# Daily Intelligence Briefing — Wednesday, August 26, 2026

> On 2026-08-26, Threadlinqs published 14 new threat reports and updated 3, 5 rated critical and 9 high, spanning 151 MITRE ATT&CK techniques and 8 named threat actors. Coverage that day added 153 new detection rules and 349 extracted indicators.

- **Edition:** 2026-08-26 (Wednesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-08-26
- **Last updated:** 2026-09-01
- **New threats:** 14 (3 updated)
- **Critical / high:** 5 critical, 9 high, 2 medium, 0 low
- **ATT&CK techniques:** 151
- **Threat actors:** 8
- **Indicators (count only):** 349
- **New detection rules (count only):** 153

## Summary & highlights

Dissection of a PHP Backdoor Leveraging php-win.exe for Stealthy Windows Persistence. 24 Malicious npm Packages Abuse Registry Mirrors as Phishing Infrastructure (Fake Cloudflare/Microsoft Login Pages). Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demon.

- [TL-2026-2148](https://intel.threadlinqs.com/threat/TL-2026-2148) — Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demon
- [TL-2026-2151](https://intel.threadlinqs.com/threat/TL-2026-2151) — CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain Patch-Pinning Risk
- [TL-2026-2153](https://intel.threadlinqs.com/threat/TL-2026-2153) — Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter Devices
- [TL-2026-2154](https://intel.threadlinqs.com/threat/TL-2026-2154) — Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption Campaigns Against NATO/EU Infrastructure
- [TL-2026-2155](https://intel.threadlinqs.com/threat/TL-2026-2155) — "The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware distribution, extortion, and predatory recruitment

## Theme of the day

Routine activity — no dominant theme emerged.

authentication-bypass, remote-code-execution, dead-drop-resolver, phishing, social-engineering

## Threats published

- [TL-2026-2152](https://intel.threadlinqs.com/threat/TL-2026-2152) — CRITICAL — Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic Chain
- [TL-2026-2156](https://intel.threadlinqs.com/threat/TL-2026-2156) — CRITICAL — Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free (CVE-2026-78899) and ANGLE RCE (CVE-2026-79282)
- [TL-2026-2157](https://intel.threadlinqs.com/threat/TL-2026-2157) — CRITICAL — Critical Avada WordPress Theme Flaw (CVE-2026-18431) Enables Zero-Click RCE
- [TL-2026-2159](https://intel.threadlinqs.com/threat/TL-2026-2159) — CRITICAL — Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth Fail-Open Flaws — NVD Scores 5 of 11 CRITICAL/HIGH Despite Apache's Low/Moderate Ratings
- [TL-2026-2107](https://intel.threadlinqs.com/threat/TL-2026-2107) — CRITICAL — CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted Data (update)
- [TL-2026-2148](https://intel.threadlinqs.com/threat/TL-2026-2148) — HIGH — Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc Demon
- [TL-2026-2151](https://intel.threadlinqs.com/threat/TL-2026-2151) — HIGH — CVE-2026-4800: Lodash `_.template` Arbitrary Code Injection — Broken 4.18.0 Patch Exposes Supply-Chain Patch-Pinning Risk
- [TL-2026-2153](https://intel.threadlinqs.com/threat/TL-2026-2153) — HIGH — Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter Devices
- [TL-2026-2154](https://intel.threadlinqs.com/threat/TL-2026-2154) — HIGH — Hacktivism as Hybrid Warfare: NoName057(16), Killnet, and Handala Hack Escalate Coordinated Disruption Campaigns Against NATO/EU Infrastructure
- [TL-2026-2155](https://intel.threadlinqs.com/threat/TL-2026-2155) — HIGH — "The Com" cross-platform criminal ecosystem: Discord/Telegram/Roblox/Minecraft/X abused for malware distribution, extortion, and predatory recruitment
- [TL-2026-2158](https://intel.threadlinqs.com/threat/TL-2026-2158) — HIGH — Dark Caracal Expands Espionage Arsenal with GoCaracal Framework and AsioGate Backdoor
- [TL-2026-2161](https://intel.threadlinqs.com/threat/TL-2026-2161) — HIGH — CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud Enumeration (AA26-237A)
- [TL-2026-2170](https://intel.threadlinqs.com/threat/TL-2026-2170) — HIGH — Russian State-Backed UNC5792/UNC4221 Phish EU Officials, Diplomats and Journalists via Signal and WhatsApp Linked-Device and OAuth Account Takeover
- [TL-2026-1216](https://intel.threadlinqs.com/threat/TL-2026-1216) — HIGH — Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw CVE-2025-8088 (update)
- [TL-2026-2149](https://intel.threadlinqs.com/threat/TL-2026-2149) — MEDIUM — Dissection of a PHP Backdoor Leveraging php-win.exe for Stealthy Windows Persistence
- [TL-2026-2150](https://intel.threadlinqs.com/threat/TL-2026-2150) — MEDIUM — 24 Malicious npm Packages Abuse Registry Mirrors as Phishing Infrastructure (Fake Cloudflare/Microsoft Login Pages)
- [TL-2026-2160](https://intel.threadlinqs.com/threat/TL-2026-2160) — INFO — StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited by supply-chain attacks (update)

## Techniques observed

[T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.006](https://intel.threadlinqs.com/technique/T1003.006), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.007](https://intel.threadlinqs.com/technique/T1027.007), [T1027.009](https://intel.threadlinqs.com/technique/T1027.009), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.012](https://intel.threadlinqs.com/technique/T1055.012), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), T1059.010, [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069.002](https://intel.threadlinqs.com/technique/T1069.002), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1087.004](https://intel.threadlinqs.com/technique/T1087.004), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1091](https://intel.threadlinqs.com/technique/T1091), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098.001](https://intel.threadlinqs.com/technique/T1098.001), [T1098.003](https://intel.threadlinqs.com/technique/T1098.003), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1114.002](https://intel.threadlinqs.com/technique/T1114.002), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1136.002](https://intel.threadlinqs.com/technique/T1136.002), T1136.003, [T1140](https://intel.threadlinqs.com/technique/T1140), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1218.005](https://intel.threadlinqs.com/technique/T1218.005), [T1219](https://intel.threadlinqs.com/technique/T1219), T1451, [T1484](https://intel.threadlinqs.com/technique/T1484), [T1491.002](https://intel.threadlinqs.com/technique/T1491.002), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1498.001](https://intel.threadlinqs.com/technique/T1498.001), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1499.003](https://intel.threadlinqs.com/technique/T1499.003), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1556](https://intel.threadlinqs.com/technique/T1556), T1556.009, [T1557](https://intel.threadlinqs.com/technique/T1557), T1558.001, [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), [T1561.001](https://intel.threadlinqs.com/technique/T1561.001), T1562.001, [T1564.003](https://intel.threadlinqs.com/technique/T1564.003), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.003](https://intel.threadlinqs.com/technique/T1566.003), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.001](https://intel.threadlinqs.com/technique/T1567.001), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), T1574.002, [T1574.006](https://intel.threadlinqs.com/technique/T1574.006), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.005](https://intel.threadlinqs.com/technique/T1583.005), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1584.004](https://intel.threadlinqs.com/technique/T1584.004), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1586.002](https://intel.threadlinqs.com/technique/T1586.002), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.001](https://intel.threadlinqs.com/technique/T1589.001), [T1589.002](https://intel.threadlinqs.com/technique/T1589.002), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1598.004](https://intel.threadlinqs.com/technique/T1598.004), T1606.001, T1606.002, [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1608.004](https://intel.threadlinqs.com/technique/T1608.004), [T1611](https://intel.threadlinqs.com/technique/T1611), T1615, [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1649](https://intel.threadlinqs.com/technique/T1649), [T1657](https://intel.threadlinqs.com/technique/T1657), [T1684.001](https://intel.threadlinqs.com/technique/T1684.001), [T1685](https://intel.threadlinqs.com/technique/T1685)

## Threat actors

[Amber Saolao](https://intel.threadlinqs.com/actor/Amber%20Saolao), [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)), [The Com](https://intel.threadlinqs.com/actor/The%20Com), [Dark Caracal](https://intel.threadlinqs.com/actor/Dark%20Caracal), [CISA Red Team](https://intel.threadlinqs.com/actor/CISA%20Red%20Team), [UNC5792](https://intel.threadlinqs.com/actor/UNC5792), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP), [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon)

Nation-state attribution: China, Russia, Iran, North Korea (multi-nexus convergence; also financially motivated/unattributed criminal actors), Russia, Iran, Lebanon, Russia

Threat categories: MALWARE, SUPPLY_CHAIN, APT, VULNERABILITY, THREAT_INTEL, PHISHING

## Severity breakdown

- critical: 5
- high: 9
- medium: 2
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 349 (network 73, file 55, infrastructure 53, entity 52, package 46, malware 36, tool 22, behavioral 11, technique 1)
- New detection rules: 153 (100% of the day’s threats covered)

## More editions

- Previous: [2026-08-23](https://intel.threadlinqs.com/debrief/2026-08-23)
- Next: [2026-08-28](https://intel.threadlinqs.com/debrief/2026-08-28)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-08-26
