UK NCSC
Last successful collection 21 Aug 2026 · 16:33 UTC
Before the vulnerability record
Track reported campaigns, active threat actors and targeted sectors, including activity described before a CVE is named.
Updated 21 Aug 2026 · 17:57 UTC

Pre-CVE means a trusted source has described malicious activity or a previously unknown weakness without naming a CVE. ATT&CK mappings marked Explicit were stated by the source. Inferred mappings are conservative interpretations of source wording and must be verified against the original report.
Target-sector mentions · 30 days
Counts reflect explicit sector mentions in collected reports. One report may mention several sectors, so this is a comparison of evidence coverage rather than a share of all attacks.
Retail is included. A zero means no qualifying report in the current 30-day evidence window named the sector, not that retail faces no threat.
0 of 0 reports shown
Try a wider reporting window or clear a filter. The feed fills after the first threat-feeds job runs.
Provenance and freshness
The dashboard currently uses freely available government, vendor and vendor-research reporting. A source problem is shown here instead of silently hiding stale data.
Last successful collection 21 Aug 2026 · 16:33 UTC
Last successful collection 21 Aug 2026 · 16:33 UTC
Last successful collection 21 Aug 2026 · 16:33 UTC
Last successful collection 21 Aug 2026 · 16:33 UTC
Last successful collection 21 Aug 2026 · 16:33 UTC
Last successful collection 21 Aug 2026 · 16:33 UTC
Last successful collection 21 Aug 2026 · 16:33 UTC
Last successful collection 21 Aug 2026 · 16:33 UTC
Last successful collection 21 Aug 2026 · 16:33 UTC
Last successful collection 21 Aug 2026 · 16:33 UTC
Last successful collection 21 Aug 2026 · 16:33 UTC
Last successful collection 21 Aug 2026 · 16:33 UTC