# Daily Intelligence Briefing — Saturday, August 29, 2026

> On 2026-08-29, Threadlinqs published 18 new threat reports and updated 14, 11 rated critical and 19 high, spanning 221 MITRE ATT&CK techniques and 16 named threat actors. Coverage that day added 288 new detection rules and 784 extracted indicators.

- **Edition:** 2026-08-29 (Saturday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-08-29
- **Last updated:** 2026-09-04
- **New threats:** 18 (14 updated)
- **Critical / high:** 11 critical, 19 high, 2 medium, 0 low
- **ATT&CK techniques:** 221
- **Threat actors:** 16
- **Indicators (count only):** 784
- **New detection rules (count only):** 288

## Summary & highlights

Threat Actors Impersonate OpenAI, Anthropic, and DeepSeek AI Crawlers to Harvest Credentials and Secrets. Emperador ransomware group claims breach of Uniguaçu (Brazilian education sector). Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware.

- [TL-2026-2197](https://intel.threadlinqs.com/threat/TL-2026-2197) — Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware
- [TL-2026-2199](https://intel.threadlinqs.com/threat/TL-2026-2199) — ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked to Vanilla Tempest
- [TL-2026-2201](https://intel.threadlinqs.com/threat/TL-2026-2201) — Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations System
- [TL-2026-2202](https://intel.threadlinqs.com/threat/TL-2026-2202) — TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and India
- [TL-2026-2203](https://intel.threadlinqs.com/threat/TL-2026-2203) — Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel via ClickFix-Style DLL Sideloading

## Theme of the day

Unattributed threats dominated the day, with Qilin ransomware and Silent Ransom Group also active, alongside diverse malware like AMOS and ArechClient2.

privilege-escalation, remote-code-execution, double-extortion, scheduled-task-persistence, social-engineering

## Threats published

- [TL-2026-2208](https://intel.threadlinqs.com/threat/TL-2026-2208) — CRITICAL — ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and Salesforce/Snowflake Compromise
- [TL-2026-2210](https://intel.threadlinqs.com/threat/TL-2026-2210) — CRITICAL — Five Critical WordPress Plugin/Theme Flaws (CVSS up to 10.0) Enable Site Takeover or RCE: WPMU DEV Dashboard, Avada/Fusion Builder, TranslatePress, Pods, GiveWP
- [TL-2026-2221](https://intel.threadlinqs.com/threat/TL-2026-2221) — CRITICAL — Pre-Authentication Remote Code Execution in SPIP CMS (CVE-2026-77806) — Actively Exploited
- [TL-2026-0304](https://intel.threadlinqs.com/threat/TL-2026-0304) — CRITICAL — TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload (update)
- [TL-2026-1767](https://intel.threadlinqs.com/threat/TL-2026-1767) — CRITICAL — Gitea Remote Code Execution via diffpatch Git Hook Installation (CVE-2026-60004) (update)
- [TL-2026-2092](https://intel.threadlinqs.com/threat/TL-2026-2092) — CRITICAL — Gogs Critical RCE via Path Traversal in Organization Names (CVE-2026-52813) (update)
- [TL-2026-2157](https://intel.threadlinqs.com/threat/TL-2026-2157) — CRITICAL — Critical Avada WordPress Theme Flaw (CVE-2026-18431) Enables Zero-Click RCE (update)
- [TL-2026-2177](https://intel.threadlinqs.com/threat/TL-2026-2177) — CRITICAL — CVE-2026-65643: Arbitrary File Creation in cPanel/WHM Domain Parking Leads to Root-Level Code Execution (update)
- [TL-2026-2184](https://intel.threadlinqs.com/threat/TL-2026-2184) — CRITICAL — PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation (update)
- [TL-2026-2195](https://intel.threadlinqs.com/threat/TL-2026-2195) — CRITICAL — ServiceNow Patches Four Critical Flaws Including Three CVSS 10.0 Unauthenticated RCE/SQLi Bugs (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, CVE-2026-6876) (update)
- [TL-2026-2196](https://intel.threadlinqs.com/threat/TL-2026-2196) — CRITICAL — UniBLEed: Unauthenticated Root RCE Chain Over Bluetooth in Unitree G1 EDU Humanoid Robot (CVE-2026-76639, CVE-2026-76640) (update)
- [TL-2026-2197](https://intel.threadlinqs.com/threat/TL-2026-2197) — HIGH — Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware
- [TL-2026-2199](https://intel.threadlinqs.com/threat/TL-2026-2199) — HIGH — ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked to Vanilla Tempest
- [TL-2026-2201](https://intel.threadlinqs.com/threat/TL-2026-2201) — HIGH — Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations System
- [TL-2026-2202](https://intel.threadlinqs.com/threat/TL-2026-2202) — HIGH — TA4922 Deploys PackClient RAT via Tax-Themed Phishing Against Organizations in China and India
- [TL-2026-2203](https://intel.threadlinqs.com/threat/TL-2026-2203) — HIGH — Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel via ClickFix-Style DLL Sideloading
- [TL-2026-2206](https://intel.threadlinqs.com/threat/TL-2026-2206) — HIGH — Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Election
- [TL-2026-2212](https://intel.threadlinqs.com/threat/TL-2026-2212) — HIGH — PEAR ransomware group claims data leak from South Plains Rural Health Services (SPRHS)
- [TL-2026-2213](https://intel.threadlinqs.com/threat/TL-2026-2213) — HIGH — APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and Türkiye
- [TL-2026-2214](https://intel.threadlinqs.com/threat/TL-2026-2214) — HIGH — Hundreds of WordPress Sites Hijacked via Malicious Plugins to Deploy Amatera Stealer through EtherHiding and ClickFix
- [TL-2026-2217](https://intel.threadlinqs.com/threat/TL-2026-2217) — HIGH — Fake Beijing Institute of Technology Resume Lure Delivers SNOWLIGHT Shellcode and Fileless VShell RAT to Chinese Academic Researchers
- [TL-2026-2219](https://intel.threadlinqs.com/threat/TL-2026-2219) — HIGH — Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breach
- [TL-2026-2220](https://intel.threadlinqs.com/threat/TL-2026-2220) — HIGH — CVE-2026-53362 ("ipv6_frag_escape"): Linux Kernel IPv6 Fragmentation Flaw Enables Container-to-Host Privilege Escalation, Actively Exploited — Added to CISA KEV
- [TL-2026-2223](https://intel.threadlinqs.com/threat/TL-2026-2223) — HIGH — Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access (CVE-2025-31718 + Unpatched MPU Privilege Escalation)
- [TL-2026-0828](https://intel.threadlinqs.com/threat/TL-2026-0828) — HIGH — BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling Large-Scale Credential Harvesting, AiTM MFA Bypass, and Account Takeover (update)
- [TL-2026-0884](https://intel.threadlinqs.com/threat/TL-2026-0884) — HIGH — FishMonger (I-SOON / Winnti) Ports SprySOCKS Backdoor to Windows — WIN_DRV (RawWNPF Kernel Rootkit) & WIN_PLUS Variants (update)
- [TL-2026-2173](https://intel.threadlinqs.com/threat/TL-2026-2173) — HIGH — BlueDelta (GRU/APT28) Targets Defense and Diplomacy with HOOKEDGE Backdoor (update)
- [TL-2026-2200](https://intel.threadlinqs.com/threat/TL-2026-2200) — HIGH — SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governments (update)
- [TL-2026-2209](https://intel.threadlinqs.com/threat/TL-2026-2209) — HIGH — Chaos Ransomware Claims MacAllister (macallister.com) — 75GB Data Exfiltration Claimed, Leadership Refused Engagement (update)
- [TL-2026-2229](https://intel.threadlinqs.com/threat/TL-2026-2229) — HIGH — Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Theft (update)
- [TL-2026-2204](https://intel.threadlinqs.com/threat/TL-2026-2204) — MEDIUM — Threat Actors Impersonate OpenAI, Anthropic, and DeepSeek AI Crawlers to Harvest Credentials and Secrets
- [TL-2026-2207](https://intel.threadlinqs.com/threat/TL-2026-2207) — MEDIUM — Emperador ransomware group claims breach of Uniguaçu (Brazilian education sector)

## Techniques observed

[T1001](https://intel.threadlinqs.com/technique/T1001), [T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.003](https://intel.threadlinqs.com/technique/T1003.003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1007](https://intel.threadlinqs.com/technique/T1007), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1010](https://intel.threadlinqs.com/technique/T1010), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1021.005](https://intel.threadlinqs.com/technique/T1021.005), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1027.003](https://intel.threadlinqs.com/technique/T1027.003), [T1027.010](https://intel.threadlinqs.com/technique/T1027.010), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.008](https://intel.threadlinqs.com/technique/T1036.008), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.003](https://intel.threadlinqs.com/technique/T1053.003), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.002](https://intel.threadlinqs.com/technique/T1059.002), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069.002](https://intel.threadlinqs.com/technique/T1069.002), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1074.001](https://intel.threadlinqs.com/technique/T1074.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.003](https://intel.threadlinqs.com/technique/T1078.003), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1080](https://intel.threadlinqs.com/technique/T1080), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1091](https://intel.threadlinqs.com/technique/T1091), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.004](https://intel.threadlinqs.com/technique/T1098.004), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110.003](https://intel.threadlinqs.com/technique/T1110.003), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1124](https://intel.threadlinqs.com/technique/T1124), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1132.002](https://intel.threadlinqs.com/technique/T1132.002), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1204.004](https://intel.threadlinqs.com/technique/T1204.004), [T1205](https://intel.threadlinqs.com/technique/T1205), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1218.005](https://intel.threadlinqs.com/technique/T1218.005), [T1218.007](https://intel.threadlinqs.com/technique/T1218.007), [T1218.011](https://intel.threadlinqs.com/technique/T1218.011), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1480](https://intel.threadlinqs.com/technique/T1480), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1491.002](https://intel.threadlinqs.com/technique/T1491.002), [T1496](https://intel.threadlinqs.com/technique/T1496), T1496.001, [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1497.003](https://intel.threadlinqs.com/technique/T1497.003), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), T1542.003, [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1547.013](https://intel.threadlinqs.com/technique/T1547.013), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.001](https://intel.threadlinqs.com/technique/T1555.001), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1558.003](https://intel.threadlinqs.com/technique/T1558.003), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1564.003](https://intel.threadlinqs.com/technique/T1564.003), [T1564.004](https://intel.threadlinqs.com/technique/T1564.004), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.004](https://intel.threadlinqs.com/technique/T1566.004), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.001](https://intel.threadlinqs.com/technique/T1567.001), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1567.004](https://intel.threadlinqs.com/technique/T1567.004), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1584.004](https://intel.threadlinqs.com/technique/T1584.004), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.001](https://intel.threadlinqs.com/technique/T1588.001), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589.002](https://intel.threadlinqs.com/technique/T1589.002), [T1590](https://intel.threadlinqs.com/technique/T1590), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), T1595.003, [T1598](https://intel.threadlinqs.com/technique/T1598), [T1601.001](https://intel.threadlinqs.com/technique/T1601.001), [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1610](https://intel.threadlinqs.com/technique/T1610), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1622](https://intel.threadlinqs.com/technique/T1622), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657), T1664, [T1665](https://intel.threadlinqs.com/technique/T1665), T1681, [T1684.001](https://intel.threadlinqs.com/technique/T1684.001), [T1685](https://intel.threadlinqs.com/technique/T1685), [T1685.005](https://intel.threadlinqs.com/technique/T1685.005)

## Threat actors

[Emperador](https://intel.threadlinqs.com/actor/Emperador), [Vanilla Tempest](https://intel.threadlinqs.com/actor/Vanilla%20Tempest), [Qilin](https://intel.threadlinqs.com/actor/Qilin), [TA4922](https://intel.threadlinqs.com/actor/TA4922), [Rhysida](https://intel.threadlinqs.com/actor/Rhysida), [PEAR](https://intel.threadlinqs.com/actor/PEAR), [APT28](https://intel.threadlinqs.com/actor/APT28), [Dark Caracal](https://intel.threadlinqs.com/actor/Dark%20Caracal), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters), [BlueKit operators](https://intel.threadlinqs.com/actor/BlueKit%20operators), [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta), [SilkParasite](https://intel.threadlinqs.com/actor/SilkParasite), [Chaos](https://intel.threadlinqs.com/actor/Chaos), [Interlock](https://intel.threadlinqs.com/actor/Interlock), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP)

Nation-state attribution: Russia, CN, Lebanon, China

Threat categories: THREAT_INTEL, RANSOMWARE, MALWARE, DATA_BREACH, VULNERABILITY, PHISHING, APT, SUPPLY_CHAIN

## Severity breakdown

- critical: 11
- high: 19
- medium: 2
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 784 (file 214, network 193, entity 90, behavioral 83, infrastructure 64, tool 58, malware 43, package 36, technique 3)
- New detection rules: 288 (100% of the day’s threats covered)

## More editions

- Previous: [2026-08-28](https://intel.threadlinqs.com/debrief/2026-08-28)
- Next: [2026-08-31](https://intel.threadlinqs.com/debrief/2026-08-31)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-08-29
