Track reported campaigns, active threat actors and targeted sectors, including activity described before a CVE is named.
Updated 21 Aug 2026 · 17:09 UTC
Signals become useful when evidence, behaviour and targets are connected.
Evidence, not prediction.
Pre-CVE means a trusted source has described malicious activity or a previously unknown weakness without naming a CVE. ATT&CK mappings marked Explicit were stated by the source. Inferred mappings are conservative interpretations of source wording and must be verified against the original report.
1Reports in 24 hours
0Pre-CVE reports · 7 days
30Named actors · 30 days
7Targeted sectors · 30 days
2ATT&CK-mapped reports · 7 days
Target-sector mentions · 30 days
Where reported activity is focused
Counts reflect explicit sector mentions in collected reports. One report may mention several sectors, so this is a comparison of evidence coverage rather than a share of all attacks.
Threat IntelligenceGoing with the Flow(s): Distinct Clusters Target Individuals of Interest to RussiaAugust 20, 2026Google Threat Intelligence Group Google Threat IntelligenceVisibility and context on the threats that matter most.Contact Us & Get a Demo Written by: Gabby Roncone,…
Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise…
Update (July 30): A table listing the new names of select prominent threat actors was appended to this post. Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors.…
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an…
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an…
The dashboard currently uses freely available government, vendor and vendor-research reporting. A source problem is shown here instead of silently hiding stale data.