Skip to content
Weekly Signal

Before the vulnerability record

Threat Activity

Track reported campaigns, active threat actors and targeted sectors, including activity described before a CVE is named.

Updated 20 Aug 2026 · 15:30 UTC

Evidence, not prediction.

Pre-CVE means a trusted source has described malicious activity or a previously unknown weakness without naming a CVE. ATT&CK mappings marked Explicit were stated by the source. Inferred mappings are conservative interpretations of source wording and must be verified against the original report.

5Reports in 24 hours
0Pre-CVE reports · 7 days
30Named actors · 30 days
7Targeted sectors · 30 days
2ATT&CK-mapped reports · 7 days

Emerging activity

2 of 2 reports shown

49Signal
RANSOMWARE

Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise

Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise…

Source
Google Threat Intelligence Group
Published
30 Jul 2026 · 14:00 UTC
Actor
APT29, UNC1069, UNC4736, UNC6780
Targets
Mobile, Operational technology, Supply chain
Read source ↗
49Signal
THREAT REPORT

Updated Cyber Threat Actor Naming System

Update (July 30): A table listing the new names of select prominent threat actors was appended to this post.  Introduction  Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors.…

Source
Google Threat Intelligence Group
Published
24 Jul 2026 · 14:00 UTC
Actor
APT15, APT20, APT27, APT28, APT29, APT30, APT31, APT33, APT34, APT35, APT37, APT39, APT40, APT41, APT42, APT44, APT45, FIN7, Sandworm, UNC1069, UNC1088, UNC2814, UNC4057
Targets
Defence
Read source ↗

Provenance and freshness

Source coverage

The dashboard currently uses freely available government, vendor and vendor-research reporting. A source problem is shown here instead of silently hiding stale data.

HEALTHY

UK NCSC

Last successful collection 20 Aug 2026 · 14:58 UTC

HEALTHY

SentinelLABS

Last successful collection 20 Aug 2026 · 14:58 UTC

HEALTHY

ESET Research

Last successful collection 20 Aug 2026 · 14:58 UTC

HEALTHY

Securelist

Last successful collection 20 Aug 2026 · 14:58 UTC