Skip to content
Weekly Signal

Before the vulnerability record

Threat Activity

Track reported campaigns, active threat actors and targeted sectors, including activity described before a CVE is named.

Updated 21 Aug 2026 · 17:06 UTC

Signals become useful when evidence, behaviour and targets are connected.
Evidence, not prediction.

Pre-CVE means a trusted source has described malicious activity or a previously unknown weakness without naming a CVE. ATT&CK mappings marked Explicit were stated by the source. Inferred mappings are conservative interpretations of source wording and must be verified against the original report.

1Reports in 24 hours
0Pre-CVE reports · 7 days
30Named actors · 30 days
7Targeted sectors · 30 days
2ATT&CK-mapped reports · 7 days

Target-sector mentions · 30 days

Where reported activity is focused

Counts reflect explicit sector mentions in collected reports. One report may mention several sectors, so this is a comparison of evidence coverage rather than a share of all attacks.

Retail is included. A zero means no qualifying report in the current 30-day evidence window named the sector, not that retail faces no threat.

Emerging activity

5 of 5 reports shown

55Signal
PRE-CVETHREAT REPORT

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries.…

Source
Check Point Research
Published
11 Aug 2026 · 17:30 UTC
Actor
Not named
Targets
Defence, Transport
Read source ↗
49Signal
MALWAREFULL REPORT ANALYSED

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Threat IntelligenceGoing with the Flow(s): Distinct Clusters Target Individuals of Interest to RussiaAugust 20, 2026Google Threat Intelligence Group Google Threat IntelligenceVisibility and context on the threats that matter most.Contact Us & Get a Demo Written by: Gabby Roncone,…

Source
Google Threat Intelligence Group
Published
20 Aug 2026 · 14:00 UTC
Targets
Defence, Government, Healthcare, Europe, Ukraine
Read source ↗
49Signal
THREAT REPORT

Updated Cyber Threat Actor Naming System

Update (July 30): A table listing the new names of select prominent threat actors was appended to this post.  Introduction  Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors.…

Source
Google Threat Intelligence Group
Published
24 Jul 2026 · 14:00 UTC
Targets
Defence
Read source ↗
39Signal
THREAT REPORTFULL REPORT ANALYSED

Staying Ahead of Adversarial AI Through Agentic Source Code Review

Threat IntelligenceStaying Ahead of Adversarial AI Through Agentic Source Code ReviewAugust 18, 2026Google Threat Intelligence Group Google Threat IntelligenceVisibility and context on the threats that matter most.Contact Us & Get a Demo Written by: Alex Tselevich, Michael Maturi…

Source
Google Threat Intelligence Group
Published
18 Aug 2026 · 14:00 UTC
Actor
Not named
Targets
Defence, United States, Identity
Read source ↗
37Signal
THREAT REPORTFULL REPORT ANALYSED

Identity Abuse Through Trusted Communication Channels

Threat Research CenterThreat ResearchMalware Malware Identity Abuse Through Trusted Communication Channels 12 min read Related ProductsCortexCortex XDRCortex XSIAMIdiraUnit 42 Incident Response By:Bill Batchelor Published:August 20, 2026 Categories:MalwareThreat Research Tags:AuthenticationIdentity theftMalwareMFARemote access softwareSocial engineering Share Executive Summary Identity has…

Source
Palo Alto Networks Unit 42
Published
20 Aug 2026 · 10:00 UTC
Actor
Not named
Targets
Defence
Read source ↗

Provenance and freshness

Source coverage

The dashboard currently uses freely available government, vendor and vendor-research reporting. A source problem is shown here instead of silently hiding stale data.

HEALTHY

UK NCSC

Last successful collection 21 Aug 2026 · 16:33 UTC

HEALTHY

SentinelLABS

Last successful collection 21 Aug 2026 · 16:33 UTC

HEALTHY

ESET Research

Last successful collection 21 Aug 2026 · 16:33 UTC

HEALTHY

Securelist

Last successful collection 21 Aug 2026 · 16:33 UTC