Latest APT activity, actively exploited CVEs, and curated threat intelligence sources.
Hand-curated · Last updated
Operation Dream Job came back carrying CVE-2026-68820, a use-after-free race in afd.sys exploited in the wild for five weeks before the August Patch Tuesday fix. Chain: SEO-poisoned fake vendor sites → trojanized MuPDF viewer → MISTPEN downloader riding the Microsoft Graph API → SYSTEM → FudModule 3.1, which blinds 94 ETW providers and resets Smart App Control's policy state. Defence and aerospace targets in France, Germany, India and Brazil. Full technical breakdown on the blog.
JFrog patched CVE-2026-82329 on Aug 28; by Sep 1 watchTowr was observing attackers minting administrator tokens on default-configuration self-hosted instances, then enumerating users, groups, credentials and federated access to decide whether the environment was worth going deeper into. SaaS is unaffected. An artifact repository is a build-pipeline root of trust, so admin there is downstream code execution everywhere.
Same playbook as MOVEit and Cleo, new target: CVE-2026-12569 in PTC Windchill and FlexPLM, exploited as a zero-day from early June. The chain pairs a pre-auth information disclosure in the FlexPLM WSDL endpoint with a flaw in the Windchill login servlet for unauthenticated RCE, then drops hex-named JSP webshells under /Windchill/login/. Shell, Philips, Fiserv, Zebra and Largan Precision are among those named on the leak site. PLM systems hold product designs, so the exfil target is engineering IP, not customer records.
Darktrace tracked a China-nexus campaign across APJ finance and sports targets using DLL sideloading against legitimate binaries (biz_render.exe, dfsvc.exe) to load a .NET RAT speaking a custom DMTP protocol. Persistence via registry plugin storage plus COM object registration; the framework self-updates every five minutes from icloud-cdn[.]net, AES-decrypting a payload straight into Assembly.Load(). C2 domains impersonate CDNs. A near-complete emulation target: ~12 mapped techniques, no exploit required.
Mandiant's APTnn/FINnn numbering and TAG's separate identifiers merge into one scheme: a memorable first word plus a category word: CASTLE (China), RELIC (Russia), NEPTUNE (North Korea), ION (Iran), COMET (cybercrime). APT44 → SANDWORM RELIC, APT41 → SPIRE CASTLE, FIN7 → WILD COMET. Old names stay searchable and UNC survives for unattributed clusters. Practical impact: actor names are aliases, technique IDs are the stable key.
Confirmed in-the-wild activity
Q3 2026
146 ransomware brands were active as of June 2026, 61 of them new in the preceding year, so the long tail is now most of the problem. Emulate the shared playbook, not the brand.