BLOG
Threat Intelligence Research
In-depth CVE analysis, ransomware group tracking, and threat actor research from the PurpleOps intelligence platform. Every report is built on our own telemetry and reviewed by our analysts.
Showing 12 of 122 articles
APT3 Gothic Panda: 3 Campaigns, 44 ATT&CK TTPs
APT3, tracked as Gothic Panda and Buckeye, ran three campaigns and burned two zero-days before its 2017 indictment. Tools, CVEs and ATT&CK mapping.
CVE-2026-50522 SharePoint KEV RCE: PoC Still Immature
CVE-2026-50522: Critical SharePoint RCE KEV-listed, deadline passed. Our triage: one public PoC scores 75/100, an educational scaffold.
wp2shell WordPress RCE Critical CVE-2026-63030 Exploited
WordPress Core is impacted by the critical pre-authentication RCE vulnerability chain wp2shell, CVE-2026-63030 & CVE-2026-60137.
SonicWall CVE-2026-15409 Exploited by Inc Ransomware
SonicWall CVE-2026-15409, a critical zero-day with CVSS 10.0, is actively exploited by Inc Ransomware for RCE and enterprise infiltration.
Microsoft SharePoint CVE-2026-45659 (CVSS 8.8) RCE
Microsoft SharePoint Server is affected by CVE-2026-45659, a CVSS 8.8 RCE vulnerability actively exploited and added to CISA KEV.
CVE-2026-8037 (CVSS 9.6): Kemp LoadMaster RCE
Progress Kemp LoadMaster devices face active exploitation attempts targeting CVE-2026-8037, a critical pre-authentication RCE with a CVSS score of 9.6.
Oracle PeopleSoft CVE-2026-35273 RCE Actively Exploited
Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) is an RCE zero-day actively exploited by ShinyHunters targeting higher education.
Cisco CUCM CVE-2026-20230 Exploited For Root Access
Threat actors are actively exploiting Cisco CUCM CVE-2026-20230, an SSRF flaw, to gain root access within 24 hours of public PoC.
Cisco Splunk CVE-2026-20253 Critical Exploit
Cisco Splunk Enterprise CVE-2026-20253, a high-severity unauthenticated file manipulation vulnerability, is actively exploited in-the-wild.
SimpleHelp CVE-2026-48558 (CVSS 10.0) Bypass
SimpleHelp CVE-2026-48558, a critical authentication bypass with a CVSS of 10.0, is actively exploited.
Ivanti Sentry CVE-2026-10520 (CVSS 10.0) RCE
Ivanti Sentry CVE-2026-10520, a critical OS command injection with CVSS 10.0, enables unauthenticated RCE; patch immediately to mitigate active exploitation.
Check Point VPN CVE-2026-50751 (CVSS 9.3) Bypass
Check Point CVE-2026-50751 is a critical authentication bypass (CVSS 9.3) in IKEv1 VPNs, actively exploited by Qilin ransomware for unauthorized access.
No articles found matching your search.
Get Threat Intelligence in Your Inbox
New CVE analysis, ransomware tracking, and threat research, sent when we publish.
Free threat intelligence research. Unsubscribe anytime.