Detection Playbook: Windows Command Shell (T1059.003)

T1059.003 · 2026-06-14 Windows Command Shell Execution Windows MITRE ATT&CK → Technique Windows Command Shell (T1059.003) Tactic Execution Platforms Windows Overview Windows Command Shell (T1059.003) refers to adversary abuse of cmd.exe — the native Windows command interpreter — to execute commands, run batch scripts (.bat/.cmd files), and interact with nearly every layer of the operating … Read more

Detection Playbook: PowerShell (T1059.001)

T1059.001 · 2026-06-13 PowerShell Execution Windows MITRE ATT&CK → Technique PowerShell (T1059.001) Tactic Execution Platforms Windows Overview PowerShell (T1059.001) refers to adversary abuse of Windows PowerShell — Microsoft’s built-in scripting language and interactive shell — to execute commands, run scripts, download payloads, and perform post-exploitation activity. Because PowerShell is deeply integrated into Windows administration and … Read more

Threat Intelligence Report — June 13, 2026 | 7 New KEVs · 162 Victims

Report Date: 2026-06-13

New KEVs: 7  ▲ +2 vs last weekRansomware Victims: 162  ▲ +38 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period, of which 2 are linked to active ransomware campaigns. Oracle products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 162 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more

Threat Intelligence Report — June 12, 2026 | 7 New KEVs · 163 Victims

Report Date: 2026-06-12

New KEVs: 7  ▲ +2 vs last weekRansomware Victims: 163  ▲ +23 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period, of which 2 are linked to active ransomware campaigns. Google products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 163 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more

CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools: Missing Authentication | CVSS 9.8 CRITICAL

CRITICAL

CVSS 9.8 CRITICAL  ·  EPSS 0%  ·  Oracle  PeopleSoft Enterprise PeopleTools

Read more

Threat Intelligence Report — June 11, 2026 | 7 New KEVs · 146 Victims

Report Date: 2026-06-11

New KEVs: 7  ▲ +2 vs last weekRansomware Victims: 146  ▲ +14 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period, of which 1 is linked to active ransomware campaigns. Google products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 146 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more

CVE-2026-10520 — Ivanti Sentry: OS Command Injection | CVSS 10.0 CRITICAL

CRITICAL

CVSS 10.0 CRITICAL  ·  EPSS 3%  ·  Ivanti Sentry

Read more

Threat Intelligence Report — June 10, 2026 | 6 New KEVs · 143 Victims

Report Date: 2026-06-10

New KEVs: 6  ▲ +1 vs last weekRansomware Victims: 143  — unchanged vs last week

6 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period, of which 1 is linked to active ransomware campaigns. Google products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 143 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Read more

Threat Intelligence Report — June 9, 2026 | 7 New KEVs · 132 Victims

Report Date: 2026-06-09

New KEVs: 7  — unchanged vs last weekRansomware Victims: 132  ▼ -27 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period, of which 1 is linked to active ransomware campaigns. Google products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 132 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Read more

CVE-2026-20245 — Cisco Catalyst SD-WAN Manager | CVSS 7.8 HIGH

HIGH

CVSS 7.8 HIGH  ·  EPSS 0%  ·  Cisco Catalyst SD-WAN Manager

Read more