IntelliOS Threat Intel Operating System
IntelliOSRolling Intelligence|AIRolling Exploitable Technology Watch

Exploitable Technology Risk Rolling Intelligence Card

AI-generated, AI-updated weekly, AI quality-checked, and source-cited, this rolling 90-day product reviews the complete IntelliOS catalog and dozens of government, vendor, incident-response, exposure, insurance, and research sources to identify named technologies under active exploitation. It tells executives which owned products can create an incident now, why they matter to the business, what evidence to monitor, and which IntelliOS products contain the deeper campaign, actor, vulnerability, and response analysis.

Coverage
Apr 30–Jul 28, 2026
Record Version
v5
Updated
Jul 28, 2026
AI Monitor
Weekly · Fri 1:00 PM ET
Evidence
25 Retained Sources
Product
Rolling Intelligence Card
Classification
TLP:CLEAR

Research Framing

Reporting-Period Statistics

Rolling 90-Day Intelligence Snapshot

At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.

Period Coverage

Apr 30, 2026Jul 28, 2026

90 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.

90-day windowWeekly on Friday at 1:00 PM ET

70[1]

KEV additions

CISA additions dated Apr 30–Jul 28, 2026.Evidence dated Jul 24, 2026

37[1]

Vendors represented

Distinct vendor names in the rolling extract.Evidence dated Jul 24, 2026

54[1]

Product families

Normalized vendor-product ownership units.Evidence dated Jul 24, 2026

7[1]

Known ransomware use

Entries explicitly marked Known by CISA; not seven confirmed local incidents.Evidence dated Jul 24, 2026

Intended Reader and Decision Context

Persona / Audience

Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.

Audience fieldPrimary audienceAssessmentBoards, CISOs, CIOs, risk and insurance leaders, vulnerability and asset owners, incident-response teams, MSPs, brokers, underwriters, and executives accountable for operational resilience.
Audience fieldOrganization profileAssessmentU.S.-oriented with global source coverage; useful to SMB, midmarket, enterprise, government, education, manufacturing, technology, healthcare, professional services, hosting, and managed-service organizations.
Audience fieldDecision perspectiveAssessmentUse the card to convert a broad vulnerability feed into named ownership questions: Do we operate it? Was it exposed? Is it fixed? Can we prove it remained trustworthy before the fix? Which credentials, workflows, data, or business services require containment or recovery?
Audience fieldNot a substitute forAssessmentAn authenticated asset inventory, vendor-specific applicability review, forensic investigation, legal advice, policy interpretation, or a complete vulnerability-management program.

Chronology and Decision Milestones

Timeline of Notable Activity

Observed activity, public disclosure, KEV catalog action, and required-action deadlines are labeled separately. Later reporting is not backdated to imply that it was public on the underlying activity date.

  1. KEV / hosting control plane

    cPanel & WHM authentication bypass enters the urgent window

    CISA added CVE-2026-41940 and marked known ransomware campaign use, elevating a hosting administration product that can concentrate many customer sites and credentials.[1]

  2. Vendor disclosure

    Ivanti reports very limited exploitation of EPMM

    Ivanti's May security update identifies CVE-2026-6973 and the administrative prerequisite, separating a serious mobile-management risk from an unauthenticated internet takeover.[17]

  3. VPN exploitation

    Palo Alto GlobalProtect bypass becomes ransomware-relevant

    Palo Alto describes limited exploitation of CVE-2026-0257; CISA later marks known ransomware campaign use. Remote access ownership therefore becomes an incident-history question, not only a version check.[1][11]

  4. Software supply chain

    Malicious Nx Console release reaches developer workstations

    Nx says affected workstations should be treated as compromised. CISA connects the malicious extension to GitHub repository and CI/CD secret risk.[12][13]

  5. Edge campaign

    Check Point discloses exploited IKEv1 VPN authentication bypass

    Check Point connects CVE-2026-50751 with medium confidence to financially motivated activity associated with Qilin; CISA marks known ransomware use.[1][8]

  6. Enterprise application

    PeopleSoft exploitation becomes an extortion campaign

    Oracle publishes CVE-2026-35273 guidance. Mandiant links exploitation to UNC6240/ShinyHunters, an education-sector concentration, and extortion activity.[1][6][7]

  7. Product lifecycle / manufacturing

    PTC tells Windchill and FlexPLM owners to patch and hunt web shells

    PTC controls affected-product and response guidance; CISA marks CVE-2026-12569 for known ransomware campaign use.[1][9]

  8. Remote support

    SimpleHelp fixes an OIDC authentication bypass

    CISA and the vendor elevate CVE-2026-48558 in remote-support infrastructure, where one service may bridge administrators, customers, and internal endpoints.[1][10]

  9. Observed zero-day campaign

    SMA1000 compromise moves from WebSocket proxying to privileged execution

    Volexity's earliest observed activity is June 22. SonicWall later confirms active exploitation of CVE-2026-15409 and CVE-2026-15410; Volexity reports SMA-specific malware, credential access, and attempted lateral movement under its separate UTA0533 label.[2][3][4]

  10. Collaboration platform

    On-premises SharePoint exploitation cluster expands

    Microsoft and partner-government advisories identify a current on-premises SharePoint cluster requiring urgent updates and compromise assessment. Cloud SharePoint is not the affected product class.[1][14][15][20]

  11. Security appliance

    FortiSandbox vulnerabilities enter CISA KEV

    CISA adds CVE-2026-25089 and CVE-2026-39808; the irony is operationally important because a security-analysis system can itself become a trusted foothold.[1][16]

  12. AI infrastructure

    Langflow root-context code execution enters KEV

    CISA and NVD elevate CVE-2026-0770. An exposed AI workflow server may hold model keys, APIs, secrets, data connectors, and trusted automation.[1][5]

  13. FortiOS / post-compromise persistence

    CISA makes FortiOS remediation and forensic triage a two-part action

    CISA added CVE-2025-68686 with an August 10 due date. Fortinet says a remote unauthenticated attacker can bypass a fix for symbolic-link persistence observed after prior filesystem-level compromise. The 5.9 Medium CVSS score reflects high attack complexity, while CWE-200 describes unauthorized information exposure; neither changes the need for a fixed release and retrospective integrity investigation.[1][24][25]

Bottom Line Up Front

BLUF

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026
  • Start with ownership, not CVE volume: Seventy new KEVs are too many for an executive list; the decision is whether the organization owns any of the 54 affected product families and whether those systems were reachable during exploitation.[1]Evidence dated Jul 24, 2026

  • FortiOS CVE-2025-68686 is an incident-history question, not only a patch task: Fortinet says the bypass follows earlier filesystem-level compromise, while CISA requires BOD 26-04 forensic triage. Its 5.9 Medium score reflects that hard prerequisite; CWE-200 captures the confidentiality consequence but is too broad to stand in for the exploit's root cause. Owners must determine whether attacker-created persistence or altered trust survived before the fixed release was installed.[1][24][25]First cited source Jul 24, 2026 · Latest cited source Current definition checked 2026-07-28

  • Remote access remains the shortest path to a major loss: SonicWall SMA1000, Check Point IKEv1, Palo Alto GlobalProtect, SimpleHelp, and Ivanti EPMM sit at or near privileged access. A successful edge compromise can expose credentials, sessions, internal routing, managed endpoints, and recovery systems.[1][2][3][8][10][11][17][18]First cited source May 2026 · Latest cited source Jul 24, 2026

  • Patching does not answer whether trust was already lost: For an internet-facing system exploited before remediation, management needs both a closure decision and an incident decision: investigate historical access, preserve evidence, rotate reachable secrets, and validate downstream systems.[2][3][9][13][15]First cited source May 21, 2026 · Latest cited source Jul 17, 2026

  • Business applications can be better extortion targets than security tools: PeopleSoft and Windchill/FlexPLM combine sensitive data, privileged workflows, and operational dependency. Current reporting ties them to ShinyHunters extortion and known ransomware use.[1][6][7][9]First cited source Jun 10, 2026 · Latest cited source Jul 24, 2026

  • Developer and AI systems enlarge the blast radius through trust: Nx Console and Langflow can expose code, CI/CD secrets, cloud credentials, model keys, APIs, data connectors, and automation—not merely the server on which the vulnerable component runs.[5][12][13]First cited source May 21, 2026 · Latest cited source Jul 21, 2026

  • The card is an evidence-backed watchlist, not a compromise declaration: CISA, vendors, responders, insurers, and IntelliOS products answer different questions. The table preserves those boundaries while giving owners one coherent action queue.[1][2][3][18][19][21]First cited source May 2026 · Latest cited source Jul 24, 2026

Decision Context

Executive Summary

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026

This card exists because a conventional vulnerability list does not explain business exposure. From April 30 through July 28, CISA added 70 known-exploited vulnerabilities across 37 vendors and 54 product families. Forty-six carried action windows of three days or less. That tempo is a governance problem: an organization cannot make defensible decisions if it cannot quickly connect a product name to an owner, an exposed instance, a business function, and an incident-response threshold.[1]Evidence dated Jul 24, 2026

The highest-consequence group sits on the network edge or provides remote administration. SonicWall SMA1000, Check Point Security Gateway, Palo Alto GlobalProtect, SimpleHelp, and Ivanti EPMM can place an attacker close to privileged sessions, device management, credentials, or internal routing. Volexity's SMA1000 case shows why version status is insufficient: observed activity included appliance-specific malware, credential gathering, and attempted lateral movement.[2][3][8][10][11][17]First cited source May 7, 2026 · Latest cited source Jul 17, 2026

FortiOS CVE-2025-68686 reinforces that same point with unusually direct vendor and government language. Fortinet says exploitation bypasses a fix for symbolic-link persistence after another vulnerability already delivered filesystem-level compromise. The CNA's 5.9 Medium score reflects that high-complexity prerequisite and rates confidentiality impact High. Fortinet's CWE-200 mapping describes unauthorized information exposure, but MITRE cautions that CWE-200 is broad and discouraged as a precise root-cause mapping. CISA’s KEV action pairs vendor mitigation with BOD 26-04 forensic triage. FortiOS 7.6.0–7.6.1 should move to 7.6.2 or later and 7.4.0–7.4.6 to 7.4.7 or later; owners of the listed 7.2, 7.0, and 6.4 branches should obtain supported migration guidance rather than assume a fixed release exists in those branches.[1][24][25]First cited source Jul 24, 2026 · Latest cited source Current definition checked 2026-07-28

A second group is valuable because of the business data and workflows it concentrates. Oracle PeopleSoft may contain payroll, student, personnel, and financial records; PTC Windchill and FlexPLM may hold product designs, engineering data, and supply-chain workflows; on-premises SharePoint often stores collaboration data and trusted business content. Current sources connect PeopleSoft to UNC6240/ShinyHunters extortion and PTC to a vulnerability marked for known ransomware use.[1][6][7][9][14][15][20]First cited source Jun 10, 2026 · Latest cited source Jul 24, 2026

The newest exposure class is trusted developer and AI infrastructure. A malicious Nx Console extension can compromise a workstation and its repository or CI/CD secrets. Langflow can connect models, APIs, data, and automation; root-context code execution can therefore become secret theft, connected-service access, data exposure, or manipulation of a trusted AI workflow. These products may be less prevalent than VPNs, but one owned instance can carry disproportionate privilege.[5][12][13]First cited source May 21, 2026 · Latest cited source Jul 21, 2026

Seven rolling-period KEVs are marked for known ransomware use, but the ransomware field should not be stretched beyond what it says. It does not identify every actor, victim, or outcome. Where stronger attribution exists, this card says so and preserves the source: Check Point assesses a Qilin connection with medium confidence; Mandiant tracks PeopleSoft activity as UNC6240/ShinyHunters; Volexity uses UTA0533 for SMA1000 activity and does not establish that UTA0533 is INC Ransom. CISA marks ransomware use for CVE-2025-68686 as Unknown, which neither establishes nor rules out ransomware use.[1][3][7][8]First cited source Jun 8, 2026 · Latest cited source Jul 24, 2026

The executive standard is straightforward. First prove whether the product exists and was reachable. Then apply the vendor fix or isolation action. If exploitation could have preceded remediation—or logs are missing—open an incident workstream: preserve evidence, hunt persistence, rotate secrets, test lateral movement, validate backups and recovery control planes, and notify insurer or counsel when policy and facts require it. A closed patch ticket is not proof of historical trust.[2][3][9][10][13][15][21]First cited source May 21, 2026 · Latest cited source Jul 17, 2026

Executive Briefing Priorities

Top 10 Briefing Points

  1. 1

    FortiOS CVE-2025-68686 requires remediation plus historical investigationThe Fortinet advisory makes prior compromise a prerequisite. The 5.9 Medium score and CWE-200 classification explain complexity and confidentiality impact; they do not reduce the KEV response requirement. Preserve evidence, apply a documented fixed branch, hunt persistence and configuration change, rotate exposed trust material, and validate downstream access before closing the event.[1][24][25]First cited source Jul 24, 2026 · Latest cited source Current definition checked 2026-07-28

  2. 2

    70 KEVs became 54 ownership questionsThe useful denominator is distinct vendor-product family, because that maps to asset owners and business functions.[1]Evidence dated Jul 24, 2026

  3. 3

    SMA1000 is both a vulnerability and incident-response eventThe chain can move from unauthenticated proxy access into an authenticated privileged workflow; observed cases included credential access and attempted lateral movement.[2][3][4]First cited source Jul 14, 2026 · Latest cited source Jul 21, 2026

  4. 4

    PeopleSoft combines extortion and regulated dataMandiant links exploitation to ShinyHunters activity concentrated in education, while Oracle controls affected-version guidance.[6][7]First cited source Jun 10, 2026 · Latest cited source Jun 11, 2026

  5. 5

    Check Point's attribution is useful but boundedThe vendor assesses a Qilin association with medium confidence; that is stronger than generic ransomware context but not a universal attribution for every exploit attempt.[8]Evidence dated Jun 8, 2026

  6. 6

    Windchill/FlexPLM can expose the product pipelineWeb-shell persistence in PLM infrastructure can threaten designs, engineering collaboration, supplier trust, and manufacturing continuity.[1][9]First cited source Jun 18, 2026 · Latest cited source Jul 24, 2026

  7. 7

    GlobalProtect bypass converts perimeter trust into ransomware riskPalo Alto reports limited exploitation and CISA marks known ransomware campaign use.[1][11]First cited source Jun 3, 2026 · Latest cited source Jul 24, 2026

  8. 8

    Langflow is narrower but potentially highly privilegedAn internet-exposed instance may bridge model keys, SaaS APIs, databases, secrets, and automated decisions.[1][5]First cited source Jul 21, 2026 · Latest cited source Jul 24, 2026

  9. 9

    Supply-chain compromise changes the unit of responseNx advises treating affected developer workstations as compromised, requiring credential and repository response rather than extension removal alone.[12][13]First cited source May 21, 2026 · Latest cited source May 28, 2026

  10. 10

    On-premises SharePoint needs product-specific scopingThe current cluster affects on-premises servers; executives should not report generic “SharePoint exposure” that wrongly includes unaffected cloud services.[14][15][20]First cited source Jul 14, 2026 · Latest cited source Jul 20, 2026

  11. 11

    Three-day deadlines expose asset-governance weaknessForty-six rolling-period KEVs allowed three days or less for federal action. Unknown, ownerless, or vendor-managed assets are the recurring organizational failure mode.[1]Evidence dated Jul 24, 2026

Company Exposure and Exploitability

Exploitable Technologies for Companies

Specific products and control interfaces elevated by the retained government record. Each row explains the exploitable condition, which companies should care, the business consequence, and the evidence a defender should monitor.

Technology

Fortinet FortiOS · CVE-2025-68686[1][24][25]First cited source Jul 24, 2026 · Latest cited source Current definition checked 2026-07-28

Exploitable condition

Fortinet says a remote unauthenticated attacker can bypass a fix for symbolic-link persistence after the device was already compromised at filesystem level through another vulnerability. CVSS is 5.9 Medium; CWE-200 captures the confidentiality consequence but is a broad classification.

Which companies should care

Organizations and service providers operating affected FortiOS 7.6.0–7.6.1, 7.4.0–7.4.6, 7.2.0–7.2.13, 7.0.0–7.0.19, or 6.4.0–6.4.16 devices.

Business risk

Attacker persistence can survive an incomplete remediation, leaving perimeter trust, administrator credentials, configuration, sessions, routing, and connected networks at risk.

What to monitor

Move 7.6 to 7.6.2+ and 7.4 to 7.4.7+; obtain supported migration guidance for listed older branches; preserve evidence; review filesystem and configuration integrity, accounts, sessions, credential use, outbound traffic, and downstream access.

IntelliOS coverage
Technology

SonicWall SMA1000 6210, 7210, 8200v · CVE-2026-15409 / CVE-2026-15410[1][2][3][4][18]First cited source May 2026 · Latest cited source Jul 24, 2026

Exploitable condition

Unauthenticated SSRF/WebSocket proxy access can reach an appliance workflow where the second, authenticated-admin flaw enables path traversal and command execution. The chain can end in root-level appliance control.

Which companies should care

Organizations using SMA1000 for enterprise remote access, including managed and distributed environments.

Business risk

Credential, session, and TOTP theft; appliance malware; lateral movement; ransomware initial access; prolonged identity and network-trust recovery.

What to monitor

Owned models and fixed releases; historical WorkPlace/local-control activity; configuration changes; new users; credential access; outbound traffic; appliance-sourced lateral movement.

IntelliOS coverage
Technology

Microsoft SharePoint Server (on premises) · CVE-2026-50522 / 58644 / 56164 / 45659[1][14][15][20]First cited source Jul 14, 2026 · Latest cited source Jul 24, 2026

Exploitable condition

Current exploited vulnerabilities affect on-premises SharePoint trust and code-execution paths; Microsoft and partner advisories control applicability.

Which companies should care

Organizations running on-premises SharePoint for collaboration, records, intranet, or business workflows.

Business risk

Web-shell persistence, credential theft, document exposure, lateral movement, interruption, privacy response, and recovery of a highly trusted collaboration service.

What to monitor

Exact on-premises versions; emergency updates; web-shell and child-process evidence; credential use; configuration and service changes; outbound traffic; cloud/on-prem boundary accuracy.

IntelliOS coverage
Technology

Oracle PeopleSoft PeopleTools · CVE-2026-35273[1][6][7]First cited source Jun 10, 2026 · Latest cited source Jul 24, 2026

Exploitable condition

Unauthenticated network exploitation of affected PeopleTools versions; CISA marks known ransomware use.

Which companies should care

Higher education, government, healthcare, and enterprises using PeopleSoft for HR, payroll, student, finance, or administrative processes.

Business risk

Extortion, regulated-data theft, payroll or administrative disruption, credential exposure, notification, litigation, and restoration cost.

What to monitor

Affected versions; exploitation requests; unexpected processes and files; PeopleSoft administrative activity; data export; identity changes; extortion contact.

IntelliOS coverage
Technology

Check Point Security Gateway IKEv1 remote access · CVE-2026-50751[1][8][19]First cited source Jun 8, 2026 · Latest cited source Jul 24, 2026

Exploitable condition

Authentication bypass affects deprecated IKEv1 VPN configurations and is actively exploited.

Which companies should care

Organizations retaining legacy Check Point remote-access configurations.

Business risk

Unauthorized perimeter access, credential or session abuse, internal reconnaissance, data theft, ransomware deployment, and emergency VPN disruption.

What to monitor

IKEv1 configuration; hotfix status; unusual VPN authentications; new source geography; privileged access; lateral movement; Qilin-linked downstream behavior.

IntelliOS coverage
Technology

PTC Windchill / FlexPLM · CVE-2026-12569[1][9]First cited source Jun 18, 2026 · Latest cited source Jul 24, 2026

Exploitable condition

Remote code execution against affected PLM systems; vendor guidance includes web-shell hunting and CISA marks known ransomware use.

Which companies should care

Manufacturers, engineering firms, product companies, and suppliers using PLM for designs, bills of material, and collaboration.

Business risk

Intellectual-property theft, web-shell persistence, engineering outage, supplier compromise, contractual harm, and ransomware.

What to monitor

Versions and patches; vendor IOCs; web shells; unusual Java/process activity; new admin actions; bulk design export; supplier-account use.

IntelliOS coverage
Technology

Palo Alto PAN-OS GlobalProtect · CVE-2026-0257[1][11]First cited source Jun 3, 2026 · Latest cited source Jul 24, 2026

Exploitable condition

Authentication bypass affects specified GlobalProtect configurations; the vendor reports limited exploitation and CISA marks known ransomware use.

Which companies should care

Organizations using PAN-OS or Prisma Access for remote workforce access.

Business risk

Unauthorized access at the identity/network boundary, internal movement, data theft, ransomware, and loss of confidence in remote-access logs.

What to monitor

Affected versions and configuration; fixes; historical VPN sessions; impossible travel; new users/tokens; configuration drift; internal access from the appliance.

IntelliOS coverage
Technology

Langflow AI workflow servers · CVE-2026-0770[1][5]First cited source Jul 21, 2026 · Latest cited source Jul 24, 2026

Exploitable condition

Unauthenticated code execution through exec_globals handling can run in the server's root context.

Which companies should care

AI teams, developers, integrators, consultants, and organizations self-hosting Langflow to connect models, data, APIs, and agents.

Business risk

Root takeover, model/API secret theft, connected-service access, data exposure, workflow manipulation, lateral movement, and loss of trust in AI outputs.

What to monitor

Internet exposure; version and mitigation; validate-endpoint requests; child processes; secret reads; outbound connections; flow changes; downstream API activity.

IntelliOS coverage
Technology

SimpleHelp remote support · CVE-2026-48558[1][10]First cited source Jun 29, 2026 · Latest cited source Jul 24, 2026

Exploitable condition

OIDC authentication bypass affects specified 5.5 and pre-release 6.0 versions.

Which companies should care

Internal IT teams and MSPs using SimpleHelp to administer endpoints and customer systems.

Business risk

Remote administration takeover, multi-customer blast radius, tool-assisted persistence, credential access, ransomware, and service-provider liability.

What to monitor

Public servers; exact versions; OIDC configuration; administrative logins; newly enrolled devices/users; remote sessions; client-wide unusual commands.

IntelliOS coverage
Technology

Nx Console for VS Code · CVE-2026-48027 / malicious v18.95.0[1][12][13]First cited source May 21, 2026 · Latest cited source Jul 24, 2026

Exploitable condition

A malicious marketplace release compromised developer workstations and could expose GitHub and CI/CD trust.

Which companies should care

Software developers and organizations using Nx, VS Code, GitHub, package registries, and automated build/deploy systems.

Business risk

Developer-machine compromise, repository and CI/CD secret theft, malicious code changes, software supply-chain propagation, and downstream customer impact.

What to monitor

Extension history; affected workstation inventory; repository tokens; GitHub activity; CI/CD secret use; package publication; code changes; rebuilt endpoints.

IntelliOS coverage
Technology

FortiSandbox · CVE-2026-25089 / CVE-2026-39808[1][16]First cited source Jul 16, 2026 · Latest cited source Jul 24, 2026

Exploitable condition

Actively exploited vulnerabilities affect a security-analysis appliance; Fortinet controls affected versions and fixes.

Which companies should care

Enterprises, MSSPs, and security operations teams using FortiSandbox for malware analysis and security integration.

Business risk

Compromise of a trusted security control, analysis data exposure, management access, detection impairment, and a foothold inside the security stack.

What to monitor

Models and versions; management exposure; administrative changes; child processes; new integrations; outbound traffic; altered analysis or detection behavior.

IntelliOS coverage
Technology

WebPros cPanel & WHM · CVE-2026-41940[1]Evidence dated Jul 24, 2026

Exploitable condition

Authentication bypass in a hosting control plane; CISA marks known ransomware campaign use.

Which companies should care

Hosting providers, web agencies, MSPs, and companies administering multiple sites and mail services through cPanel.

Business risk

Multi-tenant website and email compromise, credential theft, data destruction, ransomware, customer notification, and correlated portfolio loss.

What to monitor

Control-panel versions; admin authentications; new accounts/API tokens; site and mail configuration changes; backup access; cross-tenant activity.

IntelliOS coverage
Technology

Ivanti EPMM · CVE-2026-6973[1][17][21]First cited source May 7, 2026 · Latest cited source Jul 24, 2026

Exploitable condition

A serious flaw with an administrative-authentication prerequisite; Ivanti reports very limited known exploitation.

Which companies should care

Organizations using EPMM to manage mobile devices, policies, certificates, and enterprise access.

Business risk

Privileged mobile-management compromise, policy and certificate abuse, device fleet disruption, credential access, and difficult trust recovery.

What to monitor

Affected versions; admin account history; fixes; unexpected policy/certificate changes; enrollment activity; configuration exports; managed-device anomalies.

IntelliOS coverage

Source-Bound Exposure and Targeting

Victimology Matrix

This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.

Victim / exposure populationFortiOS owners with historical internet exposure[1][24]First cited source Jul 24, 2026 · Latest cited source 2026-07-27 KEV actionSectorsCross-industry; MSP, network, security, government, healthcare, finance, manufacturing, and professional servicesGeographyGlobalConfirmation statusFortinet and CISA establish affected products and exploitation; neither source publishes a named-victim list for CVE-2025-68686.How companies should use itIdentify affected and previously exposed devices, open forensic triage where compromise could predate the fix, and recover credentials and downstream trust according to evidence.
Victim / exposure populationNational Association of Insurance Commissioners (NAIC)[7][22]First cited source Jun 11, 2026 · Latest cited source Jun 17, 2026SectorsInsurance regulation, financial services, and standardsGeographyUnited StatesConfirmation statusNamed victim; NAIC says the incident resulted from the broad PeopleSoft zero-day campaign and describes the systems and data reached. Third-party ShinyHunters attribution and volume claims remain separate.How companies should use itTreat exposed PeopleSoft as a path beyond HR or finance records: scope credentials, internal storage, automation, regulatory data, and dependent publication workflows.
Victim / exposure populationUniversity of Nottingham[7][23]First cited source Jun 11, 2026 · Latest cited source Jun 12, 2026SectorsHigher educationGeographyUnited Kingdom, with Malaysia and China campus implications reported separatelyConfirmation statusNamed organization with a public institutional disclosure confirming significant student-record data access by an external party. Mandiant controls the broader UNC6240/ShinyHunters PeopleSoft campaign assessment; actor claims are not treated as university-confirmed.How companies should use itUniversities should scope students, alumni, applicants, staff, finance, identity, and international-campus data connected to PeopleSoft and preserve evidence before restoring service.
Victim / exposure populationNx and users exposed to Nx Console v18.95.0[12][13]First cited source May 21, 2026 · Latest cited source May 28, 2026SectorsSoftware development, technology, and any organization operating CI/CDGeographyGlobal Visual Studio Marketplace and Open VSX distributionConfirmation statusNamed first-party incident; Nx says a compromised contributor path enabled publication of a malicious extension and directs anyone exposed during the distribution window to treat the developer machine as compromised.How companies should use itIdentify affected developer machines, rotate every reachable repository, cloud, package, CI/CD, SSH, and vault credential, validate code integrity, and examine downstream releases.
Victim / exposure populationRemote-workforce organizations[2][3][8][10][11]First cited source Jun 3, 2026 · Latest cited source Jul 17, 2026SectorsCross-industry enterprise, government, healthcare, education, professional servicesGeographyGlobalConfirmation statusConfirmed product targeting across SonicWall, Check Point, Palo Alto, and SimpleHelp; not a named-victim census.How companies should use itInventory every internet-facing remote-access path and validate historical trust, not only patch status.
Victim / exposure populationOther PeopleSoft operators not publicly named[6][7]First cited source Jun 10, 2026 · Latest cited source Jun 11, 2026SectorsEducation, government, insurance, HR, finance, and administrative servicesGeographyPrimarily U.S. reporting with global product relevanceConfirmation statusMandiant notified more than 100 organizations whose IP addresses correlated with potentially vulnerable endpoints and reported a 68% higher-education concentration. Notification or exposure does not prove every organization was compromised.How companies should use itPrioritize PeopleTools ownership, sensitive-data scope, extortion readiness, and identity recovery without converting aggregate notification into a victim list.
Victim / exposure populationManufacturers and engineering supply chains[1][9]First cited source Jun 18, 2026 · Latest cited source Jul 24, 2026SectorsManufacturing, aerospace, automotive, consumer products, suppliersGeographyGlobalConfirmation statusProduct-function victimology inferred from Windchill/FlexPLM ownership; no universal compromise claim.How companies should use itProtect designs, product data, supplier access, and engineering continuity; hunt web shells when exposure preceded the fix.
Victim / exposure populationMSPs, hosting providers, and remote-support operators[1][10]First cited source Jun 29, 2026 · Latest cited source Jul 24, 2026SectorsManaged services, IT support, hosting, web servicesGeographyGlobalConfirmation statusSimpleHelp and cPanel are multi-customer control planes; blast-radius assessment is architectural, not a reported victim count.How companies should use itModel cross-customer compromise, privileged-tool abuse, notification, and correlated loss.
Victim / exposure populationSelf-hosted AI workflow operators[1][5]First cited source Jul 21, 2026 · Latest cited source Jul 24, 2026SectorsTechnology, consulting, government, research, SMB and enterprise innovation teamsGeographyGlobalConfirmation statusLangflow ownership profile and business impact are architectural; CISA/NVD control active exploitation, not a named-victim list.How companies should use itFind exposed instances and map every model, API, secret, data, and automation connection before declaring containment.

Distinct Operational Records

Exploitation Campaigns & Operational Clusters

UTA0533 SMA1000 zero-day activity

Volexity's separate cluster label covers observed exploitation, appliance malware, credential gathering, and attempted lateral movement. Public evidence does not prove UTA0533 equals INC Ransom.[2][3][4]First cited source Jul 14, 2026 · Latest cited source Jul 21, 2026

UNC6240 / ShinyHunters PeopleSoft extortion

Mandiant connects PeopleSoft exploitation to an education-focused data-theft and extortion campaign.[6][7]First cited source Jun 10, 2026 · Latest cited source Jun 11, 2026

Qilin-associated Check Point exploitation

Check Point makes a medium-confidence assessment of financially motivated activity associated with Qilin; CISA independently marks ransomware use.[1][8]First cited source Jun 8, 2026 · Latest cited source Jul 24, 2026

Nx Console / TeamPCP supply-chain operation

The malicious developer extension and connected repository activity turn a single workstation into a potential CI/CD and downstream software event.[12][13]First cited source May 21, 2026 · Latest cited source May 28, 2026

Source-Bound Actor Context

Threat Actors & Attribution Boundaries

UTA0533

Volexity's activity-cluster label for observed SMA1000 exploitation. Keep separate from INC unless new source-backed attribution closes the gap.[3]Evidence dated Jul 17, 2026

UNC6240 / ShinyHunters

Mandiant's tracking connects the PeopleSoft campaign to data theft and extortion, especially in education.[7]Evidence dated Jun 11, 2026

Qilin ransomware ecosystem

Check Point assesses the IKEv1 VPN campaign connection with medium confidence; this does not attribute every exploit attempt.[8][19]First cited source Jun 8, 2026 · Latest cited source Jul 2026

TeamPCP / Megalodon supply-chain operators

The Nx incident illustrates how developer tools and marketplace trust can become an initial-access and credential-theft pathway.[12][13]First cited source May 21, 2026 · Latest cited source May 28, 2026

Malware, Implants, and Intrusion Tooling

Malware Summary

Source-backed malware and malicious tooling named in the retained campaigns. The table distinguishes malware families, open-source tools, custom implants, exploit or collection tooling, and reported outcomes that lack a publicly identified sample.

Malware / toolingKNUCKLEBALL / ORANGETAIL / Suo5[3]Evidence dated Jul 17, 2026Classification and campaignSMA1000-focused malware and toolingVolexity reports appliance-specific malware and supporting tools during UTA0533-tracked activity.Capability and potential impactSupports persistence, credential access, traffic handling, and movement from a trusted remote-access appliance.What defenders should monitorVendor and responder indicators; unexpected appliance files/processes; altered configuration; outbound traffic; credential access; lateral movement.
Malware / toolingWeb shells[9][15]First cited source Jun 18, 2026 · Latest cited source Jul 16, 2026Classification and campaignServer-side persistencePTC directs exposed Windchill/FlexPLM owners to hunt for web-shell evidence; similar persistence is relevant to exploited collaboration servers.Capability and potential impactMaintains remote command access after patching and can enable credential theft, data staging, and lateral movement.What defenders should monitorNew or modified web-accessible files; child processes; unusual HTTP requests; encoded commands; outbound connections; account changes.
Malware / toolingQilin ransomware[8][19]First cited source Jun 8, 2026 · Latest cited source Jul 2026Classification and campaignRansomware and data-extortion ecosystemCheck Point assesses a medium-confidence association with exploitation of CVE-2026-50751.Capability and potential impactCan turn edge access into data theft, encryption, operational interruption, ransom pressure, legal response, and recovery cost.What defenders should monitorVPN-originated reconnaissance; credential access; privileged movement; exfiltration; backup/hypervisor access; encryption precursors.
Malware / toolingMalicious Nx Console extension[12][13]First cited source May 21, 2026 · Latest cited source May 28, 2026Classification and campaignSoftware supply-chain implantNx confirms malicious v18.95.0 distribution through extension marketplaces.Capability and potential impactCompromises developer endpoints and can expose repository, package, cloud, and CI/CD credentials.What defenders should monitorExtension installation history; affected endpoints; secret use; GitHub and build logs; package publication; unexpected code changes.

Enterprise Exposure

Technology Classes & Trust Boundaries

Edge and remote administration

FortiOS, SonicWall, Check Point, Palo Alto, SimpleHelp, and Ivanti should be governed as privileged access systems whose compromise may require credential and downstream trust recovery.[2][3][8][10][11][17][24]First cited source May 7, 2026 · Latest cited source 2026-07-27 KEV action

Business data and workflow concentration

PeopleSoft, Windchill/FlexPLM, and SharePoint hold data and workflows that create immediate extortion, privacy, contractual, and interruption consequences.[6][7][9][14][15]First cited source Jun 10, 2026 · Latest cited source Jul 16, 2026

Developer and AI trust chains

Nx Console and Langflow can expose code, secrets, cloud access, model credentials, connected services, and trusted automation.[5][12][13]First cited source May 21, 2026 · Latest cited source Jul 21, 2026

Security and hosting control planes

FortiSandbox and cPanel show how an attacker can compromise systems expected to analyze threats or administer many customer services.[1][16]First cited source Jul 16, 2026 · Latest cited source Jul 24, 2026

Current Carry-Forward Watchlist

Top 10 Specific Threats to Monitor

Prioritized source-backed developments that convert the rolling activity record into named operational monitoring requirements.

1Threat / Category

Network edge

Fortinet FortiOS[1][24][25]First cited source Jul 24, 2026 · Latest cited source Current definition checked 2026-07-28

Why it mattersCVE-2025-68686 can bypass a prior fix for symbolic-link persistence after filesystem-level compromise. Track its KEV status, 5.9 Medium vector, and broad CWE-200 mapping as separate fields.What to monitorAffected and historical versions, fixed-branch migration, filesystem and configuration integrity, accounts, sessions, credential access, outbound traffic, and downstream network activity.IntelliOS coverage
2Threat / Category

Remote access

SonicWall SMA1000[2][3][4]First cited source Jul 14, 2026 · Latest cited source Jul 21, 2026

Why it mattersObserved zero-day exploitation reached credentials and internal movement.What to monitorModels, versions, historical appliance activity, configuration change, secrets, outbound traffic, and lateral movement.IntelliOS coverage
3Threat / Category

Collaboration

On-premises SharePoint[14][15][20]First cited source Jul 14, 2026 · Latest cited source Jul 20, 2026

Why it mattersCurrent exploitation affects a high-trust document and workflow system.What to monitorExact on-prem versions, patches, web shells, child processes, credentials, and egress.IntelliOS coverage
4Threat / Category

Enterprise app

Oracle PeopleSoft[6][7]First cited source Jun 10, 2026 · Latest cited source Jun 11, 2026

Why it mattersShinyHunters-linked extortion targets sensitive administrative data.What to monitorAffected PeopleTools, exploit traffic, file/process changes, data export, and extortion.IntelliOS coverage
5Threat / Category

VPN

Check Point IKEv1[8]Evidence dated Jun 8, 2026

Why it mattersActive exploitation is assessed with medium confidence as Qilin-associated.What to monitorDeprecated IKEv1, hotfix, unusual VPN access, internal movement, and Qilin precursors.IntelliOS coverage
6Threat / Category

PLM

PTC Windchill / FlexPLM[1][9]First cited source Jun 18, 2026 · Latest cited source Jul 24, 2026

Why it mattersKnown ransomware use threatens intellectual property and engineering continuity.What to monitorPatch, web shells, bulk export, supplier-account activity, and process anomalies.IntelliOS coverage
7Threat / Category

VPN

Palo Alto GlobalProtect[1][11]First cited source Jun 3, 2026 · Latest cited source Jul 24, 2026

Why it mattersLimited exploitation plus CISA ransomware marking elevates historical access review.What to monitorAffected configuration, sessions, tokens, new accounts, and appliance-origin movement.IntelliOS coverage
8Threat / Category

AI infrastructure

Langflow[1][5]First cited source Jul 21, 2026 · Latest cited source Jul 24, 2026

Why it mattersRoot execution can expose secrets and connected automation.What to monitorExposure, version, validate requests, child processes, secret reads, flow changes, and outbound calls.IntelliOS coverage
9Threat / Category

Remote support

SimpleHelp[1][10]First cited source Jun 29, 2026 · Latest cited source Jul 24, 2026

Why it mattersA remote-support authentication bypass can create multi-endpoint or multi-customer impact.What to monitorVersion, OIDC, admins, devices, sessions, and unusual remote commands.IntelliOS coverage
10Threat / Category

Software supply chain

Nx Console[12][13]First cited source May 21, 2026 · Latest cited source May 28, 2026

Why it mattersA malicious extension requires workstation, secret, repository, and release-integrity response.What to monitorAffected endpoints, credentials, GitHub, builds, packages, and code changes.IntelliOS coverage
11Threat / Category

Control plane

FortiSandbox, cPanel, and Ivanti EPMM[1][16][17][21]First cited source May 7, 2026 · Latest cited source Jul 24, 2026

Why it mattersTrusted security, hosting, and mobile-management systems can create correlated or privileged impact.What to monitorVersions, management exposure, admin activity, configuration change, secrets, tenants, and managed devices.IntelliOS coverage

Operational Standards from the Evidence

Best Practices and Lessons Learned

The practices below convert the retained public evidence into repeatable executive standards. Each lesson remains bounded to its cited sources.

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026
  1. 1

    Best Practice

    Maintain an ownership-grade product inventory[1]Evidence dated Jul 24, 2026

    Lesson Learned

    A CVE cannot be actioned when the company knows a category but not the exact product, model, version, exposure, business owner, and service dependency.

    Minimum Operating Standard

    For every named technology, record owner, model/version, internet reachability, vendor/MSP responsibility, business service, data, credentials, and recovery tier.

  2. 2

    Best Practice

    Separate vulnerability closure from incident closure[2][3][9][13][15]First cited source May 21, 2026 · Latest cited source Jul 17, 2026

    Lesson Learned

    Patching prevents a future exploit attempt; it does not prove the appliance or server was not compromised before the fix.

    Minimum Operating Standard

    Define exposure, missing-log, persistence, credential-access, and anomalous-admin triggers that automatically open incident response.

  3. 3

    Best Practice

    Rotate secrets by reachable blast radius[3][5][12][13]First cited source May 21, 2026 · Latest cited source Jul 21, 2026

    Lesson Learned

    Edge, AI, developer, and management systems can access more credentials than their local operating system suggests.

    Minimum Operating Standard

    Map and rotate appliance credentials, sessions, tokens, certificates, API keys, repository secrets, model keys, and downstream service identities when exposure warrants it.

  4. 4

    Best Practice

    Preserve product and attribution boundaries[1][3][8][15][18]First cited source May 2026 · Latest cited source Jul 24, 2026

    Lesson Learned

    Cloud and on-prem products, activity-cluster labels, ransomware fields, and carrier cohorts answer different questions.

    Minimum Operating Standard

    Every executive statement must name the affected product, source, confidence, observation date, and whether it describes exploitation, attribution, victim outcome, or historical loss.

  5. 5

    Best Practice

    Test recovery of trust, not only service[3][9][13][21]First cited source May 21, 2026 · Latest cited source Jul 17, 2026

    Lesson Learned

    A restored VPN, PLM, collaboration, or AI service can still carry stolen credentials, persistence, or corrupted workflows.

    Minimum Operating Standard

    Rebuild or validate the system, rotate secrets, examine downstream access, test backups, and obtain an evidence-based return-to-service decision.

Automation Transparency

AI Agent Run Status

AgentExploitable Technology Risk Rolling Intelligence Card Publisher
StatusActive · rolling 90-day automation
CadenceWeekly on Friday at 1:00 PM ET
Previous run24 Jul 2026 · 1:00 PM ET · Run exploitable-technology-risk-2026-07-24-1300
Previous resultThe rolling window was refreshed through July 28; 70 KEVs were normalized into 54 product-family ownership questions and FortiOS CVE-2025-68686 was promoted as a remediation-plus-forensics priority.
What the previous run found
  • Reviewed every existing IntelliOS Rolling Intelligence Card, linked CVE/KEV record, campaign/actor relationship, and Flash Threat Brief.
  • Retained 26 controlling or decision-relevant sources after checking government, canonical CVE/CWE, vendor, victim, IR, exposure, insurance, news, community, and internal discovery tiers.
  • Added Fortinet’s CVE-2025-68686 affected and fixed releases, CISA’s BOD 26-04 forensic-triage requirement, the CNA's CVSS 5.9 vector, and MITRE's CWE-200 definition and mapping caution.
  • Kept severity, CWE classification, exploitation, attribution, victim, and loss evidence separate; no named victim or actor is asserted for CVE-2025-68686.
Next run31 Jul 2026 · 1:00 PM ET
Sources monitored
  • CISA KEV plus NVD/CVE severity, vector, and CWE fields
  • MITRE CWE definitions and mapping guidance
  • National CSIRTs, CERTs, and multinational advisories
  • Vendor PSIRTs, release notes, postmortems, and fixed-version guidance
  • Incident responders, threat research, exposure monitoring, ransomware research, and insurer security advisories
  • All IntelliOS Rolling Intelligence Cards, CVE/KEV Cards, campaigns, actors, PANDA briefs, Page Alerts, and Forge registry
  • PETRA rolling-window query and IntelliOS vulnerability-exposure source trackers
  • PETRA report database query constrained to the active rolling 90-day publication window; older reports remain discovery-only
Publication and alert policyPublish and alert only when a source-backed change adds or removes a named product, changes exploitation or ransomware status, materially changes affected versions or remediation, identifies a campaign or victimology shift, or alters the executive action standard. Suppress routine no-change email.

Related Intelligence and CARDS Records

Other IntelliOS Products

PANDA CVE Watch Brief

CVE-2025-68686 — FortiOS Persistence Patch Bypass

Affected releases, KEV deadline, technical prerequisite, hunting questions, and remediation requirements.

Open product

PANDA Flash Threat Brief

FortiOS Persistence Bypass Under Active Exploitation

Executive and operational response to a FortiOS post-compromise persistence bypass.

Open product

PANDA Flash Threat Brief

SonicWall SMA1000 / INC Ransom Exploitation

Detailed chain, attribution boundaries, incident response, malware, and campaign context.

Open product

PANDA Flash Threat Brief

Langflow AI Workflow Servers Under Active Exploitation

Plain-English business impact, vendor context, scenarios, and response guidance.

Open product

Rolling Intelligence

Government Cybersecurity Actions & Advisories

Official government notices, exploited technologies, actor campaigns, and deadlines across the same rolling window.

Open product

Rolling Intelligence

Cyber Insurance Claims, Coverage & Underwriting

Carrier loss experience, policyholder technology risk, claims readiness, and accumulation context.

Open product

CARDS

CVE / KEV Cards

Searchable vulnerability records for the named CVEs and their connected actors, campaigns, and products.

Open product

CARDS Actor Record

Qilin Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

UTA0533 Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Campaign Record

Sonicwall Sma1000 Zero Day Exploitation Campaign Card

Connected campaign intelligence, activity timeline, affected technologies, actors, techniques, and source boundaries.

Open product

CARDS CVE / KEV Record

CVE-2025-68686 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-15409 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-15410 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-35273 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-50751 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-12569 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-0257 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-0770 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-48558 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-48027 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-25089 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-39808 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-41940 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-6973 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

Publication History

Version Change Log

Versionv5Date28 Jul 2026ChangeAdded CISA KEV and official CWE as paired discovery fields. The card now retains NVD/CNA severity and vector data, links official MITRE CWE definitions, uses CWE for weakness-pattern discovery, and explicitly prevents a broad CWE label from being treated as exploitation evidence or a precise root-cause finding. Expanded CVE-2025-68686 analysis with CVSS 5.9 and CWE-200 context.MonitoringDaily CISA KEV and NVD/CVE/CWE reconciliation plus weekly Friday material-change review
Versionv4Date28 Jul 2026ChangeAdvanced the window to Apr 30–Jul 28, recalculated KEV totals, and added FortiOS CVE-2025-68686 throughout the timeline, BLUF, executive summary, watchlist, victimology, monitoring priorities, linked products, and CVE relationships. The response now explicitly pairs fixed-release migration with forensic triage after historical exposure.MonitoringDaily CISA KEV check plus weekly Friday material-change review
Versionv3Date24 Jul 2026ChangeRebuilt the Victimology Matrix to prefer publicly named organizations. Added source-qualified rows for the NAIC, University of Nottingham, and Nx/Nx Console; retained narrow population rows only when the public record did not identify reliable victims.MonitoringWeekly Friday material-change review
Versionv2Date24 Jul 2026ChangeTightened Research Framing to the established IntelliOS reading standard: shorter question and scope statements plus a counts-first source-coverage table, while preserving the complete Tier 0–8 source audit in the underlying record.MonitoringWeekly Friday material-change review
Versionv1Date24 Jul 2026ChangeLaunched the rolling 90-day Exploitable Technology Risk intelligence product with tiered source accounting, cross-product evidence reconciliation, a normalized named-technology watchlist, executive analysis, victimology, campaign and actor context, malware coverage, monitoring priorities, Page Alerts, and weekly AI review.MonitoringWeekly Friday material-change review

Citations

Retained Sources and Claim Treatment

Source1PublisherCybersecurity and Infrastructure Security AgencyPublished2026-07-24Publication / evidenceSource indexofficialWhy used / claim treatmentControlling source for the 70 rolling-window KEV additions, 38 vendors, 53 vendor-product families, federal required-action dates, and eight entries marked for known ransomware use. KEV status proves exploitation evidence, not compromise of every deployment.SourceKnown Exploited Vulnerabilities Catalog — Apr 26–Jul 24, 2026 extract

https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

Source2PublisherSonicWall PSIRTPublished2026-07-14Publication / evidenceSource indexofficialWhy used / claim treatmentVendor advisory controlling affected SMA1000 models, fixed releases, and active exploitation of CVE-2026-15409 and CVE-2026-15410.SourceSMA 1000 Series Appliances Affected by Multiple Vulnerabilities

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

Source3PublisherVolexityPublished2026-07-17Publication / evidenceSource indexincident responseWhy used / claim treatmentFirst-hand incident-response reporting controlling UTA0533 observations, June 22 earliest observed compromise, SMA-specific malware, credential access, and attempted lateral movement. It does not prove UTA0533 is INC Ransom.SourceProxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/

Source4PublisherCanadian Centre for Cyber SecurityPublished2026-07-21Publication / evidenceSource indexofficialWhy used / claim treatmentPartner-government confirmation of vendor guidance and active exploitation. Retained for international corroboration and response urgency, not as a separate victim count.SourceSonicWall Security Advisory — AV26-699 Update 1

https://www.cyber.gc.ca/en/alerts-advisories/sonicwall-security-advisory-av26-699

Source5PublisherNational Vulnerability DatabasePublished2026-07-21Publication / evidenceSource indexofficialWhy used / claim treatmentGovernment vulnerability record used with CISA KEV for Langflow's unauthenticated root-context code-execution condition. The older discovery advisory remains background and is not counted as rolling-window evidence.SourceCVE-2026-0770 Detail and KEV Synchronization

https://nvd.nist.gov/vuln/detail/CVE-2026-0770

Source6PublisherOraclePublished2026-06-10Publication / evidenceSource indexofficialWhy used / claim treatmentVendor security alert controlling affected PeopleSoft PeopleTools versions and unauthenticated network exploitability.SourceOracle Security Alert Advisory — CVE-2026-35273

https://www.oracle.com/security-alerts/alert-cve-2026-35273.html

Source7PublisherGoogle Threat Intelligence Group / MandiantPublished2026-06-11Publication / evidenceSource indexincident responseWhy used / claim treatmentPrimary threat-intelligence reporting connecting CVE-2026-35273 exploitation to UNC6240/ShinyHunters, the May 27–June 9 activity window, extortion, and education-sector concentration.SourceShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/

Source8PublisherCheck PointPublished2026-06-08Publication / evidenceSource indexofficialWhy used / claim treatmentVendor advisory controlling the affected deprecated-IKEv1 configuration, active exploitation, remediation, and medium-confidence association with financially motivated Qilin ransomware activity.SourceActive Exploitation of Check Point VPN Authentication Bypass — CVE-2026-50751

https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/

Source9PublisherPTCPublished2026-06-18Publication / evidenceSource indexofficialWhy used / claim treatmentVendor notice controlling CVE-2026-12569 affected-product scope, patching, and web-shell hunting. CISA separately marks known ransomware campaign use.SourceCritical Windchill and FlexPLM Remote Code Execution Notice

https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability

Source10PublisherSimpleHelpPublished2026-06-29Publication / evidenceSource indexofficialWhy used / claim treatmentVendor guidance controlling affected 5.5 and pre-release 6.0 versions, the OIDC authentication-bypass condition, and fixed-version actions.SourceSimpleHelp OIDC Authentication Bypass — CVE-2026-48558

https://guides.simple-help.com/kb---security-vulnerabilities-05-2026

Source11PublisherPalo Alto NetworksPublished2026-06-03Publication / evidenceSource indexofficialWhy used / claim treatmentVendor advisory controlling affected PAN-OS and Prisma Access versions, limited exploitation, mitigations, and fixed releases. CISA marks known ransomware campaign use.SourcePAN-OS GlobalProtect Authentication Bypass — CVE-2026-0257

https://security.paloaltonetworks.com/CVE-2026-0257

Source12PublisherCybersecurity and Infrastructure Security AgencyPublished2026-05-28Publication / evidenceSource indexofficialWhy used / claim treatmentOfficial alert controlling the connection between the malicious Nx Console release, GitHub repository compromise, CI/CD secrets, and required developer-environment response.SourceSupply Chain Compromises Impact Nx Console and GitHub Repositories

https://www.cisa.gov/news-events/alerts/2026/05/28/supply-chain-compromises-impact-nx-console-and-github-repositories

Source13PublisherNxPublished2026-05-21Publication / evidenceSource indexofficialWhy used / claim treatmentFirst-party postmortem controlling the malicious version, marketplace exposure windows, safe releases, and instruction to treat affected developer machines as compromised.SourcePostmortem: Nx Console v18.95.0 Supply-Chain Compromise

https://nx.dev/blog/nx-console-v18-95-0-postmortem

Source14PublisherMicrosoft Security Response CenterPublished2026-07-14Publication / evidenceSource indexofficialWhy used / claim treatmentVendor advisory controlling affected on-premises SharePoint products, patch availability, and vulnerability scope.SourceCVE-2026-56164 Microsoft SharePoint Server Security Update

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-56164

Source15PublisherCanadian Centre for Cyber SecurityPublished2026-07-16Publication / evidenceSource indexofficialWhy used / claim treatmentOfficial partner-government alert retained to group the current on-premises SharePoint exploitation cluster and urgent response requirement.SourceCritical SharePoint Server Vulnerabilities — AL26-017

https://www.cyber.gc.ca/en/alerts-advisories/al26-017-critical-vulnerabilities-impacting-microsoft-sharepoint-server-cve-2026-56164-cve-2026-55040-cve-2026-58644

Source16PublisherFortinet PSIRTPublished2026-07-16Publication / evidenceSource indexofficialWhy used / claim treatmentVendor PSIRT index controlling FortiSandbox affected products and fixes; CISA controls the July 16 active-exploitation status for CVE-2026-25089 and CVE-2026-39808.SourceFortiSandbox PSIRT Advisories — CVE-2026-25089 and current exploited flaws

https://fortiguard.fortinet.com/psirt

Source17PublisherIvantiPublished2026-05-07Publication / evidenceSource indexofficialWhy used / claim treatmentVendor disclosure controlling affected EPMM versions, administrative-authentication prerequisite, and very limited known exploitation of CVE-2026-6973.SourceMay 2026 EPMM Security Update

https://www.ivanti.com/blog/may-2026-epmm-security-update

Source18PublisherAt-BayPublished2026-05Publication / evidenceSource indexprimary researchWhy used / claim treatmentCarrier claims analysis used as a current loss-driver baseline: remote access and named device exposure can translate into ransomware frequency and severity. Its underlying claims are from 2025 and are not treated as 90-day incident counts.Source2026 InsurSec Report — Ransomware and VPN Attack Trends

https://www.at-bay.com/wp-content/uploads/2026/04/At-Bay-2026-InsurSec-Report.pdf

Source19PublisherGuidePoint SecurityPublished2026-07Publication / evidenceSource indexprimary researchWhy used / claim treatmentQuarterly threat-research synthesis retained for ransomware-linked exploitation context, including Check Point CVE-2026-50751. Dataset and incident denominators remain separate from CISA and vendor records.SourceGRIT Q2 2026 Ransomware and Cyber Threat Insights

https://www.guidepointsecurity.com/wp-content/uploads/2026/07/GRIT_Q2_2026_Ransomware__Cyber_Threat_Insights_Report.pdf

Source20PublisherCERT-EUPublished2026-07-20Publication / evidenceSource indexofficialWhy used / claim treatmentEuropean institutional advisory retained for current SharePoint exploitation and remediation context. Microsoft remains controlling for product versions and fixes.SourceCritical Vulnerability in Windows SharePoint — CERT-EU Security Advisory 2026-004

https://cert.europa.eu/publications/security-advisories/2026-004/

Source21PublisherBeazley SecurityPublished2026-06Publication / evidenceSource indexincident responseWhy used / claim treatmentInsurer-aligned security advisory retained to translate vendor exposure into policyholder action; Ivanti remains controlling for affected versions and exploitation status.SourceCritical Vulnerabilities in Ivanti Sentry and EPMM

https://beazley.security/alerts-advisories/critical-vulnerabilities-in-ivanti-sentry-epmm-cve-2026-6973-cve-2026-10727-cve-2026-10520-cve-2026-10523

Source22PublisherNational Association of Insurance CommissionersPublished2026-06-17Publication / evidenceSource indexofficialWhy used / claim treatmentFirst-party named-victim disclosure confirming that the NAIC incident resulted from the broad PeopleSoft zero-day campaign. NAIC controls its incident facts and affected-data description; third-party actor attribution and volume claims remain separate.SourceSecurity Update — PeopleSoft Zero-Day Incident

https://content.naic.org/about/security-update

Source23PublisherUniversity of Nottingham Students’ UnionPublished2026-06-12Publication / evidenceSource indexofficialWhy used / claim treatmentPublic institutional disclosure naming the University of Nottingham and confirming unauthorized third-party access to a significant amount of data in the student-record system. Mandiant separately controls the broader PeopleSoft campaign attribution; threat-actor data-volume claims are not treated as institution-confirmed.SourceUniversity of Nottingham Data Breach

https://su.nottingham.ac.uk/news/article/data-breach

Source24PublisherCybersecurity and Infrastructure Security AgencyPublished2026-07-27 KEV actionPublication / evidenceSource indexofficialWhy used / claim treatmentGovernment implementation guidance controlling public-exposure treatment and the requirement to pair KEV remediation with forensic triage. It does not establish compromise of every affected FortiOS asset.SourceBOD 26-04 Implementation Guidance and Forensics Triage Requirements

https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk

Source25PublisherMITREPublishedCurrent definition checked 2026-07-28Publication / evidenceSource indexofficialWhy used / claim treatmentWeakness taxonomy retained to explain Fortinet's CWE-200 mapping. MITRE marks this broad category as discouraged for precise root-cause mapping; it describes unauthorized information exposure and does not independently establish exploitation, the underlying coding error, or local impact.SourceCWE-200 — Exposure of Sensitive Information to an Unauthorized Actor

https://cwe.mitre.org/data/definitions/200.html