CRITICAL
CVSS 9.8 CRITICAL · EPSS 20% · Microsoft SharePoint
Threat Intelligence for Every Defender
Modify Registry (T1112) describes adversary interactions with the Windows Registry to achieve defense evasion, persistence, or execution. Attackers use regis…
Report Date: 2026-07-21
New KEVs: 7 — unchanged vs last weekRansomware Victims: 160 ▼ -45 vs last week
7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Fortinet products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference Qilin. Ransomware activity is moderate with 160 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.
File and Directory Discovery (T1083) refers to adversaries actively enumerating the file system — listing directories, searching for specific file types, and…
Report Date: 2026-07-20
New KEVs: 7 — unchanged vs last weekRansomware Victims: 170 ▼ -51 vs last week
7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 170 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.
Process Discovery (T1057) is a reconnaissance technique where adversaries enumerate running processes on a compromised system to understand what software is …
Report Date: 2026-07-19
New KEVs: 7 ▲ +1 vs last weekRansomware Victims: 169 ▼ -50 vs last week
7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 169 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.