Archive
Cyber Threat Intelligence
130 editions
September 2026
10 editions- 11 Sept AI-Enabled Intrusions Meet 59 Exposure ClaimsFifty-nine breach and leak claims joined 51 defacements as GitLab, PaperCut and Cisco flaws drew exploitation and Trezor warned 347,000 users.198 ev 59 crit
- 10 Sept CoupDeGrace Dominates as 41 Critical Exposures Hit GloballyCoupDeGrace leads 20 of 152 tracked events as 41 alleged exposures hit finance, healthcare and government targets across multiple regions.152 ev 41 crit
- 9 Sept Telegram Data Sale, Gov Leaks Dominate Threat LandscapeZasnit's alleged Telegram data sale leads 179 tracked events, while CoupDeGrace and wpdealer drive government, telecom and finance exposure.179 ev 44 crit
- 8 Sept Telegram Harvesting Meets a Record Patch LoadZasnit and aha alleged broad account and university breaches as Microsoft fixed 974 flaws, including two exploited zero-days.237 ev 65 crit
- 7 Sept Ransomware Rebounds as Critical RCEs SurfaceThe Gentlemen leads 200 tracked claims as ransomware reaches 42 events; N-central, Magento, ScreenConnect and PEEP raise urgent defense priorities.200 ev 48 crit
- 6 Sept Public-Sector Claims Meet Router and Miner ThreatsFifty-seven alleged exposures span DOJ/FBI, ASUS, CoinPayments, and Odido as MikroTik router hijacks and REVSTEALER persistence add operational risk.181 ev 57 crit
- 5 Sept Public-Sector Breach Claims Span Three RegionsForty-six alleged breaches and leaks hit public agencies, finance and retail as Magento, TeamCity, Elementor Pro and PaperCut flaws drew attacks.206 ev 46 crit
- 4 Sept CTI Daily Brief: 2026-09-04GrayscaleInsight cyber threat intelligence brief for 2026-09-04: tracked incidents, threat actor activity, and external analysis.204 ev 59 crit
- 3 Sept HollowCrimeCorp, ChimeraZ Drive Multi-Sector Breach Wave Across France, BrazilThreat actors target France, Brazil, US with breaches spanning telecom, health, government; AI-driven attacks hit Latin America.262 ev 81 crit
- 2 Sept Taiwan Targeted in Mass Data Breach Wave; IT Support Scams RiseFORUM SHOP ROSTAM claims 25+ Taiwan breaches. Dropbox, Ticketmaster, Coinbase alleged leaks. Microsoft warns of Teams IT support impersonation attacks.251 ev 85 crit
August 2026
20 editions- 27 Aug MrDarkRoot Targets Global Education Sector in Mass Data Sale CampaignMrDarkRoot claims 18 education-sector data sales across 12 countries, hitting US universities and Israeli Ministry of Education. DDoS and initial access activity also tracked.33 ev 18 crit
- 26 Aug CTI Daily Brief: 2026-08-26GrayscaleInsight cyber threat intelligence brief for 2026-08-26: tracked incidents, threat actor activity, and external analysis.239 ev 100 crit
- 25 Aug Data Theft Claims Converge on Banks and GovernmentMarket Exchange bank claims join 59 alleged exposures as active WebLogic and WordPress flaws raise patching and identity risks.209 ev 59 crit
- 23 Aug CTI Daily Brief: 2026-08-23GrayscaleInsight cyber threat intelligence brief for 2026-08-23: tracked incidents, threat actor activity, and external analysis.244 ev 84 crit
- 22 Aug CTI Daily Brief: 2026-08-22GrayscaleInsight cyber threat intelligence brief for 2026-08-22: tracked incidents, threat actor activity, and external analysis.220 ev 70 crit
- 21 Aug CTI Daily Brief: 2026-08-21GrayscaleInsight cyber threat intelligence brief for 2026-08-21: tracked incidents, threat actor activity, and external analysis.295 ev 114 crit
- 20 Aug OAuth Espionage Meets Government Data ClaimsUNC7005 and GARUDA claims coincide with 192 incidents, while CVE-2026-73570 exploitation and a Rust supply-chain attack sharpen response priorities.192 ev 56 crit
- 19 Aug Breach Claims Hit Public Services as Exploits Surge220 events included 60 breach or leak claims; DarkMafiaX and BLACK HAT HACKERS FORCE appeared as CISA flagged four actively exploited flaws.220 ev 60 crit
- 18 Aug Financial Data Claims Converge With Active ExploitsExchange Markets claims HSBC and Manulife data sales as 53 critical exposures coincide with Medusa passing 500 victims and active Ray exploitation.218 ev 53 crit
- 17 Aug Public-Sector Breach Claims Span Three RegionsTrenggalek Cyber Army led 252 alleged events; 64 breach or leak claims hit government, telecom and healthcare as GitLab and Forminator flaws emerged.252 ev 64 crit
- 16 Aug South Asia Breach Claims Target Government, EducationShadow Protocol and Qilin feature in 346 alleged incidents, including 93 exposure claims across government, education, and major brands.346 ev 93 crit
- 15 Aug Credential Markets Surge Amid Regional Breach ClaimsX0Frankenstein, TeamPrabal and ZoneX404 drove 76 alleged exposures among 178 events, spanning banks, government and identity systems.178 ev 76 crit
- 14 Aug Financial Breach Claims Meet Supply-Chain ExposuresShipMonk exposure affected 14,000 Trezor customers as alleged finance breaches and GeoServer exploitation shaped a 184-event CTI day.184 ev 60 crit
- 13 Aug Government Breach Claims Meet Active Zero-DaysDeepCore Network led 170 events as 67 alleged exposures hit public and financial targets while two critical CVEs drew active exploitation.170 ev 67 crit
- 12 Aug French Breach Claims Rise as Lazarus Exploits Zero-DaySophia and Sophia01 claim 14 breaches, mostly in France; Lazarus exploits a Windows zero-day as 231 events include 69 breach or leak exposures.231 ev 69 crit
- 11 Aug Defense Data Claims Meet Resilient Botnet Threats301 events included 151 exposure claims; kyoshin33 targeted Indian defense data as Kimwolf v7 and an exploited Windows flaw raised urgency.301 ev 151 crit
- 10 Aug Credential Markets Converge With Infrastructure AttacksAcross 362 events, 175 alleged exposures joined Gunra ransomware, Polish energy sabotage, and public-sector breach claims.362 ev 175 crit
- 9 Aug Crypto and Public-Sector Breach Claims AccelerateDisrupt0r claims OKX and Binance; Evilx targets six Syrian institutions as 90 breach and leak claims span finance, government and education.268 ev 90 crit
- 8 Aug Government Breach Claims Meet Active Zero-Day ExploitsShinyHunt, K3LLLEAKERS and Iron Atlas appear among 56 alleged exposure events as Metabase, Rovo AI and LoadMaster flaws draw urgent action.188 ev 56 crit
- 7 Aug HELIX Breach Spree Hits Logistics and Real EstateHELIX claims breaches at Uber Freight, Westland, Morguard. Indonesia hit by 32 events. WordPress XSS, Linux SCTP flaws patched. UNC6671 vishing expands.254 ev 99 crit