Skip to content
Weekly Signal

Before the vulnerability record

Threat Activity

Track reported campaigns, active threat actors and targeted sectors, including activity described before a CVE is named.

Updated 20 Aug 2026 · 16:48 UTC

Evidence, not prediction.

Pre-CVE means a trusted source has described malicious activity or a previously unknown weakness without naming a CVE. ATT&CK mappings marked Explicit were stated by the source. Inferred mappings are conservative interpretations of source wording and must be verified against the original report.

5Reports in 24 hours
2Pre-CVE reports · 7 days
31Named actors · 30 days
8Targeted sectors · 30 days
9ATT&CK-mapped reports · 7 days

Emerging activity

1 of 1 reports shown

90Signal
PRE-CVEREPORTED ACTIVITYMALWAREFULL REPORT ANALYSED

Identity Abuse Through Trusted Communication Channels

Threat Research CenterThreat ResearchMalware Malware Identity Abuse Through Trusted Communication Channels 12 min read Related ProductsCortexCortex XDRCortex XSIAMIdiraUnit 42 Incident Response By:Bill Batchelor Published:August 20, 2026 Categories:MalwareThreat Research Tags:AuthenticationIdentity theftMalwareMFARemote access softwareSocial engineering Share Executive Summary Identity has…

Source
Palo Alto Networks Unit 42
Published
20 Aug 2026 · 10:00 UTC
Actor
APT29
Targets
Defence, Energy, Manufacturing, Europe, Middle East
Read source ↗

Provenance and freshness

Source coverage

The dashboard currently uses freely available government, vendor and vendor-research reporting. A source problem is shown here instead of silently hiding stale data.

HEALTHY

UK NCSC

Last successful collection 20 Aug 2026 · 15:32 UTC

HEALTHY

SentinelLABS

Last successful collection 20 Aug 2026 · 15:32 UTC

HEALTHY

ESET Research

Last successful collection 20 Aug 2026 · 15:32 UTC

HEALTHY

Securelist

Last successful collection 20 Aug 2026 · 15:32 UTC