AI Threat Intelligence

Threat intelligence, automated.

AI-researched threat write-ups, live IOC feeds, and MITRE ATT&CK mappings — human-reviewed before every publish. Built for defenders.

Threats tracked—
IOCs published—
MITRE techniques—
Last updated—
Latest Report
HIGHransomware

Keio Corporation Confirms Ransomware Attack Disrupting Business Systems

Keio Corporation, a major Japanese private railway operator, has confirmed a ransomware attack that disrupted some of its business systems over the weekend. While public transportation services were not affected, the incident impacted internal administrative and operational support functions. Investigations are ongoing to determine the full scope and nature of the attack.

Read full report →
Recent Threats
HIGHvulnerability

TDengine Zero-Day Vulnerability: Single-Packet DoS

A high-severity zero-day vulnerability affects the TDengine time-series database, enabling an unauthenticated attacker to crash critical OT servers with a single malformed network packet. This Denial of Service (DoS) vulnerability poses a significant operational risk to industrial, IoT, energy, and automotive environments.

Read report →
HIGHmalware

NeedyMantis: Modular Post-Compromise Malware Framework

NeedyMantis is a modular post-compromise malware framework identified by Microsoft Threat Intelligence. It employs custom loaders, encrypted archives, and extensible components to maintain long-term access and facilitate follow-on operations in targeted intrusions.

Read report →
CRITICALvulnerability

NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772 Exploited In The Wild

Citrix NetScaler devices are currently targeted by active exploitation of two zero-day vulnerabilities, `CVE-2026-88771` and `CVE-2026-88772`. Unit 42 has confirmed these vulnerabilities are being actively exploited in the wild, posing an immediate threat to organizations utilizing affected NetScaler appliances.

Read report →
CRITICALapt

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

The JADEPUFFER threat actor, tracked by Microsoft as Storm-3168, has evolved its tradecraft to conduct destructive operations within Microsoft Azure environments. Attackers leveraged compromised service principals to delete Azure resources over an 18-hour period in early June 2026. This activity highlights a significant risk to cloud infrastructure integrity.

Read report →
CRITICALapt

Bitget Crypto Exchange Suffers $387.5M Breach, Linked to North Korean APT

Cryptocurrency exchange Bitget experienced a significant security breach attributed to suspected North Korean state-sponsored hackers, resulting in the theft of approximately $387.5 million in digital assets. The incident led to a temporary suspension of Bitcoin withdrawals, which have since been resumed. This event highlights the persistent threat posed by sophisticated APT groups targeting high-value financial platforms.

Read report →
MEDIUMvulnerability

Wireshark 4.6.9 Released: Multiple Vulnerabilities Addressed

Wireshark has released version 4.6.9, which includes fixes for 19 identified vulnerabilities and 16 bugs. Users are strongly advised to update to this version to mitigate potential security risks associated with these flaws. Specific details regarding the vulnerabilities were not provided in the immediate release announcement.

Read report →
INFOthreat

Cybersecurity Outlook 2027 Event Summary

This report summarizes the Dark Reading virtual event ‘Cybersecurity Outlook 2027,’ which focuses on anticipated trends and challenges in the cybersecurity landscape over the next five years. It provides a forward-looking perspective rather than detailing a specific, immediate threat.

Read report →
INFOvulnerability

Microsoft Security Updates: September 2026

Microsoft released its September 2026 security updates, focusing on enhancing enterprise security posture. Key improvements include capabilities for discovering and controlling local AI agents, extending Zero Trust principles to agent traffic, and strengthening foundational SOC operations.

Read report →

Transparently AI-authored

Every report on this site is researched and drafted by an AI agent, then reviewed and approved by a human analyst before publication. The Agent Logbook shows every step — sources consulted, enrichment calls, tokens used, and approval status — in real time.