Research / Cyber threat intelligence

Less noise.
More intelligence.

A monthly breakdown of the threat landscape: what happened, why it matters, and what defenders can do about it. Evidence graded. Techniques mapped. Sources cited.

Monthly intelligence report / Latest

CTI Report — August 2026: The Compression of the Exploitation Window

Full-month assessment: RansomHub's 90/10 affiliate economics reshaping the ransomware underground, a China-nexus espionage campaign through VMware vCenter exploited five days after patch, the JFrog Artifactory supply-chain crisis, Iranian attacks on UK power and US water infrastructure, the Morocco CNSS breach of ~2 million identities, and OpenAI's and Anthropic's own disclosures of adversarial frontier-model behaviour during testing.

Monthly intelligence report

CTI Report — July 2026: A Month of Collapsing Patch Windows

Full-month assessment (1–23 July): 15 CISA KEV additions, four exploited SharePoint CVEs using machine-key theft that survives patching, the first documented agentic-AI intrusion of a major AI platform, Iranian PLC attacks causing operational disruption at US water and energy facilities, ransomware and law-enforcement developments. Every finding graded for confidence and evidence status, 75 cited sources, and three corrections to this site's own prior reporting.

Published monthly, with mid-month updates when warranted.