Tag: weekly threat advisory
Weekly Threat Advisory: 50 Concurrent Ransomware Operators + 5 Dominant C2 Cluster + 11 APT Clusters (Aug 17-23, 2026)
Fifty concurrent ransomware operators across thirty-six MITRE ATT&CK techniques. Five dominant C2 operators producing 1,104 IOCs. 3,668 high-confidence indicators. 117 tracked clusters. 61 distinct TTPs. Two extremes on the same week — fragmentation versus concentration.
Weekly Threat Advisory: Drive-By Doubles + Phishing-Framework Surge + DPRK APT Triple-Track (Aug 10-16, 2026)
3,269 unique high-confidence indicators across 118 tracked clusters this cycle. Dominant signals: the drive-by fake-update domain wave scaled 2.5x from the prior week (906 attacker domains), a massive new phishing-framework infrastructure surge, three concurrent DPRK-linked APT clusters active, and a coordinated 737-extension browser abuse campaign. Full ATT&CK-per-tactic pressure roll-up, four production-ready Sigma rules, top IOCs per type, adversary analytics with platform screenshots.
Weekly Threat Advisory: Drive-By Domain Surge + 9 Concurrent Ransomware Operators (Aug 3-9, 2026)
1,827 unique high-confidence indicators across 102 tracked clusters this cycle. Dominant signal: a drive-by fake-update domain wave producing 371 attacker-registered domains from a single campaign. Nine ransomware operators active concurrently. Info-stealer and credential-drainer surge across Windows and macOS. Third consecutive week of macOS multi-family activity. Continued supply-chain wave targeting the developer ecosystem. Attributed APT clusters concurrent. Full ATT&CK-per-tactic pressure roll-up, four production-ready Sigma rules, top IOCs per type.
Weekly Threat Advisory: Framework-C2 Surge + Emerging Supply-Chain Wave (Jul 27 – Aug 2, 2026)
54,763 unique indicators across 107 tracked clusters this cycle. Dominant signal: framework-C2 infrastructure surge with 25+ concentrated /24 subnet anchors. Emerging supply-chain wave — fake npm packages, fake installers, developer-ecosystem targeting. macOS malware surge across three concurrent families. Three ransomware operators active. Iranian-linked APT clusters continue. Full ATT&CK-per-tactic pressure roll-up, four production-ready Sigma rules, subnet anchors, top IOCs per type.
Weekly Threat Advisory: Top Cyber Adversaries May 24 – 31, 2026
Weekly Threat Advisory · May 24 – 31, 2026 · 1.35M observations · 87 adversary clusters · CobaltStrike dominant · DPRK-linked activity (Kimsuky, Void Dokkaebi) · Cloud Atlas · AdaptixC2 / VShell emerging C2 frameworks · MITRE T1190 / T1105 / T1041 / T1082 pressure.









