threat intel
The watch floor
Security signals ranked by what matters now, plus the latest reporting.
Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are clustered, de-duplicated, and tagged by category, vendor, and threat actor. Filter to your role, pin your stack, subscribe or point your reader at a feed. No account required.
Browse latest storiesSkip to latest storiesFilter by role (optional)View filtered stories
Trending, last 7 days
Most covered
Ranked by distinct source count; recency breaks ties.
- Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
- CISA Adds One Known Exploited Vulnerability to Catalog
- Iran-Linked Hackers Shut Down UK Power Plant for Four Days
- TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
- Lawmakers seek watchdog review of federal hacking of Americans
Common Vulnerabilities and Exposures (CVEs) gaining attention
- CVE-2026-60004Gitea Giteanew CISA KEV
- CVE-2019-1068Microsoft SQL Servernew CISA KEV
- CVE-2026-8452Citrix NetScaler ADC and NetScaler Gatewaynew CISA KEV
- CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-innew CISA KEV
- CVE-2026-73570Synacor Zimbra Collaboration Suite (ZCS)new CISA KEV
- CVE-2026-72530TrueConf Servernew CISA KEV
Latest stories, newest first
government policy
FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
Abnormal AI expands email security from detection to data protection and phishing-simulation training
AI will not fix a governance problem in your camera estate
The best human hacking team still out-solved the best AI team
vulnerabilitiesCVE-2026-8452
Recent Citrix NetScaler Vulnerability Exploited in the Wild
vulnerabilitiesCVE-2019-1068
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
government policy
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
government policy2 sources
Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit
threat intel
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
Red Flags That Expose Fake North Korean IT Workers
vulnerabilities
Critical Avada WordPress theme flaw enables zero-click RCE
Research
Democratizing FinOps with Wiz: Driving Cost Attribution with the Wiz Service Catalog
threat intelResearch
Adversary tradecraft 101: Hunting for persistence using Elastic Security (Part 2)
threat intelResearch
Hunting In Memory
threat intelResearch
Hunting For In-Memory .NET Attacks
ResearchCVE-2021-31207CVE-2021-34473
Detection and response for the actively exploited ProxyShell vulnerabilities
threat intelResearch
Collecting Cobalt Strike Beacons with the Elastic Stack
vulnerabilitiesResearchCVE-2022-30190
Vulnerability summary: Follina, CVE-2022-30190
Research
Elastic’s 2022 Global Threat Report: A roadmap for navigating today’s growing threatscape
No stories match your current filters. Reset search and filters to show all stories.
See the daily change brief for what changed since the previous snapshot. Looking further back? Browse the daily archive, this feed's own history.