.

  • credential-theft
  • social-engineering
  • data-exfiltration
  • defense-evasion
  • supply-chain-attack

Threats published

16 threat lines in the 2026-08-21 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

157 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

9 named threat actors across the reports.

Nation-state attribution

  • Russia
  • China

Threat categories

  • DATA_BREACH
  • APT
  • RANSOMWARE
  • MALWARE
  • THREAT_INTEL
  • VULNERABILITY
  • PHISHING
  • SUPPLY_CHAIN

Severity breakdown

  • critical4
  • high11
  • medium1
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

352 indicators of compromise · Red and above. Compare plans
  • network 138
  • file 99
  • infrastructure 25
  • package 23
  • tool 23
  • entity 19
  • behavioral 13
  • malware 12
144 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans