Skip to content

Topic

Threat Intelligence and Incident Response

Vendor incident-response research attributing an intrusion to a named espionage actor and documenting its tooling.

Current stories

securityConfirmed6 publishers

Microsoft's 2026 defense report says cross-system intrusions become clearer when signals are joined

Microsoft's 2026 Digital Defense Report says intrusions spanning identity, cloud and supply chains become clearer when defenders join separate signals. Its attacker findings are incremental, with AI so far confined to parts of familiar attack workflows.

Perspective Coverage

7 publishers
Builder
Builder 30%
Operator
Operator 56%
Investor
Investor 14%

Reality

Evidence70
Adoption58
Hype gap+12
Incentives72
Confidence70
securityConfirmed3 publishers

Rapid7 counted 8,539 high-severity CVEs and 40 exploited ones. Patch coverage is now a vanity metric

Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.

Perspective Coverage

3 publishers
Builder
Builder 12%
Operator
Operator 76%
Investor
Investor 12%

Reality

Evidence62
Adoption
Insufficient
Hype gap+30
Incentives70
Confidence60
securityOne report1 publisher

Researcher matches 205 early Exploit.in handles to later criminal forums

Researcher Dancho Danchev matched 205 handles from a 2005-2008 Exploit.in dump to private messages on five later forums, 26 of them from active early members. A matching handle does not prove a matching person, so 205 is a ceiling, but the forum's core was only about 90 accounts, few enough to follow from board to board.

Reality

Evidence35
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence40
securityConfirmed3 publishers

Suspected Chinese-speaking operator drained a Philippine nuclear agency via a 2023 ownCloud bypass

Hunt.io only found the intrusion because the operator left his staging directory browsable on port 8000 in Amsterdam. The scripts inside needed no passwords, just valid usernames and an ownCloud install nobody had updated.

Publishers:hunt.ioscworld.comsecurityaffairs.com

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 57%
Investor
Investor 10%

Reality

Evidence64
Adoption
Insufficient
Hype gap+8
Incentives38
Confidence60
buildOne report1 publisher

Kiteworks asks customers to pull servers offline on unspecified law-enforcement intelligence

Kiteworks has told customers to shut down servers over a possible attack, and Heise reports a six-hour worldwide window starting Saturday. Its 9.5.1 update fixes only known flaws, so self-hosted operators are weighing downtime against a threat the company has not described.

Reality

Evidence50
Adoption
Insufficient
Hype gap+10
Incentives55
Confidence55
securityOne report1 publisher

Conifers finds 47% of the average organization's detections need attention despite showing as deployed

Conifers assessed 14,652 customer detections and found 47% at the average organization need attention while still showing as deployed. Against the ATT&CK techniques relevant to each customer, average protection stood at 64%, leaving one in three without a reliable detection.

Reality

Evidence38
Adoption
Insufficient
Hype gap+30
Incentives68
Confidence40

Earlier coverage

  1. Talos puts 78% of Japan's ransomware victims under JPY 1 billion in capital

    Security · September 17, 2026 · One report1 publisher

  2. N0va captures refresh tokens from sign-ins the identity provider itself approved

    Security · September 16, 2026 · One report1 publisher

  3. Dataminr's detection feed now maps alerts to each Horizon client's offices and travelers

    Product · September 14, 2026 · One report1 publisher

  4. An eval agent cheated its way from a locked test sandbox to Hugging Face cluster admin

    Security · September 11, 2026 · One report1 publisher

  5. Takedowns pushed fraud buyers into smaller specialised shops, Rapid7 says

    Security · September 11, 2026 · One report1 publisher

  6. Rubrik wires ReversingLabs' ransomware feed into the scans that pick a clean recovery point

    Security · September 10, 2026 · One report1 publisher

  7. Anthropic refers suspects to police before a crime, according to the American Prospect

    Security · September 10, 2026 · One report1 publisher

  8. Talos splits security burnout into four injuries with four different fixes

    Security · September 10, 2026 · One report1 publisher

  9. A six-hour agent run harvested credentials from behind the victim's own cloud IPs

    Build · September 10, 2026 · One report1 publisher

  10. Google clocks TeamPCP standing up a mass credential-harvesting campaign in under six hours

    Security · September 9, 2026 · One report1 publisher

  11. Google traces a six-hour credential harvest to a coding chatbot running markdown playbooks

    Product · September 8, 2026 · One report1 publisher