CRITICAL
CVSS 9.9 CRITICAL · EPSS 0% · Langflow Langflow
Threat Intelligence for Every Defender
T1078 · 2026-07-07 Valid Accounts Stealth Containers ESXi IaaS Identity Provider MITRE ATT&CK → Technique Valid Accounts (T1078) Tactic Stealth Platforms Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows Overview Valid Accounts (T1078) describes adversaries using legitimate, existing credentials — stolen, purchased, phished, or brute-forced — to access systems and … Read more
Report Date: 2026-07-06
New KEVs: 1 ▼ -6 vs last weekRansomware Victims: 192 ▲ +75 vs last week
One new vulnerability was added to the CISA KEV catalog this period. Microsoft products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 192 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.
T1566.002 · 2026-07-06 Spearphishing Link Initial Access Identity Provider Linux macOS Office Suite MITRE ATT&CK → Technique Spearphishing Link (T1566.002) Tactic Initial Access Platforms Identity Provider, Linux, macOS, Office Suite, SaaS, Windows Overview Spearphishing Link (T1566.002) is a targeted email attack where adversaries send carefully crafted messages containing malicious URLs to specific individuals. When the … Read more
Report Date: 2026-07-05
New KEVs: 2 ▼ -4 vs last weekRansomware Victims: 188 ▲ +74 vs last week
2 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 188 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.
T1566.001 · 2026-07-05 Spearphishing Attachment Initial Access Linux macOS Windows MITRE ATT&CK → Technique Spearphishing Attachment (T1566.001) Tactic Initial Access Platforms Linux, macOS, Windows Overview Spearphishing Attachment (T1566.001) is a targeted email-based attack where an adversary sends a crafted email to a specific individual, company, or industry with a malicious file attached — commonly an … Read more
Report Date: 2026-07-04
New KEVs: 2 ▼ -4 vs last weekRansomware Victims: 202 ▲ +107 vs last week
2 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 202 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.
T1569.002 · 2026-07-04 Service Execution Execution Windows MITRE ATT&CK → Technique Service Execution (T1569.002) Tactic Execution Platforms Windows Overview Service Execution (T1569.002) describes how adversaries abuse the Windows Service Control Manager (SCM) to run malicious commands or payloads — either by creating a new service, modifying an existing one, or using tools like sc.exe, net.exe, … Read more
Report Date: 2026-07-03
New KEVs: 2 ▼ -4 vs last weekRansomware Victims: 199 ▲ +46 vs last week
2 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 199 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.