Master Intelligence Index
A comprehensive taxonomy indexing cybersecurity incidents, nation-state threat actors, novel zero-day exploit primitives, malware strains, and defensive bodies.
Trans-Pacific & European Backbone Core Routing Compromise
Coordinated exploitation of carrier SS7/Diameter interconnects and edge hypervisors targeting government voice routes and subsea fiber management planes.
Rotterdam & Antwerp Maritime Terminal Automation Freeze
Disruption of automated container crane telemetry and berth allocation SCADA controllers via malicious IEC-104 protocol packet floods.
Singapore Multi-Chain Institutional Bridge $280M Extraction
Social engineering compromise of developer cryptographic signing keys by Lazarus Group leading to massive smart contract treasury liquidation.
National Electricity Market (NEM) Grid Ingress Triage
Discovery of persistent living-off-the-land footholds in regional Australian transmission substation relays.
Navi Mumbai Cloud Provider Hypervisor Lockout
BlackCat/ALPHV ransomware deployment targeting multi-tenant VMware ESXi virtualization clusters across Indian commercial hosting provider.
Linux Kernel eBPF Verifier Boundary Evasion LPE
Critical vulnerability in the Linux kernel extended Berkeley Packet Filter (eBPF) verifier arithmetic logic allowing local unprivileged containers to break out and execute arbitrary kernel memory code.
Telecom SS7/Diameter Core Gateway Packet Deserialization RCE
Flaw in carrier-grade Signalling System 7 (SS7) and Diameter routing gateways enabling remote unauthenticated actors to execute arbitrary code within core cellular interconnects.
XZ Utils / liblzma Upstream Build Injection Backdoor
Historic multi-year supply chain backdoor inserted into xz/liblzma 5.6.0 and 5.6.1 designed to intercept OpenSSH daemon cryptographic verification routines on glibc-based systems.
Ivanti Connect Secure & Policy Secure Command Injection
Command injection in Ivanti web component allowing authenticated administrators (or unauthenticated attackers when chained with CVE-2023-46805) to execute arbitrary commands.
Lazarus Group (APT38 / Hidden Cobra / BlueNoroff)
Prolific state-backed cyber warfare and financial cyber-heist collective responsible for billions in cryptocurrency theft, defense espionage, and disruptive attacks.
Volt Typhoon (Bronze Silhouette / Vanguard Panda)
State-sponsored threat actor focused on stealth pre-positioning within critical infrastructure networks to enable disruptive kinetic or cyber sabotage.
Sandworm (Unit 74455 / Main Center for Special Technologies)
The Russian military intelligence agency’s premier cyber-sabotage unit, notorious for devastating wiper malware, power grid blackouts, and NotPetya.
Midnight Blizzard (APT29 / Nobelium / Cozy Bear)
Elite Russian Foreign Intelligence Service (SVR) cyber espionage apparatus celebrated for high-level government infiltration, SolarWinds supply chain poisoning, and cloud token manipulation.
Scattered Spider (UNC3944 / Octo Tempest / Starfraud)
Hyper-aggressive, English-speaking cybercrime syndicate mastering identity provider compromise, SIM swapping, helpdesk social engineering, and cloud infrastructure ransom.
HermeticWiper (FoxBlade / Trojan.KillDisk)
Destructive data-wiping malware weaponized by Sandworm / Russian state operators, weaponizing signed partition drivers to destroy Master Boot Records (MBR) and VSS shadow copies.
BlackCat (ALPHV / Sphynx)
Highly customizable Rust-based ransomware-as-a-service (RaaS) specializing in VMware ESXi hypervisor destruction and massive double-extortion exfiltration.
Pegasus Spyware Suite
Military-grade commercial zero-click surveillance platform developed by NSO Group, capable of silent real-time ambient recording, encrypted messaging interception, and GPS tracking.
LummaC2 Infostealer
Pervasive commodity infostealer harvesting session tokens, cryptocurrency wallet private keys, browser passwords, and MFA cookies across global consumer and corporate endpoints.
Linux Kernel
Monolithic open-source operating system kernel running majority of global cloud servers, supercomputers, Android devices, and network infrastructure.
VMware ESXi Hypervisor
Type-1 bare-metal hypervisor deployed in enterprise datacenters to host and partition virtual machines and critical workload clusters.
Ivanti Connect Secure (formerly Pulse Secure)
SSL VPN gateway and Zero Trust network access appliance safeguarding corporate perimeters and remote employee sessions.
Microsoft Entra ID (Azure AD)
Cloud-based identity and access management service orchestrating authentication and access tokens for hundreds of millions of corporate users.
Maddie Stone
Pioneering security researcher specializing in in-the-wild zero-day exploit analysis, firmware reversing, and root cause discovery.
Dr. Bill Marczak
Senior Research Fellow celebrated for unmasking commercial targeted spyware operations and zero-click iPhone/Android exploit chains.
Jen Easterly
National cybersecurity strategist known for championing Secure-by-Design principles, memory-safe software adoption, and public-private threat sharing.
Andres Freund
Principal software engineer who discovered and prevented the historic CVE-2024-3094 XZ Utils supply chain backdoor through meticulous CPU performance profiling.
Cybersecurity & Infrastructure Security Agency (CISA)
The operational lead for federal cybersecurity and the national coordinator for critical infrastructure security and resilience.
European Union Agency for Cybersecurity (ENISA)
The agency of the European Union dedicated to achieving a high common level of cybersecurity across Europe.
The Citizen Lab
An interdisciplinary laboratory based at the Munk School of Global Affairs & Public Policy, University of Toronto, focusing on digital surveillance and spyware.
Google Project Zero
Elite security research team tasked with advancing the understanding and defense of zero-day vulnerabilities in hardware and software.
Mandiant Threat Intelligence
Global leader in incident response and advanced cyber threat intelligence profiling nation-state actors and advanced cybercrime syndicates.
Directive on Measures for a High Common Level of Cybersecurity Across the Union (NIS2 Directive)
Landmark EU cybersecurity legislation expanding mandatory cyber hygiene, supply chain risk management, and rigorous 24-hour incident notification rules across 18 critical and essential sectors.
Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)
Federal statute mandating critical infrastructure entities report covered cyber incidents to CISA within 72 hours and ransomware payments within 24 hours.
Digital Personal Data Protection Act, 2023 (DPDP Act)
Comprehensive Indian legislation governing processing of digital personal data, mandating reasonable security safeguards and establishing heavy financial penalties for data breaches.
Product Security and Telecommunications Infrastructure Act 2022 (PSTI)
UK statute prohibiting default factory passwords on consumer IoT devices and requiring transparent vulnerability disclosure policies and minimum security update support periods.
United States v. Yuriy Sergeyevich Andrienko et al. (Sandworm Military Officers)
Landmark federal indictment unmasking six active-duty military intelligence officers of the Russian GRU Unit 74455 (Sandworm) for the world’s most destructive cyberattacks including NotPetya, Ukrainian power grid blackouts, and Olympic Destroyer.
SEC v. SolarWinds Corp. & Timothy G. Brown (Chief Information Security Officer)
Unprecedented SEC enforcement action charging a public software enterprise and its individual CISO with defrauding investors through misleading public cybersecurity statements prior to the historic SUNBURST supply chain breach.
R v. Arion Kurtaj & Youth Defendant (Lapsus$ Cyber Syndicate Prosecution)
High-profile criminal trial convicting key members of the teenage extortion collective Lapsus$ for brazen breaches of Rockstar Games, Uber, Nvidia, Microsoft, and British Telecom.