DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
KNOWLEDGE DISCOVERY CORPUS

Master Intelligence Index

A comprehensive taxonomy indexing cybersecurity incidents, nation-state threat actors, novel zero-day exploit primitives, malware strains, and defensive bodies.

INDEXED ENTITIES (38)SORTED BY INTELLIGENCE PRIORITY
incident

Trans-Pacific & European Backbone Core Routing Compromise

Coordinated exploitation of carrier SS7/Diameter interconnects and edge hypervisors targeting government voice routes and subsea fiber management planes.

incident

Rotterdam & Antwerp Maritime Terminal Automation Freeze

Disruption of automated container crane telemetry and berth allocation SCADA controllers via malicious IEC-104 protocol packet floods.

incident

Singapore Multi-Chain Institutional Bridge $280M Extraction

Social engineering compromise of developer cryptographic signing keys by Lazarus Group leading to massive smart contract treasury liquidation.

incident

National Electricity Market (NEM) Grid Ingress Triage

Discovery of persistent living-off-the-land footholds in regional Australian transmission substation relays.

incident

Navi Mumbai Cloud Provider Hypervisor Lockout

BlackCat/ALPHV ransomware deployment targeting multi-tenant VMware ESXi virtualization clusters across Indian commercial hosting provider.

CVE-2026-3819
CVSS 9.80-DAY

Linux Kernel eBPF Verifier Boundary Evasion LPE

Critical vulnerability in the Linux kernel extended Berkeley Packet Filter (eBPF) verifier arithmetic logic allowing local unprivileged containers to break out and execute arbitrary kernel memory code.

EPSS: 89.2%IN THE WILD
CVE-2026-1194
CVSS 10.00-DAY

Telecom SS7/Diameter Core Gateway Packet Deserialization RCE

Flaw in carrier-grade Signalling System 7 (SS7) and Diameter routing gateways enabling remote unauthenticated actors to execute arbitrary code within core cellular interconnects.

EPSS: 94.5%IN THE WILD
CVE-2024-3094
CVSS 10.0

XZ Utils / liblzma Upstream Build Injection Backdoor

Historic multi-year supply chain backdoor inserted into xz/liblzma 5.6.0 and 5.6.1 designed to intercept OpenSSH daemon cryptographic verification routines on glibc-based systems.

EPSS: 81.2%DISCLOSED
CVE-2024-21887
CVSS 9.10-DAY

Ivanti Connect Secure & Policy Secure Command Injection

Command injection in Ivanti web component allowing authenticated administrators (or unauthenticated attackers when chained with CVE-2023-46805) to execute arbitrary commands.

EPSS: 97.4%IN THE WILD
ORIGIN: Democratic People’s Republic of Korea active

Lazarus Group (APT38 / Hidden Cobra / BlueNoroff)

ACTIVE SINCE: 2009 · 4 MAJOR OPERATIONS

Prolific state-backed cyber warfare and financial cyber-heist collective responsible for billions in cryptocurrency theft, defense espionage, and disruptive attacks.

MOTIVATION: financialCONFIRMED ATTRIBUTION
ORIGIN: People’s Republic of China active

Volt Typhoon (Bronze Silhouette / Vanguard Panda)

ACTIVE SINCE: 2021 · 2 MAJOR OPERATIONS

State-sponsored threat actor focused on stealth pre-positioning within critical infrastructure networks to enable disruptive kinetic or cyber sabotage.

MOTIVATION: sabotageCONFIRMED ATTRIBUTION
ORIGIN: Russian Federation active

Sandworm (Unit 74455 / Main Center for Special Technologies)

ACTIVE SINCE: 2009 · 3 MAJOR OPERATIONS

The Russian military intelligence agency’s premier cyber-sabotage unit, notorious for devastating wiper malware, power grid blackouts, and NotPetya.

MOTIVATION: sabotageCONFIRMED ATTRIBUTION
ORIGIN: Russian Federation active

Midnight Blizzard (APT29 / Nobelium / Cozy Bear)

ACTIVE SINCE: 2008 · 2 MAJOR OPERATIONS

Elite Russian Foreign Intelligence Service (SVR) cyber espionage apparatus celebrated for high-level government infiltration, SolarWinds supply chain poisoning, and cloud token manipulation.

MOTIVATION: espionageCONFIRMED ATTRIBUTION
ORIGIN: United States / United Kingdom / Canada active

Scattered Spider (UNC3944 / Octo Tempest / Starfraud)

ACTIVE SINCE: 2022 · 1 MAJOR OPERATIONS

Hyper-aggressive, English-speaking cybercrime syndicate mastering identity provider compromise, SIM swapping, helpdesk social engineering, and cloud infrastructure ransom.

MOTIVATION: financialCONFIRMED ATTRIBUTION
wiperSEEN 2022

HermeticWiper (FoxBlade / Trojan.KillDisk)

Destructive data-wiping malware weaponized by Sandworm / Russian state operators, weaponizing signed partition drivers to destroy Master Boot Records (MBR) and VSS shadow copies.

TARGETS: x86, x64, Windows NTSandworm (Unit 74455)
ransomwareSEEN 2021

BlackCat (ALPHV / Sphynx)

Highly customizable Rust-based ransomware-as-a-service (RaaS) specializing in VMware ESXi hypervisor destruction and massive double-extortion exfiltration.

TARGETS: Rust, Windows, Linux ESXi, ARM64Scattered Spider (UNC3944)
spywareSEEN 2016

Pegasus Spyware Suite

Military-grade commercial zero-click surveillance platform developed by NSO Group, capable of silent real-time ambient recording, encrypted messaging interception, and GPS tracking.

TARGETS: iOS, iPadOS, Android, ARM64NSO Group Ecosystem
infostealerSEEN 2022

LummaC2 Infostealer

Pervasive commodity infostealer harvesting session tokens, cryptocurrency wallet private keys, browser passwords, and MFA cookies across global consumer and corporate endpoints.

TARGETS: C, x86, x64, WindowsInitial Access Brokers
operating systemLinux Foundation / Open Source Community

Linux Kernel

Monolithic open-source operating system kernel running majority of global cloud servers, supercomputers, Android devices, and network infrastructure.

1420 TRACKED FLAWS84 CRITICAL
hypervisorBroadcom / VMware

VMware ESXi Hypervisor

Type-1 bare-metal hypervisor deployed in enterprise datacenters to host and partition virtual machines and critical workload clusters.

312 TRACKED FLAWS41 CRITICAL
vpn gatewayIvanti

Ivanti Connect Secure (formerly Pulse Secure)

SSL VPN gateway and Zero Trust network access appliance safeguarding corporate perimeters and remote employee sessions.

189 TRACKED FLAWS29 CRITICAL
iam identityMicrosoft Corporation

Microsoft Entra ID (Azure AD)

Cloud-based identity and access management service orchestrating authentication and access tokens for hundreds of millions of corporate users.

120 TRACKED FLAWS18 CRITICAL
researcherUnited States

Maddie Stone

Google Project Zero

Pioneering security researcher specializing in in-the-wild zero-day exploit analysis, firmware reversing, and root cause discovery.

38 DISCLOSED CVEsVIEW DOSSIER →
researcherCanada / USA

Dr. Bill Marczak

The Citizen Lab (Univ. of Toronto) / UC Berkeley

Senior Research Fellow celebrated for unmasking commercial targeted spyware operations and zero-click iPhone/Android exploit chains.

29 DISCLOSED CVEsVIEW DOSSIER →
cert officialUnited States

Jen Easterly

Former Director, CISA

National cybersecurity strategist known for championing Secure-by-Design principles, memory-safe software adoption, and public-private threat sharing.

LEADERSHIPVIEW DOSSIER →
researcherGermany / USA

Andres Freund

PostgreSQL Core Team / Microsoft

Principal software engineer who discovered and prevented the historic CVE-2024-3094 XZ Utils supply chain backdoor through meticulous CPU performance profiling.

6 DISCLOSED CVEsVIEW DOSSIER →
organization

Cybersecurity & Infrastructure Security Agency (CISA)

The operational lead for federal cybersecurity and the national coordinator for critical infrastructure security and resilience.

organization

European Union Agency for Cybersecurity (ENISA)

The agency of the European Union dedicated to achieving a high common level of cybersecurity across Europe.

organization

The Citizen Lab

An interdisciplinary laboratory based at the Munk School of Global Affairs & Public Policy, University of Toronto, focusing on digital surveillance and spyware.

organization

Google Project Zero

Elite security research team tasked with advancing the understanding and defense of zero-day vulnerabilities in hardware and software.

organization

Mandiant Threat Intelligence

Global leader in incident response and advanced cyber threat intelligence profiling nation-state actors and advanced cybercrime syndicates.

European Union (27 Member States)in force

Directive on Measures for a High Common Level of Cybersecurity Across the Union (NIS2 Directive)

Landmark EU cybersecurity legislation expanding mandatory cyber hygiene, supply chain risk management, and rigorous 24-hour incident notification rules across 18 critical and essential sectors.

CODE: Directive (EU) 2022/2555LEGAL STATUTE →
United Statesin force

Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)

Federal statute mandating critical infrastructure entities report covered cyber incidents to CISA within 72 hours and ransomware payments within 24 hours.

CODE: Public Law 117-103, 6 U.S.C. 681 et seq.LEGAL STATUTE →
Indiain force

Digital Personal Data Protection Act, 2023 (DPDP Act)

Comprehensive Indian legislation governing processing of digital personal data, mandating reasonable security safeguards and establishing heavy financial penalties for data breaches.

CODE: Act No. 22 of 2023LEGAL STATUTE →
United Kingdomin force

Product Security and Telecommunications Infrastructure Act 2022 (PSTI)

UK statute prohibiting default factory passwords on consumer IoT devices and requiring transparent vulnerability disclosure policies and minimum security update support periods.

CODE: UK Public General Acts 2022 c. 46LEGAL STATUTE →
case

United States v. Yuriy Sergeyevich Andrienko et al. (Sandworm Military Officers)

Landmark federal indictment unmasking six active-duty military intelligence officers of the Russian GRU Unit 74455 (Sandworm) for the world’s most destructive cyberattacks including NotPetya, Ukrainian power grid blackouts, and Olympic Destroyer.

case

SEC v. SolarWinds Corp. & Timothy G. Brown (Chief Information Security Officer)

Unprecedented SEC enforcement action charging a public software enterprise and its individual CISO with defrauding investors through misleading public cybersecurity statements prior to the historic SUNBURST supply chain breach.

case

R v. Arion Kurtaj & Youth Defendant (Lapsus$ Cyber Syndicate Prosecution)

High-profile criminal trial convicting key members of the teenage extortion collective Lapsus$ for brazen breaches of Rockstar Games, Uber, Nvidia, Microsoft, and British Telecom.