Skip to content
Weekly · Threat Report · LiveRSS

Weekly Threat Report

CISA Known Exploited Vulnerabilities added in the last 7 days — fetched live from the CISA KEV feed — plus periodically-curated threat actor and ransomware reference notes below.

Report period: 17 Sept – 24 Sept 2026

CISA KEV Additions This Week

⟳ Loading KEV feed…

Standing: Ransomware Watch

Periodically-curated reference, not auto-updated — see the Ransomware Tracker for live group/victim data.

  • ·LockBit — residual affiliate activity post-Cronos takedown; renewed Asia-Pacific targeting observed Sep 2026
  • ·RansomHub — among the most active groups since ALPHV/BlackCat's 2024 exit; India manufacturing sector in scope
  • ·0APT — extorted Krybit (India) with doxxing threat Apr 2026; watching Indian MSPs and IT services firms
  • ·AI-assisted operators — Sep 2026: LLM-driven intrusion completed full enterprise breach in under 10 hours (The Register)

Standing: Threat Actor Activity

Periodically-curated reference, not auto-updated — see the Threat Actor Profiles for full dossiers.

  • ·APT36 (Transparent Tribe) — Operation RapidRust: Rust-based RUSTYSHADE backdoor + removable-media propagation vs India/Afghanistan govt and defense (observed Aug 2026)
  • ·APT29 (Midnight Blizzard) — ongoing cloud identity attacks; MFA fatigue campaigns
  • ·APT28 — credential harvesting against NATO defence/government targets
  • ·Lazarus Group — active crypto theft campaigns; targeting DeFi protocols

Patch Tuesday Tracker

Next Patch Tuesday: 2nd Tuesday of each month. Major vendors:

Microsoft2nd Tuesday
AdobePatch Tuesday
CiscoAd-hoc
FortinetQuarterly
Palo AltoAd-hoc
VMwareAd-hoc