Threat Briefs
Daily threat intelligence for detection engineers. CVEs, campaigns, TTPs, and detection coverage.
⚠️ These reports are AI-generated. Always validate findings.
Cyber Threat Brief — March 3, 2026
Tuesday, March 3, 2026New Metasploit modules for GL.iNet router brute-force+RCE and Barracuda ESG XLS RCE, a macOS infostealer tradecraft bundle with concrete C2/contact endpoints, and a new Nuclei template capturing an EKC Tournament Manager WordPress traversal pattern.
Cyber Threat Brief — February 28, 2026
Saturday, February 28, 2026APT37's Ruby Jumper air-gap bridging toolkit, new Prosperous Werewolf (Trinper/LeetAgent) YARA artifacts, and an MCP indirect prompt injection PoC enabling unauthorized filesystem access.
Cyber Threat Brief - February 27, 2026
Friday, February 27, 2026Daily threat intelligence for detection engineers: ICS/HVAC vulnerabilities, gaming trojan campaign, OpenClaw security bypass
Cyber Threat Brief — February 26, 2026
Thursday, February 26, 2026Cisco SD-WAN CVSS 10.0 zero-day exploited since 2023 gets CISA Emergency Directive; Google/Mandiant disrupt Chinese APT using Google Sheets as C2; Steaelite RAT unifies double extortion in one panel; Windows CLFS PoC drops.
Cyber Threat Brief — February 25, 2026
Wednesday, February 25, 2026FileZen KEV exploitation, SolarWinds Serv-U 4-CVE RCE cluster, Lazarus/Medusa healthcare extortion, VMware Aria Operations RCE, and the IBM X-Force + Sophos intelligence drops.
Cyber Threat Brief — February 24, 2026
Tuesday, February 24, 2026CrowdStrike GTR 2026, ClickFix + Matanbuchus 3.0 + AstarionRAT pre-ransomware chain, Silver Fox/ValleyRAT via fake AV site, APT28 Operation MacroMaze, seven MCP server RCEs, Dragos OT 2026 report, and Apache ActiveMQ → LockBit intrusion analysis.
Cyber Threat Brief — February 23, 2026
Monday, February 23, 2026SANDWORM_MODE npm supply chain worm poisons AI coding assistants; MuddyWater launches Operation Olalampo with new Rust backdoor; SolarWinds Web Help Desk RCE hits CISA KEV.
Cyber Threat Brief — February 22, 2026
Sunday, February 22, 2026AI-augmented FortiGate campaign, Sentry SAML zero-day, Phobos affiliate arrest, USB air-gap cryptominer, and D-Link RCE cluster with public exploits.
Cyber Threat Brief — February 21, 2026
Saturday, February 21, 2026CISA adds two actively exploited Roundcube webmail vulnerabilities to KEV catalog, including a 10-year-old deserialization RCE weaponized within 48 hours and an SVG-based XSS flaw.
Cyber Threat Brief — February 20, 2026
Friday, February 20, 2026BeyondTrust exploitation update with VShell/SparkRAT, VS Code extension vulnerabilities affecting 128M downloads, Cline AI supply chain attack, Remcos RAT real-time surveillance, and ClearFake/PS1Bot detection opportunities.
Cyber Threat Brief — February 19, 2026
Thursday, February 19, 2026VoIP RCE with Metasploit exploit, Dell RecoverPoint zero-day exploited by China-nexus UNC6201, Keenadu Android supply chain backdoor, CRESCENTHARVEST Iranian espionage, and DPRK MetaMask wallet tampering.
Threat Brief - 2026-02-18
Wednesday, February 18, 2026Dell RecoverPoint zero-day exploited since 2024, CISA adds 4 KEVs, AI assistants weaponized as C2 proxies, Ivanti EPMM exploitation expands
Threat Brief - 2026-02-17
Tuesday, February 17, 2026BridgePay ransomware disrupts US municipalities, Odido breach exposes 6.2M, Phobos ransomware arrest in Poland
Threat Brief - 2026-02-16
Monday, February 16, 2026Chrome zero-day under active exploitation, infostealers now targeting AI agent configurations, and malware campaigns weaponizing Google Groups
Threat Brief - 2026-02-15
Sunday, February 15, 2026DNS-based ClickFix delivers stealers via nslookup; CANFAIL malware targets Ukraine; macOS MacSync stealer via Claude artifacts
Threat Brief - 2026-02-14
Saturday, February 14, 2026BeyondTrust post-exploitation TTPs revealed; Microsoft patches 6 zero-days; Ivanti EPMM under attack; Lazarus poisons npm/PyPI; AgreeToSteal Outlook add-in
Threat Brief - 2026-02-13
Friday, February 13, 2026BeyondTrust pre-auth RCE with public PoC, Notepad++ supply chain, Windows Notepad markdown RCE, Warlock ransomware via SmarterMail, Apple dyld zero-day.
17 briefs total