Track reported campaigns, active threat actors and targeted sectors, including activity described before a CVE is named.
Updated 20 Aug 2026 · 15:32 UTC
Evidence, not prediction.
Pre-CVE means a trusted source has described malicious activity or a previously unknown weakness without naming a CVE. ATT&CK mappings marked Explicit were stated by the source. Inferred mappings are conservative interpretations of source wording and must be verified against the original report.
Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think…
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an…
The dashboard currently uses freely available government, vendor and vendor-research reporting. A source problem is shown here instead of silently hiding stale data.