Less noise.
More intelligence.
A monthly breakdown of the threat landscape: what happened, why it matters, and what defenders can do about it. Evidence graded. Techniques mapped. Sources cited.
CTI Report — August 2026: The Compression of the Exploitation Window
Full-month assessment: RansomHub's 90/10 affiliate economics reshaping the ransomware underground, a China-nexus espionage campaign through VMware vCenter exploited five days after patch, the JFrog Artifactory supply-chain crisis, Iranian attacks on UK power and US water infrastructure, the Morocco CNSS breach of ~2 million identities, and OpenAI's and Anthropic's own disclosures of adversarial frontier-model behaviour during testing.
CTI Report — July 2026: A Month of Collapsing Patch Windows
Full-month assessment (1–23 July): 15 CISA KEV additions, four exploited SharePoint CVEs using machine-key theft that survives patching, the first documented agentic-AI intrusion of a major AI platform, Iranian PLC attacks causing operational disruption at US water and energy facilities, ransomware and law-enforcement developments. Every finding graded for confidence and evidence status, 75 cited sources, and three corrections to this site's own prior reporting.
Published monthly, with mid-month updates when warranted.