Feed

Intelligence

Every strategic, operational and tactical item in one feed. Switch tiers or jump to a supporting section above.

Published source analytics

Intelligence activity

0 sourced events · Jul 23–Sep 21, 2026

No new activity in this window. The previous equal window also contains no sourced events.
critical
0
high
0
medium
0
low
0

Activity timeline

Daily published events stacked by severity

DateTotalCriticalHighMediumLow
2026-07-2300000
2026-07-2400000
2026-07-2500000
2026-07-2600000
2026-07-2700000
2026-07-2800000
2026-07-2900000
2026-07-3000000
2026-07-3100000
2026-08-0100000
2026-08-0200000
2026-08-0300000
2026-08-0400000
2026-08-0500000
2026-08-0600000
2026-08-0700000
2026-08-0800000
2026-08-0900000
2026-08-1000000
2026-08-1100000
2026-08-1200000
2026-08-1300000
2026-08-1400000
2026-08-1500000
2026-08-1600000
2026-08-1700000
2026-08-1800000
2026-08-1900000
2026-08-2000000
2026-08-2100000
2026-08-2200000
2026-08-2300000
2026-08-2400000
2026-08-2500000
2026-08-2600000
2026-08-2700000
2026-08-2800000
2026-08-2900000
2026-08-3000000
2026-08-3100000
2026-09-0100000
2026-09-0200000
2026-09-0300000
2026-09-0400000
2026-09-0500000
2026-09-0600000
2026-09-0700000
2026-09-0800000
2026-09-0900000
2026-09-1000000
2026-09-1100000
2026-09-1200000
2026-09-1300000
2026-09-1400000
2026-09-1500000
2026-09-1600000
2026-09-1700000
2026-09-1800000
2026-09-1900000
2026-09-2000000
2026-09-2100000

Actor by domain

Event volume by attributed actor track and target domain

PRC
Russia
Iran
DPRK
Cross actor
LowHigh
ActorDomainEvents

Actor activity

Daily counts with a shared scale and fixed actor colors

ActorDateEvents

Top targeted sectors

Ten largest target groups, with remaining groups folded into Other

SectorEvents

Source transparency

Published items by named source

SourceEvents

Hotspots

Current volume and seven-day sourced trend

HotspotEvents

Exploited CVEs

Vulnerabilities named in published reporting

No CVEs were named in sourced reporting for this window.

PRIVSEC·Vulnerabilities & CVEs·highCONF 61
USmedium · 45CISA

Cybersecurity and Infrastructure Security Agency confirms exploitation of Oracle E-Business Suite CVE-2025-61884

Bottom line: the flaw was added to the Known Exploited Vulnerabilities catalog after confirmed in-the-wild abuse following the earlier zero-day campaign. Treat catalog additions as a patch deadline, not a notification.

Automated analysis from cited open sources.

Private SectorOct 21, 2025BleepingComputer (opens in new tab) Details
#Known Exploited Vulnerabilities#CVE-2025-61884#Oracle
PRIVSEC·Industry & Vendors·highCONF 57

SecurityWeek: Oracle E-Business Suite flaw exploited across dozens of customer environments

Bottom line: a cluster associated with FIN11 conducted mass data theft from Oracle E-Business Suite instances before extorting victims. Inventory internet-reachable enterprise resource planning endpoints and log their outbound data volume.

Automated analysis from cited open sources.

Private SectorOct 21, 2025SecurityWeek (opens in new tab) Details
#FIN11#Data theft#Enterprise resource planning
US-FED·Cyber Policy & Strategy·criticalCONF 57
USmedium · 40CISAUS (general)

Emergency Directive 26-01 orders federal agencies to mitigate F5 device exposure

Bottom line: the Cybersecurity and Infrastructure Security Agency directed civilian agencies to inventory F5 BIG-IP products, remove public management interfaces and patch, citing a nation-state actor with immediate access risk. Emergency directives remain the fastest lever the executive branch has over federal networks.

Automated analysis from cited open sources.

Federal Civilian GovernmentOct 15, 2025CISA Emergency Directive ED 26-01 (opens in new tab) Details
#Emergency directive#F5 BIG-IP#Federal networks
US-FED·Cyber Policy & Strategy·criticalCONF 57
USmedium · 43CISAUS (general)

Cybersecurity and Infrastructure Security Agency directs agencies to act on F5 vulnerabilities

Bottom line: agencies were told to identify F5 BIG-IP assets, restrict management interfaces and apply the vendor's releases on a compressed timeline. Verify exposure of every appliance management plane, not only the patch level.

Automated analysis from cited open sources.

Federal Civilian GovernmentOct 15, 2025CISA alert (opens in new tab) Details
#F5 BIG-IP#Federal Civilian Executive Branch#Patch deadline
US-FED·Defensive Operations·criticalCONF 78
USlow · 10US (general)

F5 discloses nation-state intrusion into product development and engineering systems

Bottom line: F5 disclosed long-term access by a nation-state actor to systems holding BIG-IP source code and undisclosed vulnerability information, and United States officials warned of risk to federal networks. Vendor build environments are now part of every agency's threat model.

Automated analysis from cited open sources.

Federal Civilian GovernmentOct 15, 2025Reuters (opens in new tab) Details
#F5#Supply chain#Nation state

AI Daily Briefing

ICD 203 · Briefing for today

Automated analysis, generated from cited open sources using a methodology designed by a United States Intelligence Community veteran.

PRIVSEC·Incidents & Breaches·criticalCONF 57

Google Threat Intelligence Group and Mandiant document Oracle E-Business Suite zero-day extortion

Bottom line: an extortion campaign linked to the CL0P ecosystem exploited an Oracle E-Business Suite zero-day for mass data theft across dozens of customers. Enterprise resource planning platforms are now a primary mass-exploitation target, not a back-office concern.

Automated analysis from cited open sources.

#CL0P#Oracle E-Business Suite#Extortion
CI-ENERGY·Critical Infrastructure·highCONF 57

Joint advisory on the People's Republic of China espionage system names transportation and military infrastructure

Bottom line: the advisory's technical annex covers router configuration abuse, tunneling and long-dwell access on provider infrastructure serving energy and transport customers. Compare running configurations against known-good baselines on every internet-facing router.

Automated analysis from cited open sources.

#Router configuration#Tunneling#Persistence
ADV-CN·Threat Intelligence·criticalCONF 57
UShigh · 83CISANSA / CYBERCOMFBI / DOJUS (general)

Joint advisory AA25-239A: Chinese state actors compromise global networks to feed an espionage system

Bottom line: the Cybersecurity and Infrastructure Security Agency, National Security Agency, Federal Bureau of Investigation and international partners describe People's Republic of China actors sitting on backbone routers of telecommunications, government, transportation, lodging and military networks. Treat edge routing infrastructure as the primary hunt surface.

Automated analysis from cited open sources.

#Salt Typhoon#Joint advisory#Telecommunications
PRIVSEC·Vulnerabilities & CVEs·criticalCONF 78

Microsoft attributes on-premises SharePoint exploitation to Chinese state actors

Bottom line: Microsoft tied active exploitation of on-premises SharePoint flaws to Linen Typhoon, Violet Typhoon and Storm-2603, with post-exploitation key theft enabling persistent access. Rotate machine keys after patching, because patching alone does not evict the actor.

Automated analysis from cited open sources.

#SharePoint#Linen Typhoon#Storm-2603
ADV-CN·Threat Intelligence·mediumCONF 78

CyberScoop: twelve Chinese nationals indicted over a hacker-for-hire espionage spree

Bottom line: the unsealed cases describe a contracting ecosystem selling stolen data to Chinese security services. Expect commercial intermediaries, not uniformed units alone, in future attribution.

Automated analysis from cited open sources.

Adversary: China (PRC)Mar 5, 2025CyberScoop (opens in new tab) Details
#Hacker for hire#Attribution#Ministry of Public Security
US-FED·Legislation & Oversight·highCONF 57
USlow · 8US (general)

Justice Department charges twelve Chinese contract hackers and law enforcement officers

Bottom line: unsealed indictments name contract operators and Ministry of Public Security officers running intrusions for hire against dissidents, agencies and news organizations. The hacker-for-hire market is now treated as state apparatus in United States charging policy.

Automated analysis from cited open sources.

Federal Civilian GovernmentMar 5, 2025US Department of Justice (opens in new tab) Details
#Indictment#i-Soon#Contract hackers
CI-COMMS·Incidents & Breaches·highCONF 61
USlow · 11US (general)

Chinese operators breach additional United States telecom networks through unpatched Cisco routers

Bottom line: reporting on the Insikt Group findings identified further carrier compromises through Cisco devices left unpatched for over a year. Asset inventory gaps on network gear, not novel exploits, are carrying this campaign.

Automated analysis from cited open sources.

Critical Infra: CommunicationsFeb 14, 2025BleepingComputer (opens in new tab) Details
#Salt Typhoon#Cisco#Carriers
CI-COMMS·Threat Intelligence·highCONF 57
USlow · 33Treasury / OFACUS (general)

Recorded Future Insikt Group: RedMike (Salt Typhoon) exploits unpatched Cisco devices at telecom providers

Bottom line: between December 2024 and January 2025 Insikt Group observed continued exploitation of known Cisco IOS XE flaws against telecommunications providers, including United States affiliates. Sanctions did not change the operational tempo, so patching edge devices is the only working control.

Automated analysis from cited open sources.

Critical Infra: CommunicationsFeb 13, 2025Recorded Future Insikt Group (opens in new tab) Details
#RedMike#Cisco IOS XE#Insikt Group
ADV-CN·Threat Intelligence·mediumCONF 57
USmedium · 40Treasury / OFAC

WIRED: Salt Typhoon keeps hacking telecoms despite sanctions

Bottom line: public reporting confirmed the group continued operations through the sanctions and indictment cycle. Assume designation has deterrence value for financiers, not for the operators themselves.

Automated analysis from cited open sources.

Adversary: China (PRC)Feb 13, 2025WIRED (opens in new tab) Details
#Salt Typhoon#Deterrence#Open source reporting
ADV-CN·Cyber Diplomacy & Norms·highCONF 57
USmedium · 48Treasury / OFACUS (general)

Associated Press: Treasury sanctions follow the telecom hack and the breach of its own network

Bottom line: the designations covered both the carrier campaign and an intrusion into Treasury systems through a third-party support provider. Third-party remote support tooling remains an unresolved federal exposure.

Automated analysis from cited open sources.

Adversary: China (PRC)Jan 17, 2025Associated Press (opens in new tab) Details
#Treasury#Third party access#Sanctions
ADV-CN·Cyber Diplomacy & Norms·highCONF 57
USmedium · 50Treasury / OFAC

Treasury sanctions Sichuan Juxinhe Network Technology over Salt Typhoon telecom intrusions

Bottom line: the Office of Foreign Assets Control designated a Sichuan firm tied to the telecommunications campaign and an actor linked to the Treasury network compromise. Expect sanctions to keep running ahead of, not after, technical remediation.

Automated analysis from cited open sources.

Adversary: China (PRC)Jan 17, 2025US Department of the Treasury (opens in new tab) Details
#OFAC#Sanctions#Salt Typhoon
CI-COMMS·Cyber Diplomacy & Norms·criticalCONF 57
UShigh · 81CISAFBI / DOJUS (general)

Joint Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency statement on telecom targeting

Bottom line: the two agencies publicly confirmed a broad People's Republic of China espionage campaign inside multiple telecommunications carriers, including call records and lawful intercept systems. It set the baseline for every later Salt Typhoon action.

Automated analysis from cited open sources.

Critical Infra: CommunicationsNov 13, 2024FBI / CISA joint statement (opens in new tab) Details
#Salt Typhoon#Lawful intercept#Carriers
ALLIES·Defensive Operations·mediumCONF 57
USlow · 8US (general)

Canadian Centre for Cyber Security bulletin on People's Republic of China targeting of telecom operators

Bottom line: an allied agency independently confirmed the same telecommunications espionage pattern against its own carriers. Coordinated allied bulletins raise the confidence level attached to the United States assessment.

Automated analysis from cited open sources.

Allied & Partner NationsOct 21, 2024Canadian Centre for Cyber Security (opens in new tab) Details
#Five Eyes#Telecommunications#Allied reporting
DOD·Offensive Operations·highCONF 57
USmedium · 35FBI / DOJUS (general)

Court-authorized operation disrupts the Raptor Train botnet used by People's Republic of China actors

Bottom line: the Federal Bureau of Investigation removed malware from roughly 260,000 consumer routers, cameras and storage devices used as attack relay infrastructure by Flax Typhoon. Consumer devices inside United States address space are strategic terrain and are being cleaned by court order.

Automated analysis from cited open sources.

Defense / MilitarySep 18, 2024US Department of Justice (opens in new tab) Details
#Flax Typhoon#Botnet takedown#Raptor Train
CRIME·Incidents & Breaches·highCONF 57
USlow · 8US (general)

Operation Cronos seizes LockBit infrastructure and publishes affiliate detail

Bottom line: international law enforcement took the leak site, recovered decryption keys and exposed the affiliate structure of the most active ransomware brand. Infrastructure seizure combined with public exposure now precedes arrests in United States practice.

Automated analysis from cited open sources.

Cybercrime / RansomwareFeb 20, 2024US Department of Justice (opens in new tab) Details
#LockBit#Operation Cronos#Ransomware
CI-WATER·Critical Infrastructure·criticalCONF 57
USlow · 11US (general)

Advisory AA24-038A: Volt Typhoon pre-positioning inside United States critical infrastructure

Bottom line: authoring agencies assessed that Chinese state actors are pre-positioned on communications, energy, transportation and water networks to enable disruption, not espionage. Hunt for living-off-the-land activity on edge appliances rather than waiting on malware signatures.

Automated analysis from cited open sources.

#Volt Typhoon#Living off the land#Pre-positioning
ADV-IR·Threat Intelligence·highCONF 57

Advisory AA23-335A: CyberAv3ngers exploit Unitronics controllers at water utilities

Bottom line: Iranian Government Islamic Revolutionary Guard Corps affiliated actors defaced and disrupted programmable logic controllers at small water systems using default credentials on internet-exposed devices. Change default passwords and remove operational technology from the public internet as the first control.

Automated analysis from cited open sources.

#CyberAv3ngers#Unitronics#Water sector