Threat Briefs

Daily threat intelligence for detection engineers. CVEs, campaigns, TTPs, and detection coverage.

⚠️ These reports are AI-generated. Always validate findings.

Cyber Threat Brief — March 3, 2026

Tuesday, March 3, 2026

New Metasploit modules for GL.iNet router brute-force+RCE and Barracuda ESG XLS RCE, a macOS infostealer tradecraft bundle with concrete C2/contact endpoints, and a new Nuclei template capturing an EKC Tournament Manager WordPress traversal pattern.

Cyber Threat Brief — February 28, 2026

Saturday, February 28, 2026

APT37's Ruby Jumper air-gap bridging toolkit, new Prosperous Werewolf (Trinper/LeetAgent) YARA artifacts, and an MCP indirect prompt injection PoC enabling unauthorized filesystem access.

Cyber Threat Brief - February 27, 2026

Friday, February 27, 2026

Daily threat intelligence for detection engineers: ICS/HVAC vulnerabilities, gaming trojan campaign, OpenClaw security bypass

Cyber Threat Brief — February 26, 2026

Thursday, February 26, 2026

Cisco SD-WAN CVSS 10.0 zero-day exploited since 2023 gets CISA Emergency Directive; Google/Mandiant disrupt Chinese APT using Google Sheets as C2; Steaelite RAT unifies double extortion in one panel; Windows CLFS PoC drops.

Cyber Threat Brief — February 25, 2026

Wednesday, February 25, 2026

FileZen KEV exploitation, SolarWinds Serv-U 4-CVE RCE cluster, Lazarus/Medusa healthcare extortion, VMware Aria Operations RCE, and the IBM X-Force + Sophos intelligence drops.

Cyber Threat Brief — February 24, 2026

Tuesday, February 24, 2026

CrowdStrike GTR 2026, ClickFix + Matanbuchus 3.0 + AstarionRAT pre-ransomware chain, Silver Fox/ValleyRAT via fake AV site, APT28 Operation MacroMaze, seven MCP server RCEs, Dragos OT 2026 report, and Apache ActiveMQ → LockBit intrusion analysis.

Cyber Threat Brief — February 23, 2026

Monday, February 23, 2026

SANDWORM_MODE npm supply chain worm poisons AI coding assistants; MuddyWater launches Operation Olalampo with new Rust backdoor; SolarWinds Web Help Desk RCE hits CISA KEV.

Cyber Threat Brief — February 22, 2026

Sunday, February 22, 2026

AI-augmented FortiGate campaign, Sentry SAML zero-day, Phobos affiliate arrest, USB air-gap cryptominer, and D-Link RCE cluster with public exploits.

Cyber Threat Brief — February 21, 2026

Saturday, February 21, 2026

CISA adds two actively exploited Roundcube webmail vulnerabilities to KEV catalog, including a 10-year-old deserialization RCE weaponized within 48 hours and an SVG-based XSS flaw.

Cyber Threat Brief — February 20, 2026

Friday, February 20, 2026

BeyondTrust exploitation update with VShell/SparkRAT, VS Code extension vulnerabilities affecting 128M downloads, Cline AI supply chain attack, Remcos RAT real-time surveillance, and ClearFake/PS1Bot detection opportunities.

Cyber Threat Brief — February 19, 2026

Thursday, February 19, 2026

VoIP RCE with Metasploit exploit, Dell RecoverPoint zero-day exploited by China-nexus UNC6201, Keenadu Android supply chain backdoor, CRESCENTHARVEST Iranian espionage, and DPRK MetaMask wallet tampering.

Threat Brief - 2026-02-18

Wednesday, February 18, 2026

Dell RecoverPoint zero-day exploited since 2024, CISA adds 4 KEVs, AI assistants weaponized as C2 proxies, Ivanti EPMM exploitation expands

Threat Brief - 2026-02-17

Tuesday, February 17, 2026

BridgePay ransomware disrupts US municipalities, Odido breach exposes 6.2M, Phobos ransomware arrest in Poland

Threat Brief - 2026-02-16

Monday, February 16, 2026

Chrome zero-day under active exploitation, infostealers now targeting AI agent configurations, and malware campaigns weaponizing Google Groups

Threat Brief - 2026-02-15

Sunday, February 15, 2026

DNS-based ClickFix delivers stealers via nslookup; CANFAIL malware targets Ukraine; macOS MacSync stealer via Claude artifacts

Threat Brief - 2026-02-14

Saturday, February 14, 2026

BeyondTrust post-exploitation TTPs revealed; Microsoft patches 6 zero-days; Ivanti EPMM under attack; Lazarus poisons npm/PyPI; AgreeToSteal Outlook add-in

Threat Brief - 2026-02-13

Friday, February 13, 2026

BeyondTrust pre-auth RCE with public PoC, Notepad++ supply chain, Windows Notepad markdown RCE, Warlock ransomware via SmarterMail, Apple dyld zero-day.

17 briefs total