Detection Playbook: SMB/Windows Admin Shares (T1021.002)

T1021.002 · 2026-07-03 SMB/Windows Admin Shares Lateral Movement Windows MITRE ATT&CK → Technique SMB/Windows Admin Shares (T1021.002) Tactic Lateral Movement Platforms Windows Overview SMB/Windows Admin Shares (T1021.002) is a lateral movement technique where attackers use valid credentials — stolen, brute-forced, or obtained through credential dumping — to access hidden administrative network shares such as C$, … Read more

Threat Intelligence Report — July 2, 2026 | 2 New KEVs · 202 Victims

Report Date: 2026-07-02

New KEVs: 2  ▼ -4 vs last weekRansomware Victims: 202  ▲ +46 vs last week

2 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Simplehelp products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference INC Ransom and Scattered Spider. Ransomware activity is moderate with 202 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.

Read more

Detection Playbook: Remote Desktop Protocol (T1021.001)

T1021.001 · 2026-07-02 Remote Desktop Protocol Lateral Movement Windows MITRE ATT&CK → Technique Remote Desktop Protocol (T1021.001) Tactic Lateral Movement Platforms Windows Overview Remote Desktop Protocol (RDP) lateral movement occurs when an adversary uses valid credentials to interactively log into a remote Windows system via port 3389, gaining a full graphical desktop session as the … Read more

Threat Intelligence Report — July 1, 2026 | 4 New KEVs · 145 Victims

Report Date: 2026-07-01

New KEVs: 4  ▼ -1 vs last weekRansomware Victims: 145  ▼ -23 vs last week

4 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference Scattered Spider. Ransomware activity is moderate with 145 new victims posted to leak sites over the last 7 days, with Settra posting the most victims.

Read more

CVE-2026-45659 — Microsoft SharePoint Server: Insecure Deserialization | CVSS 8.8 HIGH

HIGH

CVSS 8.8 HIGH  ·  EPSS 3%  ·  Microsoft SharePoint Server

Read more

Detection Playbook: System Information Discovery (T1082)

T1082 · 2026-07-01 System Information Discovery Discovery ESXi IaaS Linux macOS MITRE ATT&CK → Technique System Information Discovery (T1082) Tactic Discovery Platforms ESXi, IaaS, Linux, macOS, Network Devices, Windows Overview System Information Discovery (T1082) is a technique where adversaries enumerate detailed information about a target system — including OS version, patch level, architecture, hostname, and … Read more

Threat Intelligence Report — June 30, 2026 | 3 New KEVs · 131 Victims

Report Date: 2026-06-30

New KEVs: 3  ▼ -2 vs last weekRansomware Victims: 131  ▼ -34 vs last week

3 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Simplehelp products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 131 new victims posted to leak sites over the last 7 days, with Settra posting the most victims.

Read more

Detection Playbook: Domain Groups (T1069.002)

T1069.002 · 2026-06-30 Domain Groups Discovery Linux macOS Windows MITRE ATT&CK → Technique Domain Groups (T1069.002) Tactic Discovery Platforms Linux, macOS, Windows Overview Domain Groups enumeration (T1069.002) is the act of querying Active Directory or a domain controller to map out domain-level groups and their memberships. Attackers use this information to identify high-value targets — … Read more

Threat Intelligence Report — June 29, 2026 | 7 New KEVs · 117 Victims

Report Date: 2026-06-29

New KEVs: 7  ▲ +5 vs last weekRansomware Victims: 117  ▼ -55 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Ubiquiti products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 117 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Read more

CVE-2026-48558 — SimpleHelp SimpleHelp | CVSS 9.5 CRITICAL

CRITICAL

CVSS 9.5 CRITICAL  ·  EPSS 1%  ·  SimpleHelp  SimpleHelp

Read more