APT KQL Daily Ransomware

Daily Threat Intelligence Brief: 5 May 2026

May 5, 2026 22 min read

Two concurrent CRITICAL exploits: CVE-2026-31431 "Copy Fail" Linux LPE (every distro since 2017, 732-byte PoC public, CISA KEV deadline May 15) and CVE-2026-41940 cPanel pre-auth RCE targeting 1.5M servers including Southeast Asian military portals. Also: BlueHammer/RedSun Windows Defender zero-days, Team PCP AI supply chain worm, Lynx ransomware healthcare campaign, and Iranian ICS/OT PLC exploitation. 8 KQL hunting queries and 5 detection rules.

Read more →
APT KQL Daily Ransomware

Daily Threat Intelligence Brief: 4 May 2026

May 4, 2026 20 min read

Seven active threat clusters: Storm-1175/Medusa ransomware at critical tempo against healthcare; APT28 CVE-2026-32202 NTLM coercion (KEV deadline May 12); FIRESTARTER Cisco backdoor; DPRK HexagonalRodent crypto theft ($12M); Mini Shai-Hulud PyPI worm; Iranian ICS attacks; cPanel mass exploitation. 7 KQL queries and 7 detection rules.

Read more →
APT KQL Daily

Daily Threat Intelligence Brief: 3 May 2026

May 3, 2026 18 min read

Nation-state actors APT28 (PRISMEX + SLIMAGENT), Mustang Panda (LOTUSLITE v2), and BRICKSTORM remain active. New APT group TGR-STA-1030 has breached government organisations in 37 countries. Six ransomware groups active. Includes 12 KQL hunting queries, 10 detection rules, and full MITRE ATT&CK mapping.

Read more →