Severity: High CVSS: 8.8 CVE: CVE-2026-24301 Affected service: Microsoft Copilot Personal / Copilot Web Not...
Threat Advisories
THREAT ADVISORY AdaptixC2 emerges as alternative to Cobalt Strike August 24, 2026
Threat Level: High Category: Command & Control (C2) Framework / Post-Exploitation Platform Audience: SOC...
THREAT ADVISORY Stripe Merchant API Keys Exposed August 19, 2026
Executive Summary Multiple security researchers and news outlets have reported the public release of a dataset...
THREAT ADVISORY Russian APT “Laundry Bear” Exploiting OWA XSS for Persistent Mailbox Access August 5, 2026
Threat Actor: Laundry Bear (aka TA488, CL-STA-1114, UNK_PitStop, Void Blizzard) Vulnerability: CVE-2026-42897 (CVSS 8.1)...
THREAT ADVISORY Iranian-Affiliated Cyber Operations Targeting U.S. Water, Energy, and Critical Infrastructure Sectors July 27, 2026
Executive Summary U.S. federal agencies (FBI, CISA, NSA, DOE, EPA, Treasury, and U.S. Cyber Command) have issued...
THREAT ADVISORY MUNICIPAL ENERGY SECTOR June 8, 2026
Executive Summary Recent threat intelligence from late May and early June 2026 indicates a critical escalation in...
THREAT ADVISORY Palo Alto Firewall Zero-Day May 7, 2026
Background/Summary On May 6, 2026, Palo Alto Networks disclosed CVE-2026-0300, a critical buffer overflow vulnerability in...
THREAT ADVISORY Deep#Door Python-based Backdoor Framework May 7, 2026
Background/Summary DEEP#DOOR (also referred to as Deep#Door or DeepDoor), has been identified as a sophisticated, stealthy...
THREAT ADVISORY DigiCert Compromise (April 2026) May 7, 2026
Background/Summary In early April 2026, DigiCert, a major global Certificate Authority (CA), suffered a targeted social...
THREAT ADVISORY Identity-target Threat Identification and Mitigation (Bypassing MFA via Session Token Theft) May 2026
Severity: High Threat Actors: Cybercriminals, ransomware groups, nation-state actors, and initial access brokers using...