Track reported campaigns, active threat actors and targeted sectors, including activity described before a CVE is named.
Updated 20 Aug 2026 · 16:04 UTC
Evidence, not prediction.
Pre-CVE means a trusted source has described malicious activity or a previously unknown weakness without naming a CVE. ATT&CK mappings marked Explicit were stated by the source. Inferred mappings are conservative interpretations of source wording and must be verified against the original report.
Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise…
The dashboard currently uses freely available government, vendor and vendor-research reporting. A source problem is shown here instead of silently hiding stale data.