CRITICAL
CVSS 9.5 CRITICAL · EPSS 1% · SimpleHelp SimpleHelp
Threat Intelligence for Every Defender
T1087.002 · 2026-06-29 Domain Account Discovery Linux macOS Windows MITRE ATT&CK → Technique Domain Account (T1087.002) Tactic Discovery Platforms Linux, macOS, Windows Overview Domain Account Discovery (T1087.002) is a technique where adversaries enumerate domain user accounts and groups to map out the Active Directory environment. Attackers use this information to identify high-value targets — domain … Read more
Report Date: 2026-06-28
New KEVs: 6 ▲ +6 vs last weekRansomware Victims: 114 ▼ -94 vs last week
6 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Ubiquiti products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference Turla (Russia). Ransomware activity is moderate with 114 new victims posted to leak sites over the last 7 days, with Stormous posting the most victims.
T1046 · 2026-06-28 Network Service Discovery Discovery Containers IaaS Linux macOS MITRE ATT&CK → Technique Network Service Discovery (T1046) Tactic Discovery Platforms Containers, IaaS, Linux, macOS, Network Devices, Windows Overview Network Service Discovery (T1046) is a reconnaissance technique where adversaries scan local and remote systems to enumerate running services, open ports, and potentially vulnerable software. … Read more
Report Date: 2026-06-27
New KEVs: 6 ▲ +4 vs last weekRansomware Victims: 95 ▼ -109 vs last week
6 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Ubiquiti products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference Turla (Russia). Ransomware activity is low with 95 new victims posted to leak sites over the last 7 days, with Nova posting the most victims.
T1027 · 2026-06-27 Obfuscated Files or Information Stealth ESXi Linux macOS Network Devices MITRE ATT&CK → Technique Obfuscated Files or Information (T1027) Tactic Stealth Platforms ESXi, Linux, macOS, Network Devices, Windows Overview Obfuscated Files or Information (T1027) describes the practice of encoding, encrypting, compressing, or otherwise obscuring malicious content to make it harder for defenders … Read more
Report Date: 2026-06-26
New KEVs: 6 ▲ +6 vs last weekRansomware Victims: 153 ▲ +5 vs last week
6 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Ubiquiti products show the strongest concentration of risk signals this week. Threat intelligence sources this period reference Scattered Spider. Ransomware activity is moderate with 153 new victims posted to leak sites over the last 7 days, with Lockbit5 posting the most victims.
T1218.010 · 2026-06-26 Regsvr32 Stealth Windows MITRE ATT&CK → Technique Regsvr32 (T1218.010) Tactic Stealth Platforms Windows Overview Regsvr32.exe is a legitimate Windows utility designed to register and unregister COM objects and DLLs. Attackers abuse it to execute malicious scripts or DLLs while hiding behind a trusted, Microsoft-signed binary — a technique commonly called “Squiblydoo” when … Read more
Report Date: 2026-06-25
New KEVs: 6 ▲ +6 vs last weekRansomware Victims: 156 ▼ -7 vs last week
6 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Ubiquiti products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 156 new victims posted to leak sites over the last 7 days, with Lockbit5 posting the most victims.