Threat Intelligence Report — July 27, 2026 | 7 New KEVs · 268 Victims

Report Date: 2026-07-27

New KEVs: 7  — unchanged vs last weekRansomware Victims: 268  ▲ +98 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 268 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more

CVE-2026-16812 — Arista VeloCloud Orchestrator: OS Command Injection | CVSS 10.0 CRITICAL

CRITICAL

CVSS 10.0 CRITICAL  ·  EPSS N/A  ·  Arista VeloCloud Orchestrator

Read more

Detection Playbook: Data Destruction (T1485)

T1485 · 2026-07-27 Data Destruction Impact Containers ESXi IaaS Linux MITRE ATT&CK → Technique Data Destruction (T1485) Tactic Impact Platforms Containers, ESXi, IaaS, Linux, macOS, Windows Overview Data Destruction (T1485) is an impact-phase technique where adversaries deliberately overwrite, corrupt, or permanently delete files and data to make recovery impossible — going beyond simple deletion by … Read more

Threat Intelligence Report — July 26, 2026 | 6 New KEVs · 232 Victims

Report Date: 2026-07-26

New KEVs: 6  ▼ -1 vs last weekRansomware Victims: 232  ▲ +63 vs last week

6 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. WordPress products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 232 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more

Detection Playbook: External Remote Services (T1133)

T1133 · 2026-07-26 External Remote Services Persistence Containers Linux macOS Windows MITRE ATT&CK → Technique External Remote Services (T1133) Tactic Persistence Platforms Containers, Linux, macOS, Windows Overview External Remote Services (T1133) describes adversaries abusing legitimate remote access mechanisms — VPNs, Citrix, RDP gateways, SSH, VNC, exposed APIs, and similar services — to gain or maintain … Read more

Threat Intelligence Report — July 25, 2026 | 6 New KEVs · 175 Victims

Report Date: 2026-07-25

New KEVs: 6  ▼ -1 vs last weekRansomware Victims: 175  ▲ +15 vs last week

6 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. WordPress products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 175 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more

Detection Playbook: Malicious File (T1204.002)

T1204.002 · 2026-07-25 Malicious File Execution Linux macOS Windows MITRE ATT&CK → Technique Malicious File (T1204.002) Tactic Execution Platforms Linux, macOS, Windows Overview Malicious File (T1204.002) describes an attacker tricking a user into opening a weaponized file — such as a macro-enabled Office document, a disguised executable, a malicious PDF, or a container file like … Read more

Threat Intelligence Report — July 24, 2026 | 6 New KEVs · 169 Victims

Report Date: 2026-07-24

New KEVs: 6  ▼ -1 vs last weekRansomware Victims: 169  ▼ -2 vs last week

6 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. WordPress products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference Qilin. Ransomware activity is moderate with 169 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more

Detection Playbook: JavaScript (T1059.007)

T1059.007 · 2026-07-24 JavaScript Execution Linux macOS Windows MITRE ATT&CK → Technique JavaScript (T1059.007) Tactic Execution Platforms Linux, macOS, Windows Overview T1059.007 covers adversary abuse of JavaScript and its runtime variants — including JScript on Windows, Node.js across platforms, and JavaScript for Automation (JXA) on macOS — to execute malicious code. Attackers use these scripting … Read more

Threat Intelligence Report — July 23, 2026 | 6 New KEVs · 178 Victims

Report Date: 2026-07-23

New KEVs: 6  ▼ -1 vs last weekRansomware Victims: 178  ▼ -53 vs last week

6 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. WordPress products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference Qilin. Ransomware activity is moderate with 178 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more