Skip to main content

BLOG

Threat Intelligence Research

In-depth CVE analysis, ransomware group tracking, and threat actor research from the PurpleOps intelligence platform. Every report is built on our own telemetry and reviewed by our analysts.

Showing 12 of 122 articles

APT3 Gothic Panda: 3 Campaigns, 44 ATT&CK TTPs
Threat Intelligence

APT3 Gothic Panda: 3 Campaigns, 44 ATT&CK TTPs

APT3, tracked as Gothic Panda and Buckeye, ran three campaigns and burned two zero-days before its 2017 indictment. Tools, CVEs and ATT&CK mapping.

August 11, 2026  ·  8 min read Read More →
CVE-2026-50522 SharePoint KEV RCE: PoC Still Immature
CVE Analysis

CVE-2026-50522 SharePoint KEV RCE: PoC Still Immature

CVE-2026-50522: Critical SharePoint RCE KEV-listed, deadline passed. Our triage: one public PoC scores 75/100, an educational scaffold.

July 28, 2026  ·  6 min read Read More →
wp2shell WordPress RCE Critical CVE-2026-63030 Exploited
CVE Analysis

wp2shell WordPress RCE Critical CVE-2026-63030 Exploited

WordPress Core is impacted by the critical pre-authentication RCE vulnerability chain wp2shell, CVE-2026-63030 & CVE-2026-60137.

July 21, 2026  ·  5 min read Read More →
SonicWall CVE-2026-15409 Exploited by Inc Ransomware
Threat Intelligence

SonicWall CVE-2026-15409 Exploited by Inc Ransomware

SonicWall CVE-2026-15409, a critical zero-day with CVSS 10.0, is actively exploited by Inc Ransomware for RCE and enterprise infiltration.

July 18, 2026  ·  5 min read Read More →
Microsoft SharePoint CVE-2026-45659 (CVSS 8.8) RCE
CVE Analysis

Microsoft SharePoint CVE-2026-45659 (CVSS 8.8) RCE

Microsoft SharePoint Server is affected by CVE-2026-45659, a CVSS 8.8 RCE vulnerability actively exploited and added to CISA KEV.

July 3, 2026  ·  5 min read Read More →
CVE-2026-8037 (CVSS 9.6): Kemp LoadMaster RCE
CVE Analysis

CVE-2026-8037 (CVSS 9.6): Kemp LoadMaster RCE

Progress Kemp LoadMaster devices face active exploitation attempts targeting CVE-2026-8037, a critical pre-authentication RCE with a CVSS score of 9.6.

July 1, 2026  ·  5 min read Read More →
Oracle PeopleSoft CVE-2026-35273 RCE Actively Exploited
CVE Analysis

Oracle PeopleSoft CVE-2026-35273 RCE Actively Exploited

Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) is an RCE zero-day actively exploited by ShinyHunters targeting higher education.

June 27, 2026  ·  5 min read Read More →
Cisco CUCM CVE-2026-20230 Exploited For Root Access
Threat Intelligence

Cisco CUCM CVE-2026-20230 Exploited For Root Access

Threat actors are actively exploiting Cisco CUCM CVE-2026-20230, an SSRF flaw, to gain root access within 24 hours of public PoC.

June 26, 2026  ·  5 min read Read More →
Cisco Splunk CVE-2026-20253 Critical Exploit
CVE Analysis

Cisco Splunk CVE-2026-20253 Critical Exploit

Cisco Splunk Enterprise CVE-2026-20253, a high-severity unauthenticated file manipulation vulnerability, is actively exploited in-the-wild.

June 22, 2026  ·  5 min read Read More →
SimpleHelp CVE-2026-48558 (CVSS 10.0) Bypass
CVE Analysis

SimpleHelp CVE-2026-48558 (CVSS 10.0) Bypass

SimpleHelp CVE-2026-48558, a critical authentication bypass with a CVSS of 10.0, is actively exploited.

June 14, 2026  ·  5 min read Read More →
Ivanti Sentry CVE-2026-10520 (CVSS 10.0) RCE
CVE Analysis

Ivanti Sentry CVE-2026-10520 (CVSS 10.0) RCE

Ivanti Sentry CVE-2026-10520, a critical OS command injection with CVSS 10.0, enables unauthenticated RCE; patch immediately to mitigate active exploitation.

June 12, 2026  ·  5 min read Read More →
Check Point VPN CVE-2026-50751 (CVSS 9.3) Bypass
CVE Analysis

Check Point VPN CVE-2026-50751 (CVSS 9.3) Bypass

Check Point CVE-2026-50751 is a critical authentication bypass (CVSS 9.3) in IKEv1 VPNs, actively exploited by Qilin ransomware for unauthorized access.

June 9, 2026  ·  5 min read Read More →

Get Threat Intelligence in Your Inbox

New CVE analysis, ransomware tracking, and threat research, sent when we publish.

Free threat intelligence research. Unsubscribe anytime.