Threat Intelligence Report — June 22, 2026 | 2 New KEVs · 172 Victims

Report Date: 2026-06-22

New KEVs: 2  ▼ -5 vs last weekRansomware Victims: 172  ▼ -26 vs last week

2 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Splunk products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference Evil Corp. Ransomware activity is moderate with 172 new victims posted to leak sites over the last 7 days, with Lockbit5 posting the most victims.

Read more

Detection Playbook: Password Spraying (T1110.003)

T1110.003 · 2026-06-22 Password Spraying Credential Access Containers ESXi IaaS Identity Provider MITRE ATT&CK → Technique Password Spraying (T1110.003) Tactic Credential Access Platforms Containers, ESXi, IaaS, Identity Provider, Linux, Network Devices, Office Suite, SaaS, Windows, macOS Overview Password spraying is a credential access technique where an adversary attempts a single commonly used password — or … Read more

Threat Intelligence Report — June 21, 2026 | 0 New KEVs · 208 Victims

Report Date: 2026-06-21

New KEVs: 0  ▼ -7 vs last weekRansomware Victims: 208  ▲ +41 vs last week

No new vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog during this reporting window. Threat intelligence sources this period reference Evil Corp. Ransomware activity is moderate with 208 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Read more

Detection Playbook: LSASS Memory (T1003.001)

T1003.001 · 2026-06-21 LSASS Memory Credential Access Windows MITRE ATT&CK → Technique LSASS Memory (T1003.001) Tactic Credential Access Platforms Windows Overview LSASS Memory dumping (T1003.001) is a credential theft technique where attackers extract authentication material — including NTLM hashes, Kerberos tickets, and in some configurations cleartext passwords — directly from the memory of the Windows … Read more

Threat Intelligence Report — June 20, 2026 | 2 New KEVs · 204 Victims

Report Date: 2026-06-20

New KEVs: 2Ransomware Victims: 204

2 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Cisco products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 204 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Read more

Detection Playbook: DLL Side-Loading (T1574.002)

T1574.002 · 2026-06-20 DLL Side-Loading Defense Evasion MITRE ATT&CK → Technique DLL Side-Loading (T1574.002) Tactic Defense Evasion Platforms Windows, Linux, macOS Overview DLL Side-Loading (T1574.002) is a technique where an attacker places a malicious DLL with a specific filename into a directory that a legitimate, often signed application will search before finding the real DLL. … Read more

Threat Intelligence Report — June 19, 2026 | 0 New KEVs · 148 Victims

Report Date: 2026-06-19

New KEVs: 0  ▼ -7 vs last weekRansomware Victims: 148  ▼ -15 vs last week

No new vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog during this reporting window. Threat intelligence sources this period reference Evil Corp. Ransomware activity is moderate with 148 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Read more

Detection Playbook: Windows Service (T1543.003)

T1543.003 · 2026-06-19 Windows Service Persistence Windows MITRE ATT&CK → Technique Windows Service (T1543.003) Tactic Persistence Platforms Windows Overview Windows Service persistence (T1543.003) allows adversaries to register a malicious executable as a Windows service so it automatically launches every time the system boots or restarts. Because services run under the SYSTEM account by default, attackers … Read more

Threat Intelligence Report — June 18, 2026 | 0 New KEVs · 163 Victims

Report Date: 2026-06-18

New KEVs: 0  ▼ -7 vs last weekRansomware Victims: 163  ▲ +17 vs last week

No new vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog during this reporting window. Threat intelligence sources this period reference DragonForce. Ransomware activity is moderate with 163 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Read more

CVE-2026-20253 — Splunk Enterprise: Missing Authentication | CVSS 9.8 CRITICAL

CRITICAL

CVSS 9.8 CRITICAL  ·  EPSS 2%  ·  Splunk Enterprise

Read more