Detection Playbook: Match Legitimate Resource Name or Location (T1036.005)

T1036.005 · 2026-07-23 Match Legitimate Resource Name or Location Stealth Containers ESXi Linux macOS MITRE ATT&CK → Technique Match Legitimate Resource Name or Location (T1036.005) Tactic Stealth Platforms Containers, ESXi, Linux, macOS, Windows Overview Match Legitimate Resource Name or Location (T1036.005) is a masquerading technique where adversaries rename malicious executables, scripts, or other resources to … Read more

Threat Intelligence Report — July 22, 2026 | 7 New KEVs · 164 Victims

Report Date: 2026-07-22

New KEVs: 7  — unchanged vs last weekRansomware Victims: 164  ▼ -48 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference Qilin. Ransomware activity is moderate with 164 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more

CVE-2026-16232 — Check Point SmartConsole: Improper Authentication | CVSS 9.1 CRITICAL

CRITICAL

CVSS 9.1 CRITICAL  ·  EPSS N/A  ·  Check Point SmartConsole

Read more

CVE-2026-50522 — Microsoft SharePoint: Insecure Deserialization | CVSS 9.8 CRITICAL

CRITICAL

CVSS 9.8 CRITICAL  ·  EPSS 20%  ·  Microsoft SharePoint

Read more

Detection Playbook: Modify Registry (T1112)

T1112 · 2026-07-22 Modify Registry Defense Impairment Windows MITRE ATT&CK → Technique Modify Registry (T1112) Tactic Defense Impairment Platforms Windows Overview Modify Registry (T1112) describes adversary interactions with the Windows Registry to achieve defense evasion, persistence, or execution. Attackers use registry modifications to disable security tooling, store encoded payloads, enable dangerous features like plaintext credential … Read more

Threat Intelligence Report — July 21, 2026 | 7 New KEVs · 160 Victims

Report Date: 2026-07-21

New KEVs: 7  — unchanged vs last weekRansomware Victims: 160  ▼ -45 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Fortinet products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference Qilin. Ransomware activity is moderate with 160 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more

CVE-2021-27137 — DD-WRT DD-WRT | CVSS 8.1 HIGH

HIGH

CVSS 8.1 HIGH  ·  EPSS 5%  ·  DD-WRT DD-WRT

Read more

CVE-2026-0770 — Langflow Langflow | CVSS 9.8 CRITICAL

CRITICAL

CVSS 9.8 CRITICAL  ·  EPSS 10%  ·  Langflow Langflow

Read more

CVE-2026-63030 — WordPress Core | CVSS 9.8 CRITICAL

CRITICAL

CVSS 9.8 CRITICAL  ·  EPSS 9%  ·  WordPress Core

Read more

Detection Playbook: File and Directory Discovery (T1083)

T1083 · 2026-07-21 File and Directory Discovery Discovery ESXi Linux macOS Network Devices MITRE ATT&CK → Technique File and Directory Discovery (T1083) Tactic Discovery Platforms ESXi, Linux, macOS, Network Devices, Windows Overview File and Directory Discovery (T1083) refers to adversaries actively enumerating the file system — listing directories, searching for specific file types, and mapping … Read more