BLOG
Threat Intelligence Research
In-depth CVE analysis, ransomware group tracking, and threat actor research from the PurpleOps intelligence platform. Every report is built on our own telemetry and reviewed by our analysts.
Showing 12 of 125 articles
DieNet Artifacts: 223 Collected on Telegram
PurpleOps found 223 DieNet artifacts on Telegram in 7 days. Adjust collection to avoid false positives; this isn't evidence of operations.
Earth Lusca: 304 Artifact Mentions Spike in 7
Our tracking logged a 304x increase in Earth Lusca artifact mentions over seven days. We clarify this collection spike against operational activity.
CVE-2026-73570 Zimbra KEV: PoC 97/100 Readiness
CVE-2026-73570 (Zimbra ZCS) is KEV-listed and the remediation deadline passed yesterday.
APT3 Gothic Panda: 3 Campaigns, 44 ATT&CK TTPs
APT3, tracked as Gothic Panda and Buckeye, ran three campaigns and burned two zero-days before its 2017 indictment. Tools, CVEs and ATT&CK mapping.
CVE-2026-50522 SharePoint KEV RCE: PoC Still Immature
CVE-2026-50522: Critical SharePoint RCE KEV-listed, deadline passed. Our triage: one public PoC scores 75/100, an educational scaffold.
wp2shell WordPress RCE Critical CVE-2026-63030 Exploited
WordPress Core is impacted by the critical pre-authentication RCE vulnerability chain wp2shell, CVE-2026-63030 & CVE-2026-60137.
SonicWall CVE-2026-15409 Exploited by Inc Ransomware
SonicWall CVE-2026-15409, a critical zero-day with CVSS 10.0, is actively exploited by Inc Ransomware for RCE and enterprise infiltration.
Microsoft SharePoint CVE-2026-45659 (CVSS 8.8) RCE
Microsoft SharePoint Server is affected by CVE-2026-45659, a CVSS 8.8 RCE vulnerability actively exploited and added to CISA KEV.
CVE-2026-8037 (CVSS 9.6): Kemp LoadMaster RCE
Progress Kemp LoadMaster devices face active exploitation attempts targeting CVE-2026-8037, a critical pre-authentication RCE with a CVSS score of 9.6.
Oracle PeopleSoft CVE-2026-35273 RCE Actively Exploited
Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) is an RCE zero-day actively exploited by ShinyHunters targeting higher education.
Cisco CUCM CVE-2026-20230 Exploited For Root Access
Threat actors are actively exploiting Cisco CUCM CVE-2026-20230, an SSRF flaw, to gain root access within 24 hours of public PoC.
Cisco Splunk CVE-2026-20253 Critical Exploit
Cisco Splunk Enterprise CVE-2026-20253, a high-severity unauthenticated file manipulation vulnerability, is actively exploited in-the-wild.
No articles found matching your search.
Get Threat Intelligence in Your Inbox
New CVE analysis, ransomware tracking, and threat research, sent when we publish.
Free threat intelligence research. Unsubscribe anytime.