Transport Threat Intelligence
Cyber threats facing aviation, rail, maritime logistics, freight, and transport infrastructure operators.
Flash Briefings
Active exploitation of CVE-2026-41089, a pre-authentication zero-click RCE in Windows Netlogon, was confirmed by Belgium's Centre for Cybersecurity on 29 May. Successful exploitation gives an attacker SYSTEM-level control of the domain controller and full ownership of the Active Directory domain.
A medium-severity authentication bypass in Palo Alto Networks PAN-OS GlobalProtect is being actively exploited across enterprise networks, with CISA's KEV remediation deadline falling on 1 June 2026.
Iranian IRGC-affiliated APT Nimbus Manticore has resumed aggressive campaigns against aviation, telecommunications, and critical infrastructure in Europe and the US, deploying an undocumented AI-assisted backdoor and adopting new delivery techniques since the outbreak of the US-Iran conflict.
Cl0p Exploiting File Transfer Vulnerabilities Across Transport and Logistics Sector
The Cl0p ransomware group is mass-exploiting a newly disclosed vulnerability in a widely used managed file transfer platform. Several European freight and logistics operators have been impacted, with customs and supply chain data exfiltrated.
Deep Analysis
Pioneer Kitten: How Iran's IRGC Became an Access Broker for Ransomware Gangs
Pioneer Kitten — tracked as Fox Kitten, Lemon Sandstorm, and UNC757 — is an Iranian state-sponsored group that exploits network perimeter devices to establish persistent access, then sells that access to criminal ransomware affiliates. This deep dive examines the group's dual mandate, tradecraft, and what a compromise looks like in practice.
Mustang Panda (Twill Typhoon): China's Most Prolific Espionage APT
Mustang Panda is one of the most operationally active Chinese APT groups, running continuous espionage operations since at least 2012. Known for PlugX, DLL sideloading, and a rapidly evolving implant arsenal, the group has compromised government ministries, NGOs, telecoms, and religious organisations across Southeast Asia, Europe, and beyond.
Silk Typhoon: China's IT Supply Chain Pivot and the Downstream Threat to Every Sector
Silk Typhoon — the Chinese state actor behind the 2021 Exchange ProxyLogon campaign and the 2024 US Treasury breach — has fundamentally changed how it operates. A deep dive into the group's shift to IT supply chain targeting and what it means for every organisation that relies on a managed service provider.
Sandworm: Inside Russia's Most Destructive Cyber Weapon
Sandworm -- GRU Unit 74455 -- is responsible for the most destructive cyberattacks in history: the 2015 and 2016 Ukraine power grid attacks, NotPetya, Olympic Destroyer, and continuous destructive campaigns against Ukraine since 2022. This deep-dive covers their history, capabilities, and why they remain the most dangerous threat actor operating today.
Launched in mid-2025 by a disgruntled Qilin affiliate, The Gentlemen ransomware-as-a-service operation reached third place globally in Q1 2026 through pre-stockpiled FortiGate access, a 90% affiliate commission, and a deliberate strategy to target non-US markets that most groups neglect.
AI in the Attack Chain: How Threat Actors Are Using Language Models Operationally
AI-assisted exploitation is no longer theoretical. From automated vulnerability research to AI-generated spear-phishing, the adoption of LLMs across the offensive lifecycle is accelerating. This analysis examines what is confirmed, what is emerging, and what it means for defenders.
Volt Typhoon: The Long Game in Western Critical Infrastructure
A deep analysis of Volt Typhoon's objectives, methods, and targets -- and what the sustained Chinese pre-positioning campaign in Western CNI means for how operators, regulators, and governments need to respond.
Commentary
The 2026 Iran Conflict and the Dawn of Cyber-Enabled Kinetic Targeting
Iran's conflict with the US and Israel in 2026 confirmed what threat analysts had long theorised: cyberspace is now inseparable from kinetic warfare. What the Iran war reveals about hybrid doctrine — and what it means for critical infrastructure operators.
The Real Cost of a Critical Infrastructure Attack: Beyond the Ransom
When a critical infrastructure operator is hit, the ransom payment is usually the smallest line on the eventual damage assessment. The true costs -- operational, regulatory, reputational, and systemic -- are far larger and far longer-lasting.