Skip to main content
DFIRLab
ResearchUse CasesCompare
Intel BriefingsThreat Actors
IOC CheckFile AnalyzerPhishing CheckDomain LookupExposure ScannerPrivacy Check
Log → SplunkLog → Sentinel
WikiAbout
PlatformNew
DFIRLab

Security research, threat intelligence, and free DFIR tools.

Tools

Phishing CheckerExposure ScannerDomain LookupFile AnalyzerPrivacy CheckLog → SplunkLog → SentinelAPI Playground

Use Cases

SOC Phishing TriageIR IOC EnrichmentMSSP Exposure Monitoringn8n AutomationSee all use cases →

Compare

vs VirusTotalvs Shodanvs TheHiveSee all 8 →

Resources

DFIR WikiIntel BriefingsAboutPlatformAPI Docs

Legal

Privacy PolicyRSS FeedSitemap

© 2026 DFIR Lab. All rights reserved.

Intelligence Products

Threat Briefings

Curated intelligence distilled from RSS feeds, CVE databases, abuse.ch, and OSINT sources.

RSS Feed
20 reports
Latest Briefing
DailyJul 20 — Jul 21

Daily Threat Briefing — 2026-07-21

The 24-hour period from July 20-21, 2026 witnessed a significant surge in cyber threat activity across multiple vectors. Critical zero-day exploitation dominated the landscape, with SonicWall SMA1000 appliances compromised for weeks before disclosure and a WordPress vulnerability chain (CVE-2026-60137, CVE-2026-63030) being actively exploited within three days of public disclosure. The emergence of AI-targeted threats represents a paradigm shift, with JadePuffer deploying ransomware specifically designed to encrypt AI training datasets and model checkpoints, while Hugging Face disclosed a breach via autonomous AI agent compromise. Major enterprise victims include Estée Lauder (Oracle E-Business Suite breach), a $23.7M cryptocurrency theft from Ostium, and widespread ransomware campaigns targeting healthcare, manufacturing, and logistics organizations. Fourteen organizations appeared on ransomware leak sites during this period, with notable victims including Caterpillar Inc., Colliers Real Estate, Bath Fitter, and multiple healthcare facilities. The Anubis and Nova ransomware groups showed increased activity, while threat actors demonstrated sophisticated evasion techniques including Microsoft Graph abuse for C2 communications (HollowGraph malware) and AI sandbox escapes affecting Cursor, Codex, and Gemini CLI. Critical vulnerabilities in widely-deployed systems—including ServiceNow (CVE-2026-6875), FreeRDP, and multiple CRM platforms—are now being actively exploited in the wild. The infrastructure landscape saw over 1,000 domains seized by DOJ for illegal World Cup streaming, while 50+ malware distribution URLs were identified pushing Mozi botnet variants, ClearFake campaigns, and info-stealers. Organizations should prioritize patching SonicWall, ServiceNow, WordPress, and Oracle E-Business Suite systems immediately, implement enhanced monitoring for AI infrastructure compromise indicators, and review exposure to autonomous agent systems that may bypass traditional security controls.

44 findings
30 CVEs
50 IOCs
Read full briefing

Severity Breakdown

critical 7
high 26
medium 6

MITRE ATT&CK

T1190T1059T1078T1486T1204.002T1027
Weekly
Jul 13

Weekly Threat Briefing — 2026-07-13 to 2026-07-20

This week's threat landscape is marked by critical remote code execution vulnerabilities across widely deployed platforms, including WordPress Core 'wp2shell' flaws with public exploits, 7-Zip RCE vulnerabilities, and SonicWall SMA zero-days actively exploited by Inc Ransomware. CISA has mandated immediate patching of actively exploited Fortinet FortiSandbox vulnerabilities by government agencies. The period saw a surge in ACR Stealer campaigns targeting enterprise customers to harvest browser credentials and authentication tokens, while new macOS malware ClickLock employs process termination tactics to force password disclosure. Ransomware activity remains aggressive with 30 new victim postings across multiple groups including Qilin, Nova, and Doommageddon, targeting sectors from healthcare (Abbott Laboratories) to critical infrastructure (Colombian oil giant Ecopetrol, Indonesian maritime ministry). A massive credential exposure affects 23+ million Paidwork users. Notable infrastructure threats include sophisticated supply chain attacks abusing ViPNet software update mechanisms to target Russian government agencies, and North Korean threat actors deploying malware via fake coding interview processes using SVG steganography that evaded all antivirus detection. Emerging attack techniques include abuse of AI agent frameworks (Claude Chrome extension vulnerabilities, agentic AI security gaps), OpenSSL's HollowByte DoS flaw requiring only 11 bytes to trigger memory exhaustion, and a Windows LegacyHive zero-day granting admin privileges. Organizations should prioritize patching critical KEV entries, implement enhanced monitoring for ACR Stealer indicators, review AI agent security controls, and validate software supply chain integrity.

39 findings10 CVEs
T1486T1190T1059
Daily
Jul 19

Daily Threat Briefing — 2026-07-20

This briefing covers critical cybersecurity developments from July 19-20, 2026, highlighting significant supply chain compromise activity, healthcare sector targeting, and widespread ransomware operations. Most notably, advanced threat actors are exploiting the ViPNet software update mechanism to target Russian government agencies, representing a sophisticated supply chain attack vector. The healthcare sector faces particular pressure with medical giant Abbott Laboratories investigating two separate breach incidents claimed by threat actors ShinyHunters and ShadowByt3$. Ransomware activity remains elevated with 16 new victim organizations disclosed across multiple groups, including a high-profile attack on Colombian energy giant Ecopetrol ($33.1B revenue) by TheGentlemen group. Infrastructure indicators show active Mirai botnet campaigns and continued Mozi botnet activity targeting IoT devices across multiple architectures. Six high-severity vulnerabilities were published affecting various software platforms, while ClearFake malware distribution campaigns continue targeting both Windows and macOS users.

26 findings6 CVEs
T1486T1567T1190
Daily
Jul 18

Daily Threat Briefing — 2026-07-19

This 24-hour period (2026-07-18 to 2026-07-19) saw significant vulnerability disclosures across multiple enterprise platforms and a substantial surge in ransomware activity targeting diverse sectors. Critical remote code execution vulnerabilities were disclosed in VMware Avi Load Balancer (CVE-2026-47865, CVE-2026-47867) and Fastify HTTP Proxy (CVE-2026-16117), with CVSS scores ranging from 8.7 to 9.8. Multiple authentication bypass and privilege escalation flaws in VMware Avi Load Balancer pose serious risks to organizations using this load balancing solution. The malware landscape shows continued activity from established botnets including Mozi and Mirai, with 49 malicious URLs identified by abuse.ch. Microsoft issued warnings about a surge in ACR Stealer attacks targeting enterprise customers for credential theft. The ransomware ecosystem remains highly active with 21 new victim organizations posted across multiple leak sites, led by the Qilin group (11 victims) and IncRansom (9 victims). Sectors impacted include education, healthcare, logistics, manufacturing, and critical infrastructure. Immediate action is required for organizations using 7-Zip (update to 26.02), WordPress Core (wp2shell RCE patches), VMware Avi Load Balancer, and Fastify components. The 23andMe settlement ($18M) for failing to protect genetic data highlights ongoing regulatory and legal consequences for inadequate data protection practices.

27 findings28 CVEs
T1486T1567T1190
Daily
Jul 17

Daily Threat Briefing — 2026-07-18

The period from July 17-18, 2026 saw significant security developments across multiple threat vectors. Critical vulnerabilities dominated the landscape, with WordPress suffering two critical flaws (CVE-2026-60137 and CVE-2026-63030) enabling SQL injection and remote code execution. IBM's Langflow OSS platform emerged as a major concern with eight critical-to-high severity vulnerabilities including multiple RCE vectors and authentication bypasses. SonicWall SMA appliances were targeted by Inc Ransomware exploiting zero-day vulnerabilities for root-level access. A novel supply chain attack vector emerged with North Korean threat actors embedding malware in SVG images during fake developer job interviews, evading all antivirus detection. The OpenSSL HollowByte vulnerability demonstrates sophisticated DoS capabilities using minimal payloads. Ransomware groups remained highly active with 16 new victim disclosures, while botnet operators continued leveraging Mirai variants targeting IoT devices. Ernst & Young disclosed a third-party support system breach, and Abbott Laboratories is investigating dual cyber incidents involving unauthorized access and extortion claims.

36 findings31 CVEs
T1190T1059T1486
Archive (15)
Jul 16Daily

Daily Threat Briefing — 2026-07-17

38
Jul 15Daily

Daily Threat Briefing — 2026-07-16

33
Jul 14Daily

Daily Threat Briefing — 2026-07-15

44
Jul 13Daily

Daily Threat Briefing — 2026-07-14

36
Jul 6Weekly

Weekly Threat Briefing — 2026-07-06 to 2026-07-13

37
Jul 12Daily

Daily Threat Briefing — 2026-07-13

29
Jul 11Daily

Daily Threat Briefing — 2026-07-12

26
Jul 10Daily

Daily Threat Briefing — 2026-07-11

47
Jul 9Daily

Daily Threat Briefing — 2026-07-10

30
Jul 8Daily

Daily Threat Briefing — 2026-07-09

36

Get notified the moment it matters

Subscribe to threat-intel vulnerability alerts. Choose exactly what you care about — from actively-exploited CISA KEV entries to the full CVE firehose — and how often you want to hear about it.

Free foreverUnsubscribe anytimeNo spam, ever