Detection Playbook: Registry Run Keys / Startup Folder (T1547.001)

T1547.001 · 2026-06-18 Registry Run Keys / Startup Folder Persistence Windows MITRE ATT&CK → Technique Registry Run Keys / Startup Folder (T1547.001) Tactic Persistence Platforms Windows Overview Registry Run Keys and Startup Folder persistence (T1547.001) is a technique where adversaries write entries to specific Windows registry keys or drop files into startup folders so that … Read more

Threat Intelligence Report — June 17, 2026 | 0 New KEVs · 187 Victims

Report Date: 2026-06-17

New KEVs: 0  ▼ -6 vs last weekRansomware Victims: 187  ▲ +44 vs last week

No new vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog during this reporting window. Threat intelligence sources this period reference DragonForce. Ransomware activity is moderate with 187 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Read more

Detection Playbook: Visual Basic (T1059.005)

T1059.005 · 2026-06-17 Visual Basic Execution Linux macOS Windows MITRE ATT&CK → Technique Visual Basic (T1059.005) Tactic Execution Platforms Linux, macOS, Windows Overview Visual Basic (VB) and its derivatives — Visual Basic for Applications (VBA) and VBScript — are scripting and programming languages that adversaries abuse to execute malicious code on target systems. Attackers commonly … Read more

Threat Intelligence Report — June 16, 2026 | 5 New KEVs · 204 Victims

Report Date: 2026-06-16

New KEVs: 5  ▼ -2 vs last weekRansomware Victims: 204  ▲ +72 vs last week

5 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period, of which 1 is linked to active ransomware campaigns. Widget Factory products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 204 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Read more

CVE-2026-48907 — Widget Factory Joomla Content Editor | CVSS 10.0 CRITICAL

CRITICAL

CVSS 10.0 CRITICAL  ·  EPSS 1%  ·  Widget Factory Joomla Content Editor

Read more

Detection Playbook: Scheduled Task (T1053.005)

T1053.005 · 2026-06-16 Scheduled Task Execution Windows MITRE ATT&CK → Technique Scheduled Task (T1053.005) Tactic Execution Platforms Windows Overview Windows Scheduled Tasks (T1053.005) allow adversaries to register code to run automatically at a specified time, interval, or system event. Attackers use this capability to achieve persistence across reboots, execute payloads under elevated contexts such as … Read more

Threat Intelligence Report — June 15, 2026 | 7 New KEVs · 198 Victims

Report Date: 2026-06-15

New KEVs: 7  ▲ +1 vs last weekRansomware Victims: 198  ▲ +71 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period, of which 1 is linked to active ransomware campaigns. Cisco products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 198 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Read more

CVE-2026-54420 — LiteSpeed cPanel Plugin | CVSS 8.5 HIGH

HIGH

CVSS 8.5 HIGH  ·  EPSS 0%  ·  LiteSpeed cPanel Plugin

Read more

Detection Playbook: Windows Management Instrumentation (T1047)

T1047 · 2026-06-15 Windows Management Instrumentation Execution Windows MITRE ATT&CK → Technique Windows Management Instrumentation (T1047) Tactic Execution Platforms Windows Overview Windows Management Instrumentation (WMI) is a built-in Windows administration framework that allows querying system state, executing commands, and managing configuration both locally and remotely. Attackers abuse WMI to run arbitrary payloads, perform reconnaissance, delete … Read more

Threat Intelligence Report — June 14, 2026 | 7 New KEVs · 167 Victims

Report Date: 2026-06-14

New KEVs: 7Ransomware Victims: 167

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period, of which 2 are linked to active ransomware campaigns. Google products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 167 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more