Skip to content
Weekly Signal

Before the vulnerability record

Threat Activity

Track reported campaigns, active threat actors and targeted sectors, including activity described before a CVE is named.

Updated 20 Aug 2026 · 15:28 UTC

Evidence, not prediction.

Pre-CVE means a trusted source has described malicious activity or a previously unknown weakness without naming a CVE. ATT&CK mappings marked Explicit were stated by the source. Inferred mappings are conservative interpretations of source wording and must be verified against the original report.

5Reports in 24 hours
0Pre-CVE reports · 7 days
30Named actors · 30 days
7Targeted sectors · 30 days
2ATT&CK-mapped reports · 7 days

Emerging activity

12 of 12 reports shown

49Signal
MALWARE

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Written by: Gabby Roncone, Wesley Shields Overview  Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think…

Source
Google Threat Intelligence Group
Published
20 Aug 2026 · 14:00 UTC
Actor
APT29, STORM-2945, UNC5976, UNC6293, UNC7005
Targets
Defence, Government, Healthcare, Europe, Ukraine
Read source ↗
39Signal
THREAT REPORT

Staying Ahead of Adversarial AI Through Agentic Source Code Review

Written by: Alex Tselevich, Michael Maturi Introduction Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers…

Source
Google Threat Intelligence Group
Published
18 Aug 2026 · 14:00 UTC
Actor
Not named
Targets
Defence, United States, Identity
Read source ↗
37Signal
THREAT REPORT

Identity Abuse Through Trusted Communication Channels

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.

Source
Palo Alto Networks Unit 42
Published
20 Aug 2026 · 10:00 UTC
Actor
Not named
Targets
Defence
Read source ↗
33Signal
THREAT REPORT

Managing the cyber risk of agentic AI

Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.

Source
UK NCSC
Published
20 Aug 2026 · 12:00 UTC
Actor
Not named
Targets
Not specified
Read source ↗
30Signal
THREAT REPORT

Hunting MacSync Stealer infrastructure through behavioral pivots

MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The post Hunting MacSync Stealer infrastructure through behavioral pivots appeared first on Microsoft Security…

Source
Microsoft Security Blog
Published
18 Aug 2026 · 17:08 UTC
Actor
Not named
Targets
Not specified
Read source ↗
29Signal
THREAT REPORT

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from…

Source
Check Point Research
Published
20 Aug 2026 · 13:07 UTC
Actor
Not named
Targets
Not specified
Read source ↗
29Signal
THREAT REPORT

Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)

In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks. The post Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)…

Source
Palo Alto Networks Unit 42
Published
18 Aug 2026 · 19:05 UTC
Actor
Not named
Targets
Not specified
Read source ↗
29Signal
RANSOMWARE

Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Research by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique,…

Source
Check Point Research
Published
18 Aug 2026 · 13:05 UTC
Actor
Not named
Targets
Not specified
Read source ↗
29Signal
RANSOMWARE

17th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure…

Source
Check Point Research
Published
17 Aug 2026 · 13:37 UTC
Actor
Not named
Targets
Not specified
Read source ↗

Provenance and freshness

Source coverage

The dashboard currently uses freely available government, vendor and vendor-research reporting. A source problem is shown here instead of silently hiding stale data.

HEALTHY

UK NCSC

Last successful collection 20 Aug 2026 · 14:58 UTC

HEALTHY

SentinelLABS

Last successful collection 20 Aug 2026 · 14:58 UTC

HEALTHY

ESET Research

Last successful collection 20 Aug 2026 · 14:58 UTC

HEALTHY

Securelist

Last successful collection 20 Aug 2026 · 14:58 UTC