Threat Intelligence Report — July 14, 2026 | 7 New KEVs · 205 Victims

Report Date: 2026-07-14

New KEVs: 7  ▲ +2 vs last weekRansomware Victims: 205  ▼ -4 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 205 new victims posted to leak sites over the last 7 days, with Deadlock posting the most victims.

Read more

CVE-2026-56155 — Microsoft Active Directory Federation Services | CVSS 7.8 HIGH

HIGH

CVSS 7.8 HIGH  ·  EPSS N/A  ·  Microsoft Active Directory Federation Services

Read more

Detection Playbook: Process Injection (T1055)

T1055 · 2026-07-14 Process Injection Stealth Linux macOS Windows MITRE ATT&CK → Technique Process Injection (T1055) Tactic Stealth Platforms Linux, macOS, Windows Overview Process injection (T1055) is a technique where adversaries insert and execute arbitrary code within the address space of a running, legitimate process. By hijacking a trusted process, attackers can access its memory, … Read more

Threat Intelligence Report — July 13, 2026 | 7 New KEVs · 221 Victims

Report Date: 2026-07-13

New KEVs: 7  ▲ +6 vs last weekRansomware Victims: 221  ▲ +29 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Langflow products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 221 new victims posted to leak sites over the last 7 days, with Deadlock posting the most victims.

Read more

Detection Playbook: Token Impersonation/Theft (T1134.001)

T1134.001 · 2026-07-13 Token Impersonation/Theft Stealth Windows MITRE ATT&CK → Technique Token Impersonation/Theft (T1134.001) Tactic Stealth Platforms Windows Overview Token Impersonation/Theft (T1134.001) is a Windows privilege escalation technique in which an adversary duplicates an existing access token belonging to another user or process — typically one running with elevated privileges — and then impersonates that … Read more

Threat Intelligence Report — July 12, 2026 | 6 New KEVs · 219 Victims

Report Date: 2026-07-12

New KEVs: 6  ▲ +4 vs last weekRansomware Victims: 219  ▲ +31 vs last week

6 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Joomshaper products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference ALPHV / BlackCat and Qilin. Ransomware activity is moderate with 219 new victims posted to leak sites over the last 7 days, with Deadlock posting the most victims.

Read more

Detection Playbook: DNS (T1071.004)

T1071.004 · 2026-07-12 DNS Command And Control ESXi Linux macOS Network Devices MITRE ATT&CK → Technique DNS (T1071.004) Tactic Command And Control Platforms ESXi, Linux, macOS, Network Devices, Windows Overview DNS tunneling (T1071.004) is a command-and-control technique where adversaries embed data — including commands and exfiltrated output — inside DNS query and response packets. Because … Read more

Threat Intelligence Report — July 11, 2026 | 6 New KEVs · 222 Victims

Report Date: 2026-07-11

New KEVs: 6  ▲ +4 vs last weekRansomware Victims: 222  ▲ +20 vs last week

6 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Icagenda products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference ALPHV / BlackCat and Qilin. Ransomware activity is moderate with 222 new victims posted to leak sites over the last 7 days, with Deadlock posting the most victims.

Read more

Detection Playbook: Web Protocols (T1071.001)

T1071.001 · 2026-07-11 Web Protocols Command And Control ESXi Linux macOS Network Devices MITRE ATT&CK → Technique Web Protocols (T1071.001) Tactic Command And Control Platforms ESXi, Linux, macOS, Network Devices, Windows Overview Web Protocols (T1071.001) describes adversaries using HTTP, HTTPS, and WebSocket as the transport layer for command-and-control (C2) communication. Rather than inventing custom protocols, … Read more

Threat Intelligence Report — July 10, 2026 | 6 New KEVs · 197 Victims

Report Date: 2026-07-10

New KEVs: 6  ▲ +4 vs last weekRansomware Victims: 197  ▼ -2 vs last week

6 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Langflow products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference ALPHV / BlackCat and Qilin. Ransomware activity is moderate with 197 new victims posted to leak sites over the last 7 days, with Deadlock posting the most victims.

Read more