Skip to content
Weekly Signal

Before the vulnerability record

Threat Activity

Track reported campaigns, active threat actors and targeted sectors, including activity described before a CVE is named.

Updated 21 Aug 2026 · 18:18 UTC

Signals become useful when evidence, behaviour and targets are connected.
Evidence, not prediction.

Pre-CVE means a trusted source has described malicious activity or a previously unknown weakness without naming a CVE. ATT&CK mappings marked Explicit were stated by the source. Inferred mappings are conservative interpretations of source wording and must be verified against the original report.

1Reports in 24 hours
0Pre-CVE reports · 7 days
30Named actors · 30 days
7Targeted sectors · 30 days
2ATT&CK-mapped reports · 7 days

Target-sector mentions · 30 days

Where reported activity is focused

Counts reflect explicit sector mentions in collected reports. One report may mention several sectors, so this is a comparison of evidence coverage rather than a share of all attacks.

Retail is included. A zero means no qualifying report in the current 30-day evidence window named the sector, not that retail faces no threat.

Emerging activity

0 of 0 reports shown

No matching activity

Try a wider reporting window or clear a filter. The feed fills after the first threat-feeds job runs.

Provenance and freshness

Source coverage

The dashboard currently uses freely available government, vendor and vendor-research reporting. A source problem is shown here instead of silently hiding stale data.

HEALTHY

UK NCSC

Last successful collection 21 Aug 2026 · 16:33 UTC

HEALTHY

SentinelLABS

Last successful collection 21 Aug 2026 · 16:33 UTC

HEALTHY

ESET Research

Last successful collection 21 Aug 2026 · 16:33 UTC

HEALTHY

Securelist

Last successful collection 21 Aug 2026 · 16:33 UTC