Skip to content

Flash Briefings

critical

CVE-2026-41089: Critical Windows Netlogon RCE Now Actively Exploited — Every Unpatched Domain Controller at Risk

Active exploitation of CVE-2026-41089, a pre-authentication zero-click RCE in Windows Netlogon, was confirmed by Belgium's Centre for Cybersecurity on 29 May. Successful exploitation gives an attacker SYSTEM-level control of the domain controller and full ownership of the Active Directory domain.

high

CVE-2026-0257: PAN-OS GlobalProtect Authentication Bypass Under Active Exploitation — CISA Deadline Today

A medium-severity authentication bypass in Palo Alto Networks PAN-OS GlobalProtect is being actively exploited across enterprise networks, with CISA's KEV remediation deadline falling on 1 June 2026.

high Nimbus Manticore

Nimbus Manticore Resurfaces with New Backdoor and Expanded European Targeting After Operation Epic Fury

Iranian IRGC-affiliated APT Nimbus Manticore has resumed aggressive campaigns against aviation, telecommunications, and critical infrastructure in Europe and the US, deploying an undocumented AI-assisted backdoor and adopting new delivery techniques since the outbreak of the US-Iran conflict.

high Cl0p

Cl0p Exploiting File Transfer Vulnerabilities Across Transport and Logistics Sector

The Cl0p ransomware group is mass-exploiting a newly disclosed vulnerability in a widely used managed file transfer platform. Several European freight and logistics operators have been impacted, with customs and supply chain data exfiltrated.

Deep Analysis

high Pioneer Kitten / Fox Kitten 12 min read

Pioneer Kitten: How Iran's IRGC Became an Access Broker for Ransomware Gangs

Pioneer Kitten — tracked as Fox Kitten, Lemon Sandstorm, and UNC757 — is an Iranian state-sponsored group that exploits network perimeter devices to establish persistent access, then sells that access to criminal ransomware affiliates. This deep dive examines the group's dual mandate, tradecraft, and what a compromise looks like in practice.

high Mustang Panda 13 min read

Mustang Panda (Twill Typhoon): China's Most Prolific Espionage APT

Mustang Panda is one of the most operationally active Chinese APT groups, running continuous espionage operations since at least 2012. Known for PlugX, DLL sideloading, and a rapidly evolving implant arsenal, the group has compromised government ministries, NGOs, telecoms, and religious organisations across Southeast Asia, Europe, and beyond.

high Silk Typhoon 12 min read

Silk Typhoon: China's IT Supply Chain Pivot and the Downstream Threat to Every Sector

Silk Typhoon — the Chinese state actor behind the 2021 Exchange ProxyLogon campaign and the 2024 US Treasury breach — has fundamentally changed how it operates. A deep dive into the group's shift to IT supply chain targeting and what it means for every organisation that relies on a managed service provider.

critical Sandworm 22 min read

Sandworm: Inside Russia's Most Destructive Cyber Weapon

Sandworm -- GRU Unit 74455 -- is responsible for the most destructive cyberattacks in history: the 2015 and 2016 Ukraine power grid attacks, NotPetya, Olympic Destroyer, and continuous destructive campaigns against Ukraine since 2022. This deep-dive covers their history, capabilities, and why they remain the most dangerous threat actor operating today.

high The Gentlemen 10 min read

The Gentlemen: From Zero to 340 Victims in Nine Months -- Inside the RaaS Group Rewriting the Ransomware Playbook

Launched in mid-2025 by a disgruntled Qilin affiliate, The Gentlemen ransomware-as-a-service operation reached third place globally in Q1 2026 through pre-stockpiled FortiGate access, a 90% affiliate commission, and a deliberate strategy to target non-US markets that most groups neglect.

high 18 min read

AI in the Attack Chain: How Threat Actors Are Using Language Models Operationally

AI-assisted exploitation is no longer theoretical. From automated vulnerability research to AI-generated spear-phishing, the adoption of LLMs across the offensive lifecycle is accelerating. This analysis examines what is confirmed, what is emerging, and what it means for defenders.

critical Volt Typhoon 18 min read

Volt Typhoon: The Long Game in Western Critical Infrastructure

A deep analysis of Volt Typhoon's objectives, methods, and targets -- and what the sustained Chinese pre-positioning campaign in Western CNI means for how operators, regulators, and governments need to respond.

Commentary

8 min read

The 2026 Iran Conflict and the Dawn of Cyber-Enabled Kinetic Targeting

Iran's conflict with the US and Israel in 2026 confirmed what threat analysts had long theorised: cyberspace is now inseparable from kinetic warfare. What the Iran war reveals about hybrid doctrine — and what it means for critical infrastructure operators.

8 min read

The Real Cost of a Critical Infrastructure Attack: Beyond the Ransom

When a critical infrastructure operator is hit, the ransom payment is usually the smallest line on the eventual damage assessment. The true costs -- operational, regulatory, reputational, and systemic -- are far larger and far longer-lasting.