Global Threat Level
ELEVATED
0
CVEs this week
0
Active campaigns
0
Breaches today
0
KEV entries

Latest Intelligence

CRITICAL
Breaches

EU logistics giant confirms 12 TB data exfiltration by LockBit 5.0 affiliate

The threat actor is demanding €40M. A leaked sample contains customer contracts, OT diagrams and Active Directory dumps.

A. Shevchuk · 3h ago 6 min
CRITICAL
Cves

CVE-2026-31872: pre-auth RCE in Apache Stratos with public exploit code

A patch is available, yet roughly 14,000 internet-facing instances remain unpatched. Proof-of-concept code was weaponized within 18 hours of disclosure.

O. Bondar · 5h ago 4 min
HIGH
Ransomware

Cl0p resurfaces with MOVEit-style zero-day campaign targeting MFT vendors

Initial victims include three Fortune 500 firms across healthcare and finance. The group has threatened leak-site disclosure by Friday.

M. Petrenko · 7h ago 5 min
HIGH
Apt

Lazarus pivots to npm supply-chain attacks with 47 malicious packages catalogued

Post-install hooks pull a Go-based loader. Observed targets include Web3 developers and DeFi protocol maintainers.

S. Volkov · 9h ago 7 min
MEDIUM
Policy

CISA emergency directive ED-26-04 mandates Exchange patching by Friday

Federal civilian agencies have 72 hours to apply mitigations or take affected services offline.

I. Kovach · 11h ago 3 min
HIGH
Cves

Three Ivanti EPMM flaws added to CISA KEV with chained exploitation observed

CVE-2026-22014, -22015 and -22016 enable authentication bypass and remote code execution on mobile management consoles.

D. Hrytsenko · 14h ago 4 min
MEDIUM
Breaches

Healthcare provider notifies 2.3M patients after MOVEit-related breach

Stolen data includes SSNs, insurance IDs and clinical notes. The provider is offering 24 months of free credit monitoring.

K. Romaniuk · 1d ago 3 min
HIGH
Apt

Scattered Spider returns with helpdesk-vishing playbook v3

New tradecraft chains deepfake voice samples, MFA-fatigue and SIM-swap inside a 22-minute window.

M. Petrenko · 1d ago 8 min
MEDIUM
Ransomware

BlackBasta affiliate leaks builder source code on a Russian forum

Defenders have gained visibility into the AES-CTR scheme; YARA signatures were published within six hours of the leak.

A. Shevchuk · 2d ago 6 min
LOW
Policy

EU AI Cybersecurity Act passes: what changes for vendors in January 2027

New requirements include mandatory red-team testing, model-card disclosures and post-deployment incident reporting timelines.

I. Kovach · 2d ago 9 min
HIGH
Cves

Critical use-after-free in libwebp resurfaces in Electron 31 stable

Slack, Discord and Signal desktop apps are affected. Recommended mitigation: disable preview rendering until patches ship.

O. Bondar · 3d ago 5 min
HIGH
Breaches

Cloud SaaS vendor exposes 8.2B records via misconfigured Elasticsearch

Researcher disclosure: the snapshot was publicly indexed for 11 days before remediation. Customer notifications are underway.

K. Romaniuk · 3d ago 4 min

Deep Dive · Analysis

All analysis →
Threat Actor

Inside Scattered Spider: TTPs, infra, and 2026 retainer playbook

A full breakdown of social-engineering tradecraft, helpdesk impersonation flows, and the SIM-swap toolchain still in active use.

By M. Petrenko 14 min read
Defense

Detection engineering for living-off-the-land binaries in 2026

Sigma rules, Sysmon configs and the EDR blind spots every SOC analyst should know, complete with sample playbooks.

By I. Kovach 11 min read