Skip to main content

BLOG

Threat Intelligence Research

In-depth CVE analysis, ransomware group tracking, and threat actor research from the PurpleOps intelligence platform. Every report is built on our own telemetry and reviewed by our analysts.

Showing 12 of 125 articles

DieNet Artifacts: 223 Collected on Telegram
Threat Intelligence

DieNet Artifacts: 223 Collected on Telegram

PurpleOps found 223 DieNet artifacts on Telegram in 7 days. Adjust collection to avoid false positives; this isn't evidence of operations.

September 8, 2026  ·  6 min read Read More →
Earth Lusca: 304 Artifact Mentions Spike in 7
Threat Intelligence

Earth Lusca: 304 Artifact Mentions Spike in 7

Our tracking logged a 304x increase in Earth Lusca artifact mentions over seven days. We clarify this collection spike against operational activity.

September 1, 2026  ·  6 min read Read More →
CVE-2026-73570 Zimbra KEV: PoC 97/100 Readiness
CVE Analysis

CVE-2026-73570 Zimbra KEV: PoC 97/100 Readiness

CVE-2026-73570 (Zimbra ZCS) is KEV-listed and the remediation deadline passed yesterday.

August 25, 2026  ·  5 min read Read More →
APT3 Gothic Panda: 3 Campaigns, 44 ATT&CK TTPs
Threat Intelligence

APT3 Gothic Panda: 3 Campaigns, 44 ATT&CK TTPs

APT3, tracked as Gothic Panda and Buckeye, ran three campaigns and burned two zero-days before its 2017 indictment. Tools, CVEs and ATT&CK mapping.

August 11, 2026  ·  8 min read Read More →
CVE-2026-50522 SharePoint KEV RCE: PoC Still Immature
CVE Analysis

CVE-2026-50522 SharePoint KEV RCE: PoC Still Immature

CVE-2026-50522: Critical SharePoint RCE KEV-listed, deadline passed. Our triage: one public PoC scores 75/100, an educational scaffold.

July 28, 2026  ·  6 min read Read More →
wp2shell WordPress RCE Critical CVE-2026-63030 Exploited
CVE Analysis

wp2shell WordPress RCE Critical CVE-2026-63030 Exploited

WordPress Core is impacted by the critical pre-authentication RCE vulnerability chain wp2shell, CVE-2026-63030 & CVE-2026-60137.

July 21, 2026  ·  5 min read Read More →
SonicWall CVE-2026-15409 Exploited by Inc Ransomware
Threat Intelligence

SonicWall CVE-2026-15409 Exploited by Inc Ransomware

SonicWall CVE-2026-15409, a critical zero-day with CVSS 10.0, is actively exploited by Inc Ransomware for RCE and enterprise infiltration.

July 18, 2026  ·  5 min read Read More →
Microsoft SharePoint CVE-2026-45659 (CVSS 8.8) RCE
CVE Analysis

Microsoft SharePoint CVE-2026-45659 (CVSS 8.8) RCE

Microsoft SharePoint Server is affected by CVE-2026-45659, a CVSS 8.8 RCE vulnerability actively exploited and added to CISA KEV.

July 3, 2026  ·  5 min read Read More →
CVE-2026-8037 (CVSS 9.6): Kemp LoadMaster RCE
CVE Analysis

CVE-2026-8037 (CVSS 9.6): Kemp LoadMaster RCE

Progress Kemp LoadMaster devices face active exploitation attempts targeting CVE-2026-8037, a critical pre-authentication RCE with a CVSS score of 9.6.

July 1, 2026  ·  5 min read Read More →
Oracle PeopleSoft CVE-2026-35273 RCE Actively Exploited
CVE Analysis

Oracle PeopleSoft CVE-2026-35273 RCE Actively Exploited

Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) is an RCE zero-day actively exploited by ShinyHunters targeting higher education.

June 27, 2026  ·  5 min read Read More →
Cisco CUCM CVE-2026-20230 Exploited For Root Access
Threat Intelligence

Cisco CUCM CVE-2026-20230 Exploited For Root Access

Threat actors are actively exploiting Cisco CUCM CVE-2026-20230, an SSRF flaw, to gain root access within 24 hours of public PoC.

June 26, 2026  ·  5 min read Read More →
Cisco Splunk CVE-2026-20253 Critical Exploit
CVE Analysis

Cisco Splunk CVE-2026-20253 Critical Exploit

Cisco Splunk Enterprise CVE-2026-20253, a high-severity unauthenticated file manipulation vulnerability, is actively exploited in-the-wild.

June 22, 2026  ·  5 min read Read More →

Get Threat Intelligence in Your Inbox

New CVE analysis, ransomware tracking, and threat research, sent when we publish.

Free threat intelligence research. Unsubscribe anytime.