Weekly · Threat Report · Live RSS
Weekly Threat Report
CISA Known Exploited Vulnerabilities added in the last 7 days — fetched live from the CISA KEV feed — plus periodically-curated threat actor and ransomware reference notes below.
Report period: 17 Sept – 24 Sept 2026
CISA KEV Additions This Week
⟳ Loading KEV feed…
Standing: Ransomware Watch
Periodically-curated reference, not auto-updated — see the Ransomware Tracker for live group/victim data.
- ·LockBit — residual affiliate activity post-Cronos takedown; renewed Asia-Pacific targeting observed Sep 2026
- ·RansomHub — among the most active groups since ALPHV/BlackCat's 2024 exit; India manufacturing sector in scope
- ·0APT — extorted Krybit (India) with doxxing threat Apr 2026; watching Indian MSPs and IT services firms
- ·AI-assisted operators — Sep 2026: LLM-driven intrusion completed full enterprise breach in under 10 hours (The Register)
Standing: Threat Actor Activity
Periodically-curated reference, not auto-updated — see the Threat Actor Profiles for full dossiers.
- ·APT36 (Transparent Tribe) — Operation RapidRust: Rust-based RUSTYSHADE backdoor + removable-media propagation vs India/Afghanistan govt and defense (observed Aug 2026)
- ·APT29 (Midnight Blizzard) — ongoing cloud identity attacks; MFA fatigue campaigns
- ·APT28 — credential harvesting against NATO defence/government targets
- ·Lazarus Group — active crypto theft campaigns; targeting DeFi protocols
Patch Tuesday Tracker
Next Patch Tuesday: 2nd Tuesday of each month. Major vendors:
Microsoft2nd Tuesday
AdobePatch Tuesday
CiscoAd-hoc
FortinetQuarterly
Palo AltoAd-hoc
VMwareAd-hoc