IntelliOS Threat Intel Operating System
IntelliOSRolling Intelligence|AIRolling Government Advisory Watch

Government Cybersecurity Actions & Advisories Rolling Intelligence Card

AI-generated, AI-updated weekly, AI quality-checked, and source-cited, this 90-day Rolling Intelligence Card reviews CISA, FBI, NSA, DOJ, UK NCSC, Europol, ASD ACSC, sector agencies, partner governments, and qualified supporting reporting. It reconciles overlapping notices and promotes only exploited technologies, threat actors, campaigns, victimology, deadlines, and government actions that materially change company risk.

Coverage
Apr 30–Jul 28, 2026
Record Version
v32
Updated
Jul 28, 2026
AI Monitor
Weekly · Thu midday ET
Evidence
13 Retained Sources
Product
Rolling Intelligence Card
Classification
TLP:CLEAR

Research Framing

Reporting-Period Statistics

Rolling 90-Day Intelligence Snapshot

At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.

Period Coverage

Apr 30, 2026Jul 28, 2026

90 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.

90-day windowWeekly on Thursday at midday ET across U.S. and international government source streams, with one cumulative rolling 90-day analysis. Each run adds qualifying new evidence and removes evidence that has aged beyond the active window.

90d[1][2][3][4][9]

Coverage model

One cumulative window advances daily across CISA, FBI, NSA, DOJ, UK NCSC, Europol, partner-government, vendor, and retained research sourcesFirst cited source Jun 2026 · Latest cited source Jul 23, 2026

Weekly[1][2][3][4][6][7][8][9]

Collection cadence

Official U.S. and international sources are reviewed every Thursday; qualifying vendor, incident-response, and corroborating evidence is retained with source roles preservedFirst cited source Jun 2026 · Latest cited source Jul 23, 2026

Continuous[1]

KEV operating model

Each new CISA KEV enters asset discovery, exposure, ownership, remediation, and—when historical reachability exists—incident investigationEvidence dated Jun 2026

5[1][2][3][4][13]

Government action lanes

CISA exploitation evidence; FortiOS post-compromise forensic triage; FBI/NSA/CISA hardening guidance; DOJ-led U.S. disruption; and Europol or partner-government international actionFirst cited source Jun 2026 · Latest cited source Jul 27, 2026

Retained evidence source mix

Official government and vendor publications dominate the retained record; supporting research is preserved as a separate evidence class.[1][2][3][4][5][6][7][8][9][10][11][12][13]First cited source Jun 2026 · Latest cited source Jul 27, 2026

Official government / vendor15
Primary research1
Incident response1
Ecosystem monitor1

Intended Reader and Decision Context

Persona / Audience

Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.

Audience fieldPrimary audienceAssessmentU.S.-based executives, board and risk leaders, CISOs, CIOs, security directors, and operational owners who need a decision-ready view of government-reported cyber activity.
Audience fieldOrganization profileAssessmentDesigned first for small and midsize businesses and midmarket organizations, while remaining applicable to enterprises, critical-infrastructure operators, managed service providers, and organizations with internet-facing IT or operational-technology control systems.
Audience fieldGeographic orientationAssessmentU.S.-oriented in its executive decisions, KEV implications, and company-risk framing. International government reporting is incorporated when it identifies campaigns, actors, exploited technologies, victim patterns, or disruption activity relevant to U.S. organizations.
Audience fieldFunctional readersAssessmentExecutive leadership; vulnerability and exposure management; security operations; incident response; IT and OT operations; identity teams; vendor and third-party risk; legal, compliance, communications, and insurance stakeholders.
Audience fieldDecision perspectiveAssessmentWritten to translate government notices into company-specific exposure, investigation, ownership, monitoring, and escalation decisions—not to reproduce an agency-news digest or provide a federal-only compliance checklist.
Audience fieldExpected useAssessmentUse the brief to turn specific notices—such as a CISA KEV addition, an FBI/NSA/CISA joint warning, a DOJ disruption, or a UK NCSC campaign attribution—into asset priorities, accountable owners, incident-response thresholds, internal telemetry requirements, and connected IntelliOS products.

Chronology and Decision Milestones

Timeline of Notable Activity

Observed activity, public disclosure, KEV catalog action, and required-action deadlines are labeled separately. Later reporting is not backdated to imply that it was public on the underlying activity date.

  1. KEV deadline cycle

    June opens with an exploited Oracle WebLogic vulnerability

    CISA added CVE-2024-21182 to KEV with a June 4 required-action date, establishing the month’s first three-day federal remediation window.[1]

  2. Critical-infrastructure guidance

    U.S. agencies publish joint automatic-tank-gauge hardening guidance

    NSA, CISA, FBI, DOE, EPA, TSA, DOT, and USDA warned that unattributed actors had compromised and modified internet-exposed automatic tank gauges, then called for owners to identify, isolate, and harden these operational-technology systems.[2]

  3. Public-private disruption

    DOJ reports Scam Center Disruption Week results

    DOJ announced that FBI, Secret Service, and HSI target information—combined with foreign-law-enforcement and named private-sector action—helped disrupt more than 1.4 million accounts and freeze more than $3.8 million in cryptocurrency.[3]

  4. Enterprise application KEV

    Oracle PeopleSoft exploitation receives a three-day deadline

    CISA added CVE-2026-35273 to KEV with a June 15 required-action date. The exploited HTTP-takeover condition affects PeopleSoft PeopleTools, a platform commonly trusted with HR, finance, identity, and administrative workflows; asset ownership and prior internet exposure therefore matter as much as the patch ticket.[1]

  5. Network control-plane KEV

    Cisco SD-WAN Manager and LiteSpeed vulnerabilities enter KEV

    CISA added Cisco Catalyst SD-WAN Manager CVE-2026-20262 and LiteSpeed cPanel Plugin CVE-2026-54420. The Cisco flaw permits arbitrary file write in a distributed network control plane, while the LiteSpeed entry raises privilege and shared-hosting concerns; both reinforce that trusted administrative reach should drive priority.[1]

  6. Government campaign warning

    UK NCSC warns on global Fortinet gateway credential targeting

    The NCSC described a global campaign using brute force, dictionary attacks, credential stuffing, and leaked credential material against internet-facing FortiGate firewalls and SSL VPN gateways. The notice creates a credential-rotation, session-review, MFA, and management-interface decision—not merely a firmware check.[10]

  7. Operation Endgame precursor

    Dutch authorities detail the SocGholish delivery ecosystem

    Dutch police and prosecutors described SocGholish/FakeUpdates delivery through compromised WordPress sites, its relationship to Evil Corp, and remediation of 14,971 infected websites. That victim-notification and website-remediation context explains the infrastructure targeted in the broader June 24 Operation Endgame action.[11]

  8. Observed compromise

    Earliest publicly reported evidence of the SMA1000 campaign

    Volexity identified June 22 as the earliest sign of compromise in the activity it tracks as UTA0533, including rootrun execution associated with the KNUCKLEBALL backdoor. The observed chain included appliance compromise, credential and session access, and follow-on activity; June 22 is an activity date, not the later public-disclosure date.[8]

  9. Largest June KEV batch

    Industrial and network-management products receive urgent deadlines

    CISA added four vulnerabilities—the window’s largest single-day retained batch—including Lantronix EDS5000 and three Ubiquiti UniFi OS entries, all with June 26 required-action dates. The three-day window concentrated asset discovery, public-interface validation, configuration review, and remediation across industrial and distributed network-management systems.[1]

  10. International disruption

    Operation Endgame targets three malware ecosystems

    Europol and international partners announced action against servers, domains, infected websites, credentials, and criminal assets supporting SocGholish, Amadey, and StealC. Microsoft separately described the distinct delivery, credential-theft, fraud, and ransomware-enablement roles of Amadey and StealC. The action created a retro-hunting and credential-reset window; it did not establish permanent eradication.[4][11][12]

  11. Remote-management KEV

    SimpleHelp authentication bypass closes the June cohort

    CISA added SimpleHelp CVE-2026-48558 with a July 2 required-action date. Because one remote-support server can administer many endpoints or customer environments, the required response includes administrator and session review, endpoint fan-out analysis, and investigation of the historical exposure window.[1]

  12. Disclosure and KEV escalation

    SonicWall SMA1000 vulnerabilities are disclosed and added to KEV

    SonicWall published its advisory and CISA added CVE-2026-15409 and CVE-2026-15410 with a July 17 deadline. The chain uses unauthenticated server-side request forgery to reach a privileged internal workflow, then abuses the authenticated-administrator hotfix-removal path for traversal and command execution as root. The second flaw is post-authentication when considered alone.[1][6]

  13. Technical disclosure

    Volexity publishes its UTA0533 incident-response findings

    Volexity documented the SMA1000 exploitation path, root-level execution, KNUCKLEBALL and related tooling, credential, session, and TOTP access, and appliance-sourced follow-on activity. The report preserves UTA0533 as a source-specific cluster label and does not equate it with INC Ransom.[8]

  14. AI infrastructure KEV

    CISA adds Langflow CVE-2026-0770 to KEV

    The unauthenticated remote-code-execution vulnerability received a July 24 required-action date. Because affected Langflow servers can run in a root context and may hold model credentials, API keys, secrets, data connectors, and trusted automation, organizations need both immediate remediation and investigation of prior public exposure.[1][5]

  15. Ransomware reporting

    Secondary reporting connects the SMA1000 activity to INC Ransom

    Dark Reading reported that Rapid7 tied the SMA1000 activity to INC Ransom and observed a ransomware outcome. IntelliOS preserves that secondary attribution separately from Volexity’s UTA0533 label because the retained public evidence does not establish that the two names identify the same operator.[7][8]

  16. Joint government attribution

    UK and partners expose LAUNDRY BEAR’s Zimbra beehive/Ulej campaign

    UK NCSC and a 15-country partner group described an ongoing Russian state-supported campaign in which viewing a malicious message on a vulnerable Zimbra deployment can trigger zero-click email theft. The notice names defence, government, education, energy, law-enforcement, media, NGO, and technology targeting and says AI assisted development of the campaign’s simple codebase.[9]

  17. Required-action deadline

    Langflow remediation deadline arrives

    CISA’s required-action date for CVE-2026-0770 arrives. Organizations should be able to demonstrate Langflow asset discovery, ownership, internet-exposure assessment, remediation or isolation, secret and connector review, and investigation of any prior public reachability; a current fixed version does not by itself prove the server was not previously compromised.[1][5]

  18. FortiOS KEV and forensic triage

    CISA adds the FortiOS post-compromise persistence patch bypass

    CISA added CVE-2025-68686 with an August 10 required-action date and explicitly referenced BOD 26-04 Forensics Triage Requirements. Fortinet says exploitation requires prior filesystem-level compromise through another vulnerability, so owners must apply 7.6.2+ or 7.4.7+ and determine whether attacker-controlled state, credentials, configuration, or downstream access survived.[13]

Bottom Line Up Front

BLUF

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026
  • New FortiOS action: CISA added CVE-2025-68686 on July 27 with an August 10 federal deadline and a requirement for vendor mitigation plus BOD 26-04 forensic triage. Fortinet says the flaw bypasses a fix for symbolic-link persistence after an attacker already achieved filesystem-level compromise; previously exposed devices therefore need a fixed release and a retrospective integrity investigation.[13]Evidence dated Jul 27, 2026

  • Immediate priority: Do not treat this as a routine patch list. CISA’s KEV catalog says the listed vulnerabilities are being exploited. The most urgent checks in this record include internet-facing Langflow servers affected by CVE-2026-0770, SonicWall SMA1000 appliances affected by CVE-2026-15409 and CVE-2026-15410, and exposed management products such as Cisco SD-WAN Manager, SimpleHelp, Check Point gateways, Oracle PeopleSoft, Ubiquiti UniFi OS, and Lantronix EDS5000.[1][5][6]First cited source Jun 2026 · Latest cited source Jul 22, 2026

  • Why these systems matter: These products sit in trusted positions: they manage remote access, networks, endpoints, enterprise applications, or automated AI workflows. A successful attacker may inherit that trust, steal credentials or sessions, reach connected systems, and move farther into the organization. The risk is therefore larger than damage to one vulnerable server.[1][5][6][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026

  • Physical operations are in scope: NSA, CISA, FBI, DOE, EPA, TSA, DOT, and USDA reported that attackers compromised internet-exposed automatic tank gauges and changed them through remote commands. Companies that store fuel or other liquids should verify gauge ownership and internet exposure because bad readings or unavailable systems can affect inventory, leak detection, safety, environmental obligations, and operations.[2]Evidence dated Jun 3, 2026

  • Government disruption creates local hunting work: Europol’s action against SocGholish, Amadey, and StealC reduced criminal infrastructure; it did not prove that earlier infections, stolen passwords, or surviving operators disappeared. DOJ’s scam-center disruption likewise shows why companies must be ready to preserve evidence and coordinate quickly with technology providers, banks, and law enforcement when accounts or funds are at risk.[3][4]First cited source Jun 3, 2026 · Latest cited source Jun 24, 2026

  • Keep attribution honest: CISA and SonicWall establish that the two SMA1000 vulnerabilities were exploited, Volexity tracks overlapping activity as UTA0533, and Dark Reading reports an INC Ransom connection and a ransomware outcome. Those labels should be monitored together but not merged into one actor identity without stronger public evidence.[1][6][7][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026

  • Executive decision: Require proof for each exposed asset: who owns it, whether it was fixed or isolated, whether prior exposure was investigated, whether relevant credentials and sessions were reset, and who accepted any deadline exception. If the system was exposed and reliable historical logs are missing, treat that uncertainty as a possible incident—not as evidence that nothing happened.[1][2][5][6][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026

Decision Context

Executive Summary

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026

The July 27 addition of FortiOS CVE-2025-68686 sharpens the difference between vulnerability closure and incident closure. CISA now confirms exploitation and requires vendor action plus BOD 26-04 forensic triage by August 10 for federal civilian agencies. Fortinet describes the issue as a patch bypass for a symbolic-link persistence mechanism observed after an attacker already obtained filesystem-level control through another vulnerability. A previously exposed FortiOS device therefore needs a fixed release, preserved evidence, historical hunting, and a defensible integrity decision; a changed version number alone cannot answer whether attacker-controlled state survived.[13]Evidence dated Jul 27, 2026

The current rolling 90-day government cybersecurity record should be read as an executive decision framework, not as a digest of agency announcements. Across the retained window, CISA repeatedly added actively exploited vulnerabilities with required-action dates measured in days rather than normal monthly patch cycles. The practical consequence is that ownership, internet exposure, exception authority, and evidence of completion must be visible at the asset level whenever new KEV evidence enters the window.[1]Evidence dated Jun 2026

The most consequential exposures are not necessarily the systems with the largest user populations; they are the systems that administer, connect, or authenticate other systems. CISA’s retained KEV entries include Langflow AI workflow servers, SonicWall SMA1000 remote-access appliances, Cisco SD-WAN Manager, Oracle PeopleSoft, Check Point VPN gateways, SimpleHelp remote-support servers, and Ubiquiti or Lantronix management interfaces. Compromise of one of these control planes can give an attacker inherited trust across customers, sites, identities, and internal environments, turning a vulnerability-management failure into an incident-response and business-continuity event.[1]Evidence dated Jun 2026

Government guidance also pushed operational technology into the same executive exposure conversation. NSA, CISA, FBI, DOE, EPA, TSA, DOT, and USDA reported malicious actors compromising internet-exposed automatic tank gauges and modifying them through command execution. For operators in energy, chemical, food and agriculture, or transportation environments, this is not merely a software issue: altered readings or unavailable gauges can affect physical inventory, leak detection, safety, environmental obligations, and continuity of operations.[2]Evidence dated Jun 3, 2026

The retained window also demonstrates that public-private disruption is becoming an operational defensive instrument. DOJ’s Scam Center Disruption Week used information from the FBI, U.S. Secret Service, and HSI with foreign law enforcement and companies including Apple, Coinbase, Google, Meta, Microsoft, SpaceX, and others; the announced results included disruption across more than 1.4 million accounts and the freezing of more than $3.8 million in cryptocurrency. Executives should ensure their organizations can rapidly preserve evidence, act on trusted indicators, and coordinate with providers or financial institutions when government action creates a narrow intervention window.[3]Evidence dated Jun 3, 2026

Operation Endgame illustrates the other side of the same model: ecosystem disruption can reduce adversary capacity without eliminating the underlying threat. Europol and partners acted against infrastructure supporting SocGholish, Amadey, and StealC, including servers, domains, infected websites, credentials, and criminal assets. Defenders should convert the operation into retro-hunting, credential review, and successor-infrastructure monitoring rather than assume that previously stolen access or surviving operator capability disappeared.[4]Evidence dated Jun 24, 2026

The executive decision is therefore broader than whether individual KEV tickets were closed. Leadership should require a continuing watchlist that joins new deadlines to exposed-asset ownership, links named campaigns and actors to internal telemetry, and identifies when remediation must become investigation. Current Langflow and SonicWall exploitation illustrate why that operating model must persist: both concern internet-reachable control software, active exploitation, compressed response expectations, and the need to assess historical exposure—not only current version status.[1][5][6][7][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026

Executive Briefing Priorities

Top 10 Briefing Points

  1. 1

    FortiOS CVE-2025-68686 makes forensic triage part of the required actionThe July 27 KEV entry is not a stand-alone initial-access story. Fortinet says the patch bypass applies after another vulnerability already produced filesystem-level compromise. Owners must identify affected 7.6, 7.4, 7.2, 7.0, and 6.4 devices, move to a documented fixed branch, preserve evidence, and determine whether persistence, configuration changes, credentials, or downstream trust survived.[13]Evidence dated Jul 27, 2026

  2. 2

    CISA KEV turns vulnerability management into deadline governanceCISA’s catalog confirms exploitation in the wild and repeatedly imposed action windows measured in days: Oracle WebLogic and PeopleSoft received three-day windows, while Langflow CVE-2026-0770 received a July 24 deadline. Executives need an accountable technical and business owner for every matched asset, exception, and compensating control.[1][5]First cited source Jun 2026 · Latest cited source Jul 22, 2026

  3. 3

    Control-plane technologies deserve priority over raw CVSS sortingCISA’s retained KEV entries include Cisco SD-WAN Manager, SonicWall SMA1000, Check Point VPN gateways, SimpleHelp remote support, Langflow AI workflows, and Oracle PeopleSoft. These systems administer networks, identities, endpoints, data, or automation; compromise can inherit trusted reach far beyond the vulnerable server.[1][5][6]First cited source Jun 2026 · Latest cited source Jul 22, 2026

  4. 4

    “Known ransomware use: Unknown” does not lower a KEV remediation deadlineCISA uses “Unknown” when its catalog does not identify a ransomware connection for that vulnerability. The entry still represents confirmed exploitation in the wild and keeps its required-action date. For SMA1000, review CISA and SonicWall for the exploited CVEs, Volexity for UTA0533 activity, and the separate INC Ransom reporting before making an attribution.[1][6][7][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026

  5. 5

    FBI, NSA, CISA, and sector agencies elevated exposed tank gauges into a physical-risk issueThe joint warning says unattributed actors compromised internet-exposed automatic tank gauges and modified them through command execution. DOE, EPA, TSA, DOT, and USDA participation reflects the potential consequences to fuel and liquid inventory, leak detection, safety, environmental obligations, and transportation or agricultural continuity.[2]Evidence dated Jun 3, 2026

  6. 6

    A patch closes a path; it does not prove the asset remained trustworthyCISA and vendor remediation establish what must be fixed now. Volexity’s SMA1000 incident-response evidence shows why leaders must also ask whether the appliance was exposed before disclosure, whether logs exist, and whether credentials, sessions, TOTP material, or downstream systems require investigation.[1][6][8]First cited source Jun 2026 · Latest cited source Jul 17, 2026

  7. 7

    DOJ and FBI disruption reporting should become a company response triggerDOJ’s Scam Center Disruption Week used FBI, Secret Service, HSI, foreign-law-enforcement, and private-sector information to disrupt more than 1.4 million accounts and freeze more than $3.8 million. Companies should be ready to preserve evidence, validate named infrastructure, protect customers and payment workflows, and respond quickly to trusted provider or law-enforcement requests.[3]Evidence dated Jun 3, 2026

  8. 8

    Europol’s Operation Endgame creates a hunting window, not an all-clearEuropol named SocGholish, Amadey, and StealC and reported action against servers, domains, infected websites, credentials, and criminal assets. Defenders should retro-hunt those ecosystems, review already stolen credentials, and monitor replacement infrastructure because disruption does not erase surviving access or operator capability.[4]Evidence dated Jun 24, 2026

  9. 9

    UK NCSC campaign warnings add actor, victimology, and technology contextThe NCSC and partner governments identify LAUNDRY BEAR’s Zimbra beehive/Ulej email-theft campaign and separately warn about the FortiBleed credential campaign against Fortinet gateways. Those notices should drive Zimbra mailbox and authentication hunting, FortiGate credential rotation and session review, and careful preservation of each notice’s attribution boundary.[9][10]First cited source Jun 18, 2026 · Latest cited source Jul 23, 2026

  10. 10

    Every government instrument carries a different executive decisionA CISA KEV deadline requires remediation governance; an FBI/NSA/CISA joint advisory requires exposure scoping and hardening; a DOJ or Europol disruption creates hunting and evidence-preservation opportunities; a UK NCSC attribution changes intelligence and communications context. Treating these instruments as interchangeable discards their operational meaning.[1][2][3][4][9]First cited source Jun 2026 · Latest cited source Jul 23, 2026

  11. 11

    Boards need named evidence, not a generic count of closed ticketsA defensible briefing should show which CISA KEVs map to owned assets, which FBI/NSA/CISA OT warnings match real equipment, which DOJ or Europol indicators were hunted, where logging is missing, what incident findings exist, and how recovery was tested. Aggregate patch percentages cannot answer those questions.[1][2][3][4]First cited source Jun 2026 · Latest cited source Jun 24, 2026

Company Exposure and Exploitability

Exploitable Technologies for Companies

Specific products and control interfaces elevated by the retained government record. Each row explains the exploitable condition, which companies should care, the business consequence, and the evidence a defender should monitor.

Technology

Fortinet FortiOS · CVE-2025-68686[13]Evidence dated Jul 27, 2026

Exploitable condition

CISA confirms exploitation of a remote unauthenticated bypass of the patch for a symbolic-link persistence mechanism seen in some post-exploit cases. Fortinet says the attacker must first have compromised FortiOS at filesystem level through another vulnerability.

Which companies should care

Organizations and MSPs operating FortiGate appliances on affected FortiOS 7.6, 7.4, 7.2, 7.0, or 6.4 branches, especially devices with prior internet-reachable administration or VPN exposure.

Business risk

A perimeter control plane may appear patched while attacker-controlled filesystem state, configuration, credentials, sessions, or internal reach remains relevant.

What to monitor

Exact version and exposure history; unexpected symbolic links or filesystem changes; administrative sessions and accounts; configuration drift; HA peer state; outbound and internal connections; reachable secrets and downstream access.

IntelliOS coverage
Technology

Langflow AI workflow servers · CVE-2026-0770[1][5]First cited source Jun 2026 · Latest cited source Jul 22, 2026

Exploitable condition

CISA’s KEV catalog and the NIST NVD record identify internet-reachable Langflow deployments exposed to unauthenticated remote code execution through the exec_globals handling path, with execution possible in the server’s root context.

Which companies should care

Companies operating self-hosted AI workflow, agent, integration, or automation infrastructure—especially systems holding API keys, secrets, data connectors, or privileged service access.

Business risk

Remote takeover can expose model and application secrets, enable data theft, create a launch point into connected services, and alter trusted AI workflows.

What to monitor

Owned Langflow instances, version and mitigation status, validate-endpoint requests, unexpected child processes, outbound connections, credential access, and changes to flows or secrets.

IntelliOS coverage
Technology

SonicWall SMA1000 · CVE-2026-15409 and CVE-2026-15410[1][6][7][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026

Exploitable condition

SonicWall’s PSIRT advisory and Volexity’s incident-response research describe a chain that uses unauthenticated server-side request forgery to reach a privileged internal workflow, then abuses an authenticated-administrator hotfix-removal path for path traversal and command execution as root.

Which companies should care

Organizations using SMA1000 6210, 7210, or 8200v appliances for remote access, including enterprises, service providers, and environments where the appliance brokers identity and internal connectivity.

Business risk

Appliance compromise can expose credentials, sessions, authentication material, internal services, and downstream systems; public reporting includes a ransomware outcome.

What to monitor

Internet-facing SMA1000 assets, fixed-release status, historical WorkPlace and localhost-control activity, appliance configuration changes, credential or TOTP exposure, and appliance-sourced lateral movement.

IntelliOS coverage
Technology

Zimbra Collaboration servers · LAUNDRY BEAR beehive/Ulej activity[9]Evidence dated Jul 23, 2026

Exploitable condition

UK NCSC and partner governments describe a zero-click email-theft path in which viewing a malicious message on a vulnerable Zimbra deployment can trigger compromise without a user clicking a link or opening an attachment.

Which companies should care

Organizations operating Zimbra for sensitive government, defence, education, energy, law-enforcement, media, NGO, or technology communications.

Business risk

Mailbox compromise can expose strategic communications, authentication material, relationships, and intelligence useful for follow-on espionage or intrusion.

What to monitor

Zimbra version and exposure, suspicious message rendering, anomalous mailbox exports, authentication changes, new persistence, and evidence of access predating remediation.

IntelliOS coverageNo dedicated product yet
Technology

Fortinet FortiGate firewalls and SSL VPN gateways · FortiBleed[10]Evidence dated Jun 18, 2026

Exploitable condition

UK NCSC says a global campaign used brute force, dictionary attacks, credential stuffing, and leaked credential material against internet-facing FortiGate and VPN authentication portals.

Which companies should care

Companies using Fortinet firewalls or SSL VPN services, particularly where credentials were reused, MFA was incomplete, management interfaces were exposed, or older sessions remained valid.

Business risk

Successful access can bypass the perimeter, expose administrative control, enable internal reconnaissance, and create an access path for data theft or ransomware.

What to monitor

Owned domains in trusted exposure checks, unusual FortiGate or VPN authentication, unauthorized accounts, active sessions, credential reuse, and management-interface exposure.

IntelliOS coverage
Technology

Cisco Catalyst SD-WAN Manager · CVE-2026-20262[1]Evidence dated Jun 2026

Exploitable condition

CISA lists an exploited arbitrary file-write vulnerability affecting Cisco’s platform for centrally administering distributed network infrastructure.

Which companies should care

Enterprises and service providers using Cisco SD-WAN Manager to control branch, cloud, or wide-area network policy and connectivity.

Business risk

Compromise of a network control plane can affect many managed devices, alter trusted configuration, and create broad downstream reach.

What to monitor

Internet exposure, fixed-version status, unusual management requests, unexpected file creation or processes, configuration changes, and administrator activity from unfamiliar sources.

IntelliOS coverage
Technology

Oracle PeopleSoft PeopleTools · CVE-2026-35273[1]Evidence dated Jun 2026

Exploitable condition

CISA lists an exploited HTTP takeover path affecting Oracle PeopleSoft PeopleTools, an enterprise application platform that commonly carries HR, finance, identity, and administrative workflows.

Which companies should care

Organizations running internet-facing or partner-accessible PeopleSoft and PeopleTools deployments.

Business risk

Application takeover can expose regulated business data, privileged functions, trusted sessions, and a path into administrative systems.

What to monitor

Owned PeopleSoft instances, update status, abnormal HTTP requests, authentication or session anomalies, unexpected web-accessible files, process creation, and configuration changes.

IntelliOS coverage
Technology

Check Point security gateways using IKEv1 · CVE-2026-50751[1]Evidence dated Jun 2026

Exploitable condition

CISA lists an exploited VPN authentication-bypass condition affecting Check Point remote-access and security-gateway trust paths; the connected CARDS record captures known ransomware campaign use.

Which companies should care

Companies with Check Point gateways where IKEv1 remains enabled or remote-access exposure is not fully inventoried.

Business risk

Authentication bypass at the security edge can create unauthorized remote access, privileged network position, and downstream ransomware or data-theft opportunity.

What to monitor

Affected gateways, IKEv1 enablement, fixed-version status, unexpected VPN sessions, new remote-access identities, configuration changes, and gateway-originated internal activity.

IntelliOS coverage
Technology

SimpleHelp remote-support servers · CVE-2026-48558[1]Evidence dated Jun 2026

Exploitable condition

CISA’s KEV catalog identifies an exploited SimpleHelp authentication-bypass vulnerability in remote-support infrastructure.

Which companies should care

Managed service providers, internal IT teams, and organizations whose SimpleHelp deployment can administer many endpoints or customer environments.

Business risk

One compromised support server can inherit trusted reach across numerous endpoints, customers, credentials, and administrative sessions.

What to monitor

Internet-facing SimpleHelp servers, version status, new administrators, unusual support sessions, endpoint fan-out, remote execution, and access during the historical exposure window.

IntelliOS coverageNo dedicated product yet
Technology

Ubiquiti UniFi OS and Lantronix EDS5000 management interfaces[1]Evidence dated Jun 2026

Exploitable condition

CISA added four exploited vulnerabilities on June 23, concentrating urgent remediation in Ubiquiti UniFi OS and Lantronix EDS5000 industrial or network-management interfaces with internet-reachable control paths.

Which companies should care

Organizations operating distributed network, industrial, branch, facility, or vendor-managed infrastructure built on the affected platforms.

Business risk

Compromised management interfaces can alter connectivity, disrupt operations, weaken segmentation, and provide a trusted path toward internal assets.

What to monitor

Asset ownership, public administration interfaces, firmware status, configuration drift, new accounts, unexpected management traffic, and evidence of access before patching.

IntelliOS coverage
Technology

Internet-accessible automatic tank gauges and connected OT[2]Evidence dated Jun 3, 2026

Exploitable condition

NSA, CISA, FBI, DOE, EPA, TSA, DOT, and USDA reported malicious activity against internet-exposed gauges and warned that public interfaces, weak credentials, unsupported equipment, or permissive vendor access can allow compromise and command-based modification.

Which companies should care

Energy, chemical, food, agriculture, transportation, retail-fuel, and other operators that depend on connected gauges for physical inventory and operational decisions.

Business risk

Manipulated or unavailable readings can affect safety, environmental obligations, inventory integrity, dispatch, billing, and continuity of physical operations.

What to monitor

Publicly reachable gauge interfaces, default or shared credentials, unsupported models, vendor access, segmentation gaps, unexplained level or configuration changes, and tested manual recovery.

IntelliOS coverage

Source-Bound Exposure and Targeting

Victimology Matrix

This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.

Victim / exposure populationWestern organizations exposed to LAUNDRY BEAR’s Zimbra beehive/Ulej campaign[9]Evidence dated Jul 23, 2026SectorsDefence, government, education, energy, law enforcement, media, NGOs, and technologyGeographyWestern organizations; the joint notice is internationalConfirmation statusUK NCSC and partner governments provide category-level targeting for LAUNDRY BEAR; they do not publish a named-victim list in the retained notice.How companies should use itUse the NCSC warning to prioritize Zimbra discovery, version validation, mailbox hunting, and evidence review in the named sectors. Do not describe an organization as compromised without first-party or incident evidence.
Victim / exposure populationOrganizations using internet-facing Fortinet FortiGate and SSL VPN services[10]Evidence dated Jun 18, 2026SectorsCross-industry, including public-sector and critical-service environmentsGeographyGlobal campaign with potential UK impactConfirmation statusUK NCSC defines the exposed Fortinet population but does not publish a confirmed named-victim list or name the operator.How companies should use itUse owned-domain and device validation, credential rotation, session review, and historical authentication analysis before making impact claims.
Victim / exposure populationOrganizations exposed through SocGholish-infected websites, Amadey, StealC, or already stolen credentials[4]Evidence dated Jun 24, 2026SectorsCross-industry malware-delivery, credential-theft, and ransomware exposureGeographyInternationalConfirmation statusEuropol provides ecosystem-scale victimology for Operation Endgame; its release does not establish that every affected organization, infected website, or stolen credential was remediated.How companies should use itRetro-hunt the named malware ecosystems, review reused credentials, and watch for replacement infrastructure rather than treating the takedown as eradication.
Victim / exposure populationCompanies operating internet-facing Langflow or SonicWall SMA1000 infrastructure[5][6][7][8]First cited source Jul 14, 2026 · Latest cited source Jul 22, 2026SectorsAI/software operations, enterprises, service providers, and remote-access-dependent organizationsGeographyGlobal technology exposure; SMA1000 incident reporting includes observed compromise but no reliable public named-victim listConfirmation statusCISA and NIST define the Langflow exposure; SonicWall defines affected SMA1000 products; Volexity supplies incident-response observations; Dark Reading reports one ransomware outcome and the INC Ransom association. IntelliOS does not infer impact for every exposed deployment.How companies should use itUse asset ownership and historical exposure to decide which systems require incident investigation, credential response, and downstream hunting—not just patch confirmation.

Named and Source-Bound Government Signals

Government-Flagged Threat Actor Campaigns

Specific actors and campaigns identified or described in official government notices. Attribution language is preserved exactly: a row is not presented as government-attributed when the issuing authority did not name an operator.

Government notice

23 Jul 2026

UK NCSC and a 15-country joint advisory

Actor or campaign

LAUNDRY BEAR — “beehive/Ulej” Zimbra zero-click email theft[9]Evidence dated Jul 23, 2026

What the government source establishesThe government notice attributes an ongoing espionage campaign to LAUNDRY BEAR, assesses it as almost certainly supported by the Russian state, and says vulnerable Zimbra users can be compromised by viewing a malicious email without clicking. The campaign has targeted Western defence, government, education, energy, law-enforcement, media, NGO, and technology organizations.What to monitorZimbra version and exposure; suspicious message rendering; anomalous mailbox, export, or authentication activity; persistence around mail infrastructure; evidence of access predating remediation.IntelliOS coverageNo dedicated IntelliOS record yet
Government notice

18 Jun 2026

UK NCSC alert

Actor or campaign

FortiBleed global Fortinet firewall and VPN credential campaign[10]Evidence dated Jun 18, 2026

What the government source establishesThe NCSC says a threat actor targeted internet-facing FortiGate and VPN portals through brute-force, dictionary, and credential-stuffing attempts and that a resulting credential database was leaked. The government alert recognizes the campaign and potential UK impact but does not name the responsible actor.What to monitorOwned domains in trusted exposure checkers; unauthorized accounts; unusual FortiGate or SSL VPN authentication; stale or reused credentials; active sessions; management-interface exposure; device and downstream network activity.IntelliOS coverage
Government notice

24 Jun 2026

Europol Operation Endgame release

Actor or campaign

SocGholish, Amadey, and StealC malware-delivery and credential-theft ecosystems[4]Evidence dated Jun 24, 2026

What the government source establishesEuropol identifies the three named malware ecosystems as targets of an international operation against infrastructure supporting ransomware delivery, credential theft, and cybercrime. The action disrupted servers, domains, infected websites, and criminal assets without establishing permanent eradication.What to monitorReplacement domains and servers; renewed compromised-website delivery; Amadey or StealC execution; reuse of already stolen credentials; downstream ransomware; infrastructure migration after takedown activity.IntelliOS coverage

Source-Bound Actor Context

Notable Actors & Criminal Ecosystems

SocGholish ecosystem

Europol’s Operation Endgame release names SocGholish as a malware-delivery ecosystem targeted through server, domain, and infected-website disruption. Defenders should retro-hunt web and endpoint activity and watch for successor infrastructure rather than assume the delivery path disappeared.[4]Evidence dated Jun 24, 2026

Amadey operators and affiliates

Europol identifies Amadey infrastructure within the coordinated international action. The official release supports disruption context and follow-on hunting, but it does not resolve the identity behind every Amadey infection or prove the ecosystem was eradicated.[4]Evidence dated Jun 24, 2026

StealC information-stealer ecosystem

Europol names StealC as a targeted credential-theft ecosystem. Existing credential exposure remains consequential even when law enforcement removes portions of delivery infrastructure, so identity telemetry and credential reuse remain priority checks.[4]Evidence dated Jun 24, 2026

Southeast Asian scam-center networks

DOJ’s disruption record—supported by FBI, Secret Service, HSI, foreign-law-enforcement, and named private-sector actions—describes a distributed cyber-enabled fraud ecosystem spanning social-media and email accounts, hosting, telecommunications, scam platforms, and cryptocurrency. It is not a complete actor census.[3]Evidence dated Jun 3, 2026

Unattributed KEV exploitation

CISA’s KEV catalog establishes observed exploitation but often does not identify the responsible actor. IntelliOS keeps remediation urgency separate from actor attribution unless CISA, another government authority, a vendor, or source-bound incident research establishes the relationship.[1]Evidence dated Jun 2026

Malware, Implants, and Intrusion Tooling

Malware Summary

Source-backed malware and malicious tooling named in the retained campaigns. The table distinguishes malware families, open-source tools, custom implants, exploit or collection tooling, and reported outcomes that lack a publicly identified sample.

Malware / toolingSocGholish / FakeUpdates[4][11]First cited source Jun 18, 2026 · Latest cited source Jun 24, 2026Classification and campaignJavaScript loader and initial-access malwareOperation Endgame; Dutch National Police, RCMP, Europol, and partner reporting link the ecosystem to Evil Corp.Capability and potential impactCompromises legitimate WordPress sites and presents fake browser or software updates to visitors. Successful execution gives the operator an initial foothold that can deliver additional malware, steal access, or lead to ransomware.What defenders should monitorUnauthorized WordPress code or accounts; injected update prompts; browser-launched script or executable activity; new scheduled persistence; outbound connections to replacement infrastructure; credentials associated with compromised sites.
Malware / toolingAmadey[4][12]Evidence dated Jun 24, 2026Classification and campaignBot, loader, and access-enablement malwareOperation Endgame; Europol and Microsoft Digital Crimes Unit reporting describe Amadey and StealC as distinct tools that shared infrastructure.Capability and potential impactHelps attackers gain and maintain access to infected devices, collect system information, and retrieve additional payloads. Microsoft reports that Amadey and StealC were linked to more than 140,000 infected computers during the first two weeks of May 2026.What defenders should monitorKnown Amadey detections and command-and-control; suspicious downloader behavior; scheduled tasks or startup persistence; system discovery; secondary payload retrieval; credentials or sessions used after the endpoint infection.
Malware / toolingStealC[4][12]Evidence dated Jun 24, 2026Classification and campaignInformation stealer with dropper capabilityOperation Endgame; investigated by Europol EC3, European law enforcement, Microsoft DCU, IBM X-Force, Proofpoint, and other partners.Capability and potential impactExtracts passwords, browser cookies, session tokens, stored access data, and digital identities for resale or fraudulent use. It can also support follow-on payload delivery, making an apparently contained endpoint infection an identity and cloud-access incident.What defenders should monitorStealer detections; access to browser credential and cookie stores; unusual archive creation; outbound credential exfiltration; new logins using stolen cookies or tokens; follow-on fraud, mailbox, VPN, or cloud activity.
Malware / toolingROOTRUN / xzfind[8]Evidence dated Jul 17, 2026Classification and campaignSMA1000 privilege-escalation utilityUTA0533 SonicWall SMA1000 exploitation; named and analyzed by Volexity.Capability and potential impactA setuid ELF binary written to /usr/bin/xzfind that invokes setuid to elevate itself and execute attacker-supplied commands through the Bash shell as root.What defenders should monitor/usr/bin/xzfind; unexpected setuid binaries; the ROOTRUN usage string; root command execution from appliance service contexts; file creation or modification around the historical compromise window.
Malware / toolingKNUCKLEBALL / deploy_new.py[8]Evidence dated Jul 17, 2026Classification and campaignSMA1000 loader, injector, and persistence scriptUTA0533 SonicWall SMA1000 exploitation; Volexity-assigned malware name.Capability and potential impactInjects two embedded Java agents into a legitimate SonicWall process, clears temporary agent logs, deletes staged JARs, modifies NGINX Unit routes, and persists through the legitimate workplace startup script.What defenders should monitor/usr/lib/python3.11/site-packages/deploy_new.py; /tmp/agent_wp8.jar or agent_wp9.jar; .attach_pid or .java_pid artifacts; the workplace init script launching deploy_new.py; unexpected changes to /var/lib/unit/conf.json.
Malware / toolingSuo5 / agent_wp8.jar[8]Evidence dated Jul 17, 2026Classification and campaignModified open-source HTTP forwarding proxyEmbedded in KNUCKLEBALL during the UTA0533 SMA1000 intrusion and injected into a legitimate appliance Java process.Capability and potential impactCreates an attacker-controlled proxy path through the compromised appliance, allowing traffic forwarding and concealed access through a trusted internet-facing remote-access system.What defenders should monitor/tmp/agent_wp8.jar; /workplace/error.jsp; NGINX routes rewriting /__api__/login; proxying to 127.0.0.1:8085; the impossible Chrome 149 / Windows 11 user-agent string documented by Volexity.
Malware / toolingORANGETAIL / agent_wp9.jar[8]Evidence dated Jul 17, 2026Classification and campaignCustom Java webshellEmbedded in KNUCKLEBALL during the UTA0533 SMA1000 intrusion; Volexity describes it as Behinder-like.Capability and potential impactAccepts encrypted attacker-supplied Java through an HTTP POST parameter, dynamically loads it into the appliance process, and returns encrypted responses—providing a durable command-execution channel behind legitimate web paths.What defenders should monitor/tmp/agent_wp9.jar; /workplace/dialogs/errorDialog.jsp; NGINX routes rewriting /__api__/logout; repeated encrypted POST requests; the documented impossible user agent; unexplained Java class loading in the workplace process.
Malware / toolingBeehive / Ulej[9]Evidence dated Jul 23, 2026Classification and campaignZimbra exploit and email-collection tooling—not a standalone malware familyLAUNDRY BEAR campaign identified by UK NCSC and partner governments.Capability and potential impactA malicious email can execute when viewed in a vulnerable Zimbra web client, enabling collection of recent email, directory data, authentication material, and other sensitive mailbox information without a conventional link click or attachment open.What defenders should monitorVulnerable Zimbra versions; suspicious message rendering; anomalous mailbox searches or bulk exports; unusual access to address-book data; credential or token changes; persistence and outbound transfers from mail infrastructure.
Malware / toolingRansomware payload in the reported SMA1000 case[7][8]First cited source Jul 17, 2026 · Latest cited source Jul 22, 2026Classification and campaignReported outcome; malware family or sample not publicly characterizedDark Reading reports that Rapid7 associated activity with INC Ransom and that one investigated case progressed to ransomware. The retained Volexity report uses UTA0533 and does not identify a ransomware sample.Capability and potential impactThe retained secondary reporting supports a reported ransomware outcome but not a specific payload name, hash, encryption implementation, or proof that every SMA1000 intrusion produced ransomware. The gap should remain visible rather than be filled by inference.What defenders should monitorPost-appliance lateral movement; remote execution or administrative tooling; backup or security-control tampering; mass file changes; ransom notes; data staging or exfiltration; new primary reporting that identifies the payload.

Current Carry-Forward Watchlist

Top 10 Specific Threats to Monitor

Prioritized CVEs, KEVs, actors, and campaigns that convert the government-action record into named operational monitoring requirements.

1Threat / Category

CVE / KEV · AI infrastructure

CVE-2026-0770 — Langflow unauthenticated root RCE[1][5]First cited source Jun 2026 · Latest cited source Jul 22, 2026

Why it mattersCISA added this Langflow vulnerability to KEV on July 21 with a July 24 required-action date. It permits remote code execution without authentication through the exec_globals handling path and can execute in the context of root.What to monitorInternet-exposed Langflow servers; versions and mitigations against current project guidance; requests to the validate endpoint; unexpected child processes, outbound connections, credential access, or changes to flows and secrets.IntelliOS coverage
2Threat / Category

CVEs / KEVs · Edge appliance campaign

CVE-2026-15409 and CVE-2026-15410 — SonicWall SMA1000 exploitation[1][6][7][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026

Why it mattersSonicWall’s PSIRT advisory defines the two CVEs and affected appliances; CISA places both in KEV; Volexity documents the exploitation chain and UTA0533 activity; Dark Reading reports the INC Ransom association and a ransomware outcome. The chain moves from unauthenticated access to an authenticated-administrator workflow and root execution, but the actor labels remain separate.What to monitorInternet-facing SMA1000 6210, 7210, and 8200v appliances; fixed-release status; historical WorkPlace and localhost-control activity; appliance configuration changes; credential, session, and TOTP exposure; appliance-sourced lateral movement.IntelliOS coverage
3Threat / Category

Actors · Attribution boundary

INC Ransom and UTA0533 — related reporting, not a merged identity[7][8]First cited source Jul 17, 2026 · Latest cited source Jul 22, 2026

Why it mattersDark Reading reports an INC Ransom connection and a ransomware outcome, while Volexity tracks overlapping SMA1000 exploitation as UTA0533. The public record supports monitoring both labels but does not prove they represent the same operator.What to monitorNew primary reporting that resolves attribution; INC victim or access claims; UTA0533 infrastructure and tooling; overlap in SMA1000 artifacts; ransomware deployment after edge-appliance compromise.IntelliOS coverage
4Threat / Category

Campaign · Malware delivery ecosystem

Operation Endgame — SocGholish, Amadey, and StealC reconstitution[4]Evidence dated Jun 24, 2026

Why it mattersEuropol’s Operation Endgame release names SocGholish, Amadey, and StealC and reports action against infrastructure supporting delivery, credential theft, fraud, and ransomware enablement. The intervention raises adversary cost but does not invalidate credentials already stolen or prevent operators from rebuilding.What to monitorReplacement domains and servers; renewed SocGholish website infections; Amadey or StealC delivery changes; reuse of exposed credentials; downstream ransomware activity; further Operation Endgame actions.IntelliOS coverage
5Threat / Category

Campaign · Cyber-enabled fraud

DOJ / FBI Scam Center Disruption Week — account, infrastructure, and financial displacement[3]Evidence dated Jun 3, 2026

Why it mattersDOJ reports that Scam Center Disruption Week, with FBI, Secret Service, HSI, foreign-law-enforcement, and private-sector support, disrupted accounts, network access, hosting, scam platforms, and cryptocurrency laundering. The scale of action makes migration and reconstitution across providers a continuing monitoring concern.What to monitorSuccessor scam accounts and platforms; malicious IP and hosting migration; cryptocurrency laundering changes; provider or law-enforcement requests; fraud targeting employees, customers, and payment workflows.IntelliOS coverage
6Threat / Category

CVE / KEV · Network control plane

CVE-2026-20262 — Cisco Catalyst SD-WAN Manager arbitrary file write[1]Evidence dated Jun 2026

Why it mattersCISA’s KEV catalog identifies exploitation of Cisco Catalyst SD-WAN Manager CVE-2026-20262, an arbitrary file-write flaw in a platform that controls distributed network infrastructure. Its administrative reach makes it urgent even when a base score appears less dramatic than the business consequence.What to monitorInternet exposure, fixed-version status, unusual web-management requests, unexpected file creation, configuration changes, new processes, and administrative activity from unfamiliar sources.IntelliOS coverage
7Threat / Category

CVE / KEV · Enterprise application

CVE-2026-35273 — Oracle PeopleSoft PeopleTools HTTP takeover[1]Evidence dated Jun 2026

Why it mattersCISA’s KEV catalog identifies exploitation of Oracle PeopleSoft PeopleTools CVE-2026-35273. Because PeopleSoft commonly supports HR, financial, identity, and administrative workflows, HTTP takeover can expose sensitive business data and privileged functions while blending into normal web traffic.What to monitorInternet-facing PeopleSoft and PeopleTools instances, vendor update status, abnormal HTTP requests, authentication or session anomalies, unexpected web-accessible files, process creation, and changes to application configuration.IntelliOS coverage
8Threat / Category

CVE / KEV · Remote access

CVE-2026-50751 — Check Point IKEv1 VPN authentication bypass[1]Evidence dated Jun 2026

Why it mattersCISA’s KEV catalog establishes exploitation of Check Point CVE-2026-50751, while the connected CARDS record captures known ransomware campaign use. The authentication-bypass condition affects remote-access and security-gateway trust paths, raising it above ordinary perimeter patching.What to monitorAffected Check Point gateways, IKEv1 enablement, fixed-version status, unexpected VPN sessions, anomalous authentication, new remote-access identities, configuration changes, and downstream activity originating from the gateway.IntelliOS coverage
9Threat / Category

Operational technology · Exposed control interface

Internet-accessible automatic tank gauges[2]Evidence dated Jun 3, 2026

Why it mattersNSA, CISA, FBI, DOE, EPA, TSA, DOT, and USDA reported malicious actors compromising and modifying internet-exposed automatic tank gauges through command execution. The risk extends beyond confidentiality to fuel or liquid inventory integrity, leak detection, safety, environmental obligations, and continuity.What to monitorPublicly reachable gauge interfaces, default or shared credentials, unsupported models, vendor remote access, segmentation gaps, unexplained level or configuration changes, and tested manual recovery procedures.IntelliOS coverage
10Threat / Category

KEV cohort · Exposure governance

Rolling KEV exposure and remediation backlog[1]Evidence dated Jun 2026

Why it mattersEach new KEV entry retained inside the rolling window creates an asset-discovery, ownership, exposure, remediation, and—where prior reachability exists—investigation requirement. The threat is not only an unpatched CVE; it is an unknown or ownerless exposed asset that never enters the emergency workflow.What to monitorAsset-to-CVE coverage, internet exposure, business and technical ownership, remediation deadlines, expiring exceptions, compensating controls, missing logs, and evidence that previously exposed systems were assessed for compromise.IntelliOS coverage

Operational Standards from the Evidence

Best Practices and Lessons Learned

The practices below convert the retained public evidence into repeatable executive standards. Each lesson remains bounded to its cited sources.

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026
  1. 1

    Best Practice

    Run KEV remediation as an emergency operating process[1]Evidence dated Jun 2026

    Lesson Learned

    CISA’s three-day Oracle WebLogic and PeopleSoft windows and the Langflow July 24 deadline show that a conventional monthly patch cycle is too slow for vulnerabilities already known to be exploited.

    Minimum Operating Standard

    Every KEV-matched asset has a named technical owner, business owner, exposure decision, completion evidence, and a time-limited exception approved at the appropriate risk level.

  2. 2

    Best Practice

    Inventory control planes by reach and consequence[1][2]First cited source Jun 2026 · Latest cited source Jun 3, 2026

    Lesson Learned

    CISA’s Cisco SD-WAN, Check Point, SimpleHelp, and PeopleSoft entries—and the FBI/NSA/CISA automatic-tank-gauge warning—show that the highest-consequence system may be the one that administers, authenticates, or connects many other systems.

    Minimum Operating Standard

    Maintain an asset-level inventory of internet-reachable IT and OT management interfaces, including vendor-managed, forgotten, and third-party-hosted deployments, with emergency isolation options documented.

  3. 3

    Best Practice

    Treat historical exposure as an incident-response question[6][8]First cited source Jul 14, 2026 · Latest cited source Jul 17, 2026

    Lesson Learned

    A patched version proves that a known vulnerability is closed now; it does not prove that the system, its credentials, or connected environments remained trustworthy before remediation. The SMA1000 activity began before public disclosure.

    Minimum Operating Standard

    Prior exposure, missing logs, unexplained administrative activity, credential access, or appliance-sourced lateral movement automatically triggers scoped investigation rather than ticket closure alone.

  4. 4

    Best Practice

    Model exploit chains, not isolated vulnerability labels[6][8]First cited source Jul 14, 2026 · Latest cited source Jul 17, 2026

    Lesson Learned

    CVE-2026-15410 requires authenticated administrative access when considered alone, but the reported chain uses CVE-2026-15409 to reach the privileged workflow needed to exploit it. An authentication prerequisite is not a risk discount when another flaw can supply that access.

    Minimum Operating Standard

    Risk reviews document prerequisites, reachable services, privilege transitions, and plausible combinations with other vulnerabilities before accepting a lower-severity or post-authentication characterization.

  5. 5

    Best Practice

    Protect identities after edge-appliance compromise[8]Evidence dated Jul 17, 2026

    Lesson Learned

    An edge or remote-access appliance is part of the organization’s trust fabric. Volexity’s findings included credential, session, and authentication-material access, so replacing software alone may leave attacker-held access valid.

    Minimum Operating Standard

    Response plans define when to rotate administrator and service credentials, revoke sessions, replace exposed authentication seeds, validate identity-provider activity, and investigate downstream access.

  6. 6

    Best Practice

    Preserve evidence before containment destroys visibility[8]Evidence dated Jul 17, 2026

    Lesson Learned

    Emergency patching, rebooting, reimaging, or removing an appliance can eliminate the logs, configuration state, files, and volatile artifacts needed to determine whether exploitation occurred and what the attacker reached.

    Minimum Operating Standard

    Teams have a preapproved evidence-capture sequence for exposed control systems, with log export, configuration preservation, artifact collection, time synchronization, custody, and escalation responsibilities.

  7. 7

    Best Practice

    Turn government disruptions into active hunting windows[3][4]First cited source Jun 3, 2026 · Latest cited source Jun 24, 2026

    Lesson Learned

    DOJ and FBI’s Scam Center Disruption Week reporting and Europol’s Operation Endgame release show meaningful disruption of accounts, funds, domains, servers, and criminal infrastructure, but neither action invalidates stolen credentials or proves that operators and successor infrastructure disappeared.

    Minimum Operating Standard

    Official disruption reporting triggers indicator ingestion, retro-hunting, credential review, evidence preservation, provider coordination, and monitoring for migration or reconstitution.

  8. 8

    Best Practice

    Keep attribution and government action source-bound[1][3][4][7][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026

    Lesson Learned

    A KEV entry, vendor advisory, incident-response cluster, media-reported ransomware association, seizure, and international disruption each establish different facts. Combining those facts without preserving their boundaries can overstate confidence and misdirect response.

    Minimum Operating Standard

    Executive, legal, and public reporting identifies which source supports each claim, separates INC Ransom from Volexity’s UTA0533 label unless new evidence resolves the relationship, and preserves the government’s exact action language.

Source Attribution and Institutional Context

Government Contributors Used in This Record

Every government body below contributed to material actually used and cited. Co-authors are listed individually so the institutional contribution is visible rather than hidden behind “and partners.”

United States

Cybersecurity and Infrastructure Security Agency (CISA)

Mandate and role

The operational lead for federal civilian cybersecurity and the national coordinator for reducing cyber and physical risk to critical infrastructure.

Contribution to this record

Controls the rolling KEV evidence stream and co-authored the automatic-tank-gauge guidance; its KEV action also appears in the Langflow vulnerability record.[1][2][5]First cited source Jun 2026 · Latest cited source Jul 22, 2026

Sources used
United States

National Security Agency (NSA)

Mandate and role

A U.S. Intelligence Community and defense-support agency responsible for foreign signals intelligence and cybersecurity support for National Security Systems and the Defense Industrial Base.

Contribution to this record

Published and co-authored the defensive guidance on malicious activity targeting internet-exposed automatic tank gauges.[2]Evidence dated Jun 3, 2026

Sources used
United States

Federal Bureau of Investigation (FBI)

Mandate and role

The principal federal investigative and domestic-intelligence bureau for threats including cybercrime, nation-state activity, fraud, and attacks on critical infrastructure.

Contribution to this record

Co-authored the automatic-tank-gauge guidance and supplied federal investigative context for the observed malicious activity; FBI personnel also provided target information during DOJ’s Scam Center Disruption Week.[2][3]Evidence dated Jun 3, 2026

Sources used
United States

Department of Energy (DOE)

Mandate and role

The federal department responsible for U.S. energy policy, science, nuclear security, and resilience of energy infrastructure; CESER leads sector cybersecurity and emergency-response work.

Contribution to this record

Co-authored the automatic-tank-gauge guidance and supplied energy-sector and critical-infrastructure context.[2]Evidence dated Jun 3, 2026

Sources used
United States

Environmental Protection Agency (EPA)

Mandate and role

The federal environmental regulator responsible for protecting human health and the environment, with cybersecurity responsibilities touching water and chemical-sector resilience.

Contribution to this record

Co-authored the automatic-tank-gauge guidance and contributed environmental, chemical, leak-monitoring, and operational-risk context.[2]Evidence dated Jun 3, 2026

Sources used
United States

Transportation Security Administration (TSA)

Mandate and role

The Department of Homeland Security agency responsible for protecting U.S. transportation systems and issuing security requirements for regulated transportation operators.

Contribution to this record

Co-authored the automatic-tank-gauge guidance and contributed transportation-sector security and operational-continuity context.[2]Evidence dated Jun 3, 2026

Sources used
United States

Department of Transportation (DOT)

Mandate and role

The federal department responsible for transportation policy, safety, mobility, and coordination across national transportation systems.

Contribution to this record

Co-authored the automatic-tank-gauge guidance and contributed transportation-system ownership and sector context.[2]Evidence dated Jun 3, 2026

Sources used
United States

Department of Agriculture (USDA)

Mandate and role

The federal department responsible for food, agriculture, natural resources, rural development, and programs supporting the resilience of the food-and-agriculture sector.

Contribution to this record

Co-authored the automatic-tank-gauge guidance and contributed food-and-agriculture sector context for exposed fuel and liquid-storage monitoring systems.[2]Evidence dated Jun 3, 2026

Sources used
United States

Department of Justice (DOJ)

Mandate and role

The federal department responsible for enforcing federal law, prosecuting federal crimes, protecting civil rights, and coordinating national and international law-enforcement action.

Contribution to this record

Provided the official account, scope, and legal characterization of Scam Center Disruption Week.[3]Evidence dated Jun 3, 2026

Sources used
European Union

European Union Agency for Law Enforcement Cooperation (Europol)

Mandate and role

The EU law-enforcement cooperation agency that supports member states with criminal intelligence, analysis, coordination, and cross-border operational support.

Contribution to this record

Provided the official Operation Endgame account and the source-bound infrastructure, malware-family, and disruption totals used in the record.[4]Evidence dated Jun 24, 2026

Sources used
Netherlands

Dutch National Police and Netherlands Public Prosecution Service

Mandate and role

The Netherlands Police investigate national and transnational cybercrime and organized crime; the Public Prosecution Service directs criminal investigations and prosecutes criminal offenses under Dutch law.

Contribution to this record

Provided official Operation Endgame evidence on SocGholish/FakeUpdates, its relationship to Evil Corp, compromised WordPress delivery, 14,971 remediated websites, victim notification, and recommended recovery actions.[11]Evidence dated Jun 18, 2026

Sources used
United Kingdom

National Cyber Security Centre (NCSC)

Mandate and role

The United Kingdom's national technical authority for cyber security and a part of GCHQ, responsible for threat assessment, incident support, public guidance, and national cyber resilience.

Contribution to this record

Provided official campaign warnings covering LAUNDRY BEAR's Zimbra email-theft activity, APT28 router and DNS hijacking, Russian-aligned hacktivist disruption, and global Fortinet firewall and VPN credential targeting.[9][10]First cited source Jun 18, 2026 · Latest cited source Jul 23, 2026

Sources used
United States

National Institute of Standards and Technology / National Vulnerability Database (NIST NVD)

Mandate and role

NIST is the federal measurement and standards laboratory; its NVD is the U.S. government repository that enriches CVE records with standards-based vulnerability-management data.

Contribution to this record

Provided the official CVE-2026-0770 vulnerability record and its linked CISA KEV context for the Langflow monitoring priority.[5]Evidence dated Jul 22, 2026

Sources used

Source-Audit Transparency

Government Sources Checked but Not Used

Domestic, international, national-CSIRT, law-enforcement, regulator, and intergovernmental publication streams reviewed for relevance. These sources support no claim on this page and therefore do not appear in the Citations card.

United States

CISA

Publication streamCybersecurity AdvisoriesLast checked23-Jul-2026, 10:11 PM EDTReview dispositionPublication stream screened; no additional in-window item was needed beyond the retained KEV catalog and joint guidance.
United States

CISA

Publication streamIndustrial Control Systems AdvisoriesLast checked23-Jul-2026, 10:11 PM EDTReview dispositionScreened for in-window OT actions; no separate item was used to support a claim in this record.
United States

CISA

Publication streamCybersecurity DirectivesLast checked23-Jul-2026, 10:11 PM EDTReview dispositionChecked for an in-window emergency or binding directive; none was retained for the rolling-window narrative.
United States

FBI

Publication streamCyber NewsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionEndpoint check encountered publisher access controls; no FBI news claim was imported. FBI’s used contribution remains limited to the joint guidance cited as [2].
United States

FBI Internet Crime Complaint Center

Publication streamPublic Service AnnouncementsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionStream screened; no in-window PSA was necessary to substantiate the retained executive claims.
United States

NSA

Publication streamCybersecurity Advisories & Guidance LibraryLast checked23-Jul-2026, 10:11 PM EDTReview dispositionIndex endpoint was access-controlled during automated review; no item beyond the retained joint ATG release was used.
United States

U.S. Cyber Command

Publication streamNewsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionEndpoint was access-controlled during automated review; no claim from this stream was retained.
United States

Department of the Treasury / OFAC

Publication streamRecent ActionsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionSanctions and recent-action stream screened; no additional in-window action was used in the final four-lane narrative.
United States

Financial Crimes Enforcement Network

Publication streamNewsroomLast checked23-Jul-2026, 10:11 PM EDTReview dispositionFinancial-crime publication stream screened; no separate FinCEN evidence was needed for a retained claim.
United States

HHS Health Sector Cybersecurity Coordination Center

Publication streamHC3 ProductsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionEndpoint was access-controlled during automated review; no health-sector product was used in this record.
United States

Department of Energy

Publication streamCESER Cybersecurity and Emergency ResponseLast checked23-Jul-2026, 10:11 PM EDTReview dispositionProgram stream screened; DOE’s used contribution remains limited to its co-authorship of citation [2].
United States

Environmental Protection Agency

Publication streamCybersecurity for the Water SectorLast checked23-Jul-2026, 10:11 PM EDTReview dispositionSector guidance screened; no separate EPA water-sector page was used. EPA’s cited contribution remains the joint ATG guidance.
United States

Securities and Exchange Commission

Publication streamPress ReleasesLast checked23-Jul-2026, 10:11 PM EDTReview dispositionEndpoint was access-controlled during automated review; no SEC action was used in this card.
United States

Federal Communications Commission

Publication streamCybersecurityLast checked23-Jul-2026, 10:11 PM EDTReview dispositionEndpoint was access-controlled during automated review; no FCC evidence was retained.
United States

NIST Computer Security Resource Center

Publication streamNewsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionNews stream screened; no additional in-window item was used beyond the NVD record cited as [5].
United States

NIST National Cybersecurity Center of Excellence

Publication streamNews & InsightsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionEndpoint was access-controlled during automated review; no NCCoE claim was retained.
United Kingdom

National Crime Agency

Publication streamNewsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionEndpoint was access-controlled during automated review; no NCA claim was retained.
Canada

Canadian Centre for Cyber Security

Publication streamAlerts and AdvisoriesLast checked23-Jul-2026, 10:11 PM EDTReview dispositionNational alert stream screened; no additional in-window item was needed to support the retained claims.
Canada

Royal Canadian Mounted Police

Publication streamCybercrimeLast checked23-Jul-2026, 10:11 PM EDTReview dispositionFederal cybercrime stream screened; no distinct in-window operation was used.
Australia

Australian Federal Police

Publication streamNews CentreLast checked23-Jul-2026, 10:11 PM EDTReview dispositionLaw-enforcement news stream screened; no separate in-window cyber operation was retained.
New Zealand

National Cyber Security Centre

Publication streamNewsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionNational publication stream screened; no item was used in the final record.
European Union

European Union Agency for Cybersecurity (ENISA)

Publication streamNewsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionEU cybersecurity stream screened; no ENISA item was necessary for a retained claim.
European Union

CERT-EU

Publication streamPublicationsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionEU-institutional CSIRT publications screened; no separate product was retained.
International

INTERPOL

Publication streamCybercrimeLast checked23-Jul-2026, 10:11 PM EDTReview dispositionEndpoint was access-controlled during automated review; no INTERPOL claim was imported.
Germany

CERT-Bund / Federal Office for Information Security

Publication streamShort-form WarningsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionFederal warning stream screened; no item was used in this record.
France

CERT-FR / ANSSI

Publication streamAdvisories and AlertsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionNational CSIRT stream screened; no additional in-window item was retained.
France

ANSSI

Publication streamNewsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionNational cybersecurity news stream screened; no separate claim was used.
Netherlands

National Cyber Security Centre

Publication streamSecurity AdvisoriesLast checked23-Jul-2026, 10:11 PM EDTReview dispositionAdvisory stream screened; relevant vulnerability notices were not used because this card’s vulnerability claims are controlled by retained CISA/NVD sources.
Switzerland

National Cyber Security Centre

Publication streamCurrent FocusLast checked23-Jul-2026, 10:11 PM EDTReview dispositionNational publication stream screened; no Swiss item was retained.
Norway

National Security Authority / National Cyber Security Centre

Publication streamNational Cyber Security CentreLast checked23-Jul-2026, 10:11 PM EDTReview dispositionNational cyber stream screened; no additional in-window source was used.
Sweden

CERT-SE / Swedish Civil Contingencies Agency

Publication streamCERT-SELast checked23-Jul-2026, 10:11 PM EDTReview dispositionNational CSIRT stream screened; no item was retained.
Finland

National Cyber Security Centre Finland / Traficom

Publication streamAlertsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionNational alert stream screened; no item was used in this record.
Denmark

Centre for Cyber Security / Danish Agency for Societal Security

Publication streamCyber ThreatsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionLegacy publication route was checked and redirected to the current agency; no Danish claim was retained.
Estonia

Information System Authority / CERT-EE

Publication streamSituation in Cyberspace — June 2026Last checked23-Jul-2026, 10:11 PM EDTReview dispositionJune situational report reviewed; Estonia-specific incident statistics and events were outside the retained four-lane executive narrative and support no claim on this page.
Latvia

CERT.LV

Publication streamNational CSIRT PortalLast checked23-Jul-2026, 10:11 PM EDTReview dispositionEndpoint timed out during review; no Latvian content or claim was imported.
Lithuania

National Cyber Security Centre

Publication streamNational Cyber Security Centre PortalLast checked23-Jul-2026, 10:11 PM EDTReview dispositionEndpoint was access-controlled during automated review; no Lithuanian claim was imported.
Poland

CERT Polska / NASK

Publication streamCERT PolskaLast checked23-Jul-2026, 10:11 PM EDTReview dispositionNational CSIRT stream screened; no item was retained.
Japan

National Cybersecurity Office

Publication streamInternational Outreach and Joint AdvisoriesLast checked23-Jul-2026, 10:11 PM EDTReview dispositionGovernment coordination stream screened; no additional Japan-specific in-window item was used.
Japan

JPCERT Coordination Center

Publication streamAlerts and AdvisoriesLast checked23-Jul-2026, 10:11 PM EDTReview dispositionNational coordination-center stream screened; no item was retained.
Singapore

Cyber Security Agency of Singapore

Publication streamAlerts and AdvisoriesLast checked23-Jul-2026, 10:11 PM EDTReview dispositionEndpoint was access-controlled during automated review; no Singaporean claim was imported.
India

CERT-In

Publication streamVulnerability Notes and AdvisoriesLast checked23-Jul-2026, 10:11 PM EDTReview dispositionNational CSIRT advisory stream screened; no item was retained.
South Korea

KrCERT/CC

Publication streamNoticesLast checked23-Jul-2026, 10:11 PM EDTReview dispositionNational coordination-center stream screened; no item was used.
Israel

Israel National Cyber Directorate

Publication streamCyber AlertsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionEndpoint was access-controlled during automated review; no Israeli claim was imported.
Saudi Arabia

National Cybersecurity Authority

Publication streamCybersecurity AlertsLast checked23-Jul-2026, 10:11 PM EDTReview dispositionNational alert stream screened; no item was retained.
Americas

Organization of American States / CSIRTAmericas

Publication streamRegional CSIRT PortalLast checked23-Jul-2026, 10:11 PM EDTReview dispositionIntergovernmental regional stream screened; no item was used.
International

United Nations Office on Drugs and Crime

Publication streamCybercrimeLast checked23-Jul-2026, 10:11 PM EDTReview dispositionIntergovernmental cybercrime stream screened; no additional operational in-window claim was retained.

Automation Transparency

AI Agent Run Status

AgentGovernment Agencies Rolling Intelligence Card Publisher
StatusActive · production automation verified July 23, 2026
CadenceWeekly on Thursday at midday ET across U.S. and international government source streams, with one cumulative rolling 90-day analysis. Each run adds qualifying new evidence and removes evidence that has aged beyond the active window.
Previous runJuly 23, 2026 at 12:00 PM ET · Run #527
Previous resultSuccessful daily cron run. The rolling 90-day record remained publication-ready and the automation recorded a material revision.
What the previous run found
  • Zero new evidence items were promoted during the run.
  • Zero collection errors were recorded.
  • No new contributing upstream agent-run IDs were added.
  • Because a material revision event was recorded, the normal no-change notification suppression did not apply.
Next runJuly 30, 2026 at midday ET, derived from the verified weekly Thursday production cadence.
Sources monitored
  • CISA advisories, KEV changes, alerts, news releases, blogs, directives, and joint publications
  • Official FBI, DOJ, NSA, Treasury/OFAC, sector-agency, regulator, and U.S. government publications
  • UK NCSC, Europol, ENISA, ASD ACSC, national CSIRTs, international law-enforcement, and partner-government publications
  • Government-linked public source streams, retained news reporting, structured report events, and source-audit records
  • PETRA report database query constrained to the active rolling 90-day publication window; older reports remain discovery-only
Publication and alert policyMaintain one cumulative rolling 90-day IntelliOS synthesis, publish material source-backed changes after the weekly evidence gate passes, and issue Page Alerts only for a material revision. Routine no-change checks and date-only window movement do not generate subscriber notifications.

Related Intelligence and CARDS Records

Other IntelliOS Products

PANDA CVE Watch Brief

CVE-2025-68686 — FortiOS Persistence Patch Bypass

Affected releases, fixed branches, KEV deadline, post-compromise prerequisite, hunting questions, and incident-response actions.

Open product

PANDA Flash Threat Brief

FortiOS Persistence Bypass Under Active Exploitation

Executive and technical treatment of the FortiOS patch bypass, historical exposure, evidence preservation, and trust recovery.

Open product

PANDA Flash Threat Brief

Langflow AI Workflow Servers Under Active Exploitation

Executive and technical treatment of CVE-2026-0770, related Langflow vulnerabilities, active exploitation, response priorities, and source boundaries.

Open product

PANDA Flash Threat Brief

INC Ransom Exploits SonicWall SMA1000 Zero Days

Source-bound treatment of CVE-2026-15409, CVE-2026-15410, the reported ransomware outcome, UTA0533, containment, and recovery.

Open product

CARDS Campaign Record

SonicWall SMA1000 Zero-Day Exploitation Campaign

Campaign timeline, affected products, reported activity, source agreement, actors, tools, CVEs, and attribution boundaries.

Open product

FORGE Intelligence Tracker

Law-Enforcement Takedown Operations Tracker

Continuing coverage of Operation Endgame, DOJ / FBI scam-center disruption activity, infrastructure actions, actor pressure, and reconstitution.

Open product

CARDS Actor Record

INC Ransom Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS Actor Record

UTA0533 Actor Card

Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.

Open product

CARDS CVE / KEV Record

CVE-2025-68686 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-20262 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-35273 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

CARDS CVE / KEV Record

CVE-2026-50751 Vulnerability Record

Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.

Open product

Publication History

Version Change Log

Versionv32Date28-Jul-2026ChangeAdded CISA’s July 27 KEV action for FortiOS CVE-2025-68686, Fortinet’s affected and fixed releases, the August 10 federal deadline, and the requirement to pair remediation with BOD 26-04 forensic triage. Linked the new CVE Watch and Flash Threat Briefs.MonitoringDaily KEV check plus weekly Thursday rolling 90-day review
Versionv31Date26-Jul-2026ChangeReplaced the abstract KEV ransomware-status wording with a concrete operating conclusion: an “Unknown” ransomware-use field does not lower the remediation deadline, change the confirmed-exploitation status, or support an all-clear. The revised point also names the separate sources that control SMA1000 exploitation, activity-cluster, and ransomware-attribution claims.MonitoringWeekly Thursday rolling 90-day check and material-change publication
Versionv30Date24-Jul-2026ChangeAdded the PETRA report database to the Tier 6 discovery audit and weekly source monitor. The Apr 26–Jul 24 publication-date query returned no qualifying report, so PETRA is disclosed as checked but not used.MonitoringWeekly Thursday rolling 90-day check and material-change publication
Versionv29Date24-Jul-2026ChangeEmbedded the complete Tier 0–Tier 8 source audit in Research Framing, including all retained sources, the 46 government publication streams checked but not used, and the role of internal source-audit tooling.MonitoringWeekly Thursday rolling 90-day check and material-change publication
Versionv28Date24-Jul-2026ChangeAdded a source-cited evidence-mix donut chart distinguishing official government publications from retained primary research, incident-response reporting, and ecosystem monitoring.MonitoringWeekly Thursday rolling 90-day check and material-change publication
Versionv27Date24-Jul-2026ChangeMoved Timeline of Notable Activity ahead of BLUF and expanded it to 17 source-backed milestones covering KEV additions and deadlines, government warnings about Fortinet and Zimbra campaigns, automatic-tank-gauge guidance, Scam Center Disruption Week, SocGholish and Operation Endgame, and the SonicWall and Langflow exploitation timelines.MonitoringDaily rolling 90-day collection and material-change publication
Versionv26Date24-Jul-2026ChangeLocked BLUF and Executive Summary as mandatory cards and ensured both remain visible and expanded by default regardless of prior optional-card preferences.MonitoringDaily rolling 90-day collection and cumulative publication
Versionv25Date24-Jul-2026ChangeChanged Rolling 90-Day Intelligence Snapshot from a locked default card to an optional drawer-controlled card that is hidden and collapsed on a fresh load, making BLUF the first visible briefing card.MonitoringDaily rolling 90-day collection and cumulative publication
Versionv24Date24-Jul-2026ChangeAdded a six-point, source-cited BLUF before Executive Summary; made BLUF visible, locked, and open by default; and made Persona / Audience optional, hidden, and collapsed by default.MonitoringDaily rolling 90-day collection and cumulative publication
Versionv23Date24-Jul-2026ChangeChanged Research Framing from a locked default card to an optional drawer-controlled card that is hidden and collapsed on a fresh page load.MonitoringDaily rolling 90-day collection and cumulative publication
Versionv22Date24-Jul-2026ChangeMoved Other IntelliOS Products ahead of Version Change Log in both the Rolling Intelligence Card stack and right-side Cards drawer, while retaining AI Agent Run Status before both and Citations as the final card.MonitoringDaily rolling 90-day collection and cumulative publication
Versionv21Date24-Jul-2026ChangeAdded a source-backed Malware Summary table covering SocGholish/FakeUpdates, Amadey, StealC, ROOTRUN, KNUCKLEBALL, Suo5, ORANGETAIL, Beehive/Ulej, and the reported but publicly uncharacterized ransomware payload; added Dutch Police and Microsoft DCU evidence and the Dutch government contributor record.MonitoringDaily rolling 90-day collection and cumulative publication
Versionv20Date24-Jul-2026ChangeCompleted a card-by-card specificity pass: named CISA, FBI, NSA, DOJ, Europol, UK NCSC, partner agencies, vendors, incident responders, and reporting roles in the analysis; added concrete CVE, technology, campaign, victimology, and disruption examples; and strengthened source-attribution boundaries throughout.MonitoringDaily rolling 90-day collection and cumulative publication
Versionv19Date24-Jul-2026ChangeAdded Research Framing as card 1 with the user topic, interpreted questions, initial source-bound observations, a tiered source-coverage ledger, and the evidence boundary; shifted every existing Government Rolling Intelligence Card section number up by one.MonitoringDaily rolling 90-day collection and cumulative publication
Versionv18Date24-Jul-2026ChangeRemoved June-only counts and month-bound conclusions from the rolling government analysis; reframed KEV governance, monitoring, best-practice, actor, and snapshot language around the active 90-day evidence window while retaining dated June events that remain inside coverage.MonitoringDaily rolling 90-day collection and cumulative publication
Versionv17Date24-Jul-2026ChangeConverted every Rolling Intelligence Card from a hard-coded monthly edition to a daily rolling 90-day snapshot; added dynamic coverage dates; excluded sources, timeline events, government campaigns, source checks, and change-log entries outside the active window; and changed the Rolling Intelligence Cards home page default to two result rows.MonitoringDaily rolling 90-day collection and cumulative publication
Versionv16Date24-Jul-2026ChangeAdded a Persona / Audience card defining the U.S., executive, SMB and midmarket, enterprise, critical-infrastructure, and functional-reader orientation; made every Rolling Intelligence Card section collapsible; and set cards 1, 2, 3, 4, 6, 7, 8, and 9 open by default.MonitoringDaily collection; monthly cumulative publication
Versionv15Date24-Jul-2026ChangeNumbered every Rolling Intelligence Card section and added the right-side Cards drawer with jump navigation, section visibility controls, and drag reordering.MonitoringDaily collection; monthly cumulative publication
Versionv14Date24-Jul-2026ChangeConverted Government Sources Checked but Not Used into a responsive four-column source-audit table covering government source, linked publication stream, last-checked date, and review disposition.MonitoringDaily collection; monthly cumulative publication
Versionv13Date24-Jul-2026ChangeConverted Government Contributors Used in This Record into a responsive four-column comparison table covering each contributor, institutional mandate, contribution to the record, and sources used.MonitoringDaily collection; monthly cumulative publication
Versionv12Date24-Jul-2026ChangeRebuilt Exploitable Technologies for Companies as a true three-column comparison table at standard desktop widths, grouping each technology with its exploit condition, company exposure and business risk, and monitoring plus IntelliOS coverage.MonitoringDaily collection; monthly cumulative publication
Versionv11Date23-Jul-2026ChangeConsolidated the four standalone reporting-period metric tiles into a single Monthly Intelligence Snapshot card with a responsive internal statistics grid and clearer source context.MonitoringDaily collection; monthly cumulative publication; next run 24-Jul-2026
Versionv10Date23-Jul-2026ChangeRemoved the standalone Connected CARDS card and rolled its actor, campaign, and CVE/KEV relationships into the renamed Other IntelliOS Products card, with duplicate destinations suppressed.MonitoringDaily collection; monthly cumulative publication; next run 24-Jul-2026
Versionv9Date23-Jul-2026ChangeReframed the product as the monthly cumulative output of a daily multi-government AI-agent review; added a ten-row Exploitable Technologies for Companies table and an eight-row source-bound Victimology Matrix; reordered the page; moved related IntelliOS products near the end; removed the generic signals/impact/priorities card; and retired the redundant standalone CISA weekly page and agent.MonitoringDaily collection; monthly cumulative publication; next run 24-Jul-2026
Versionv8Date23-Jul-2026ChangeRemoved the generic Campaigns & Government Operations card and replaced it with a seven-row Government-Flagged Threat Actor Campaigns table. Added retained NCSC and ACSC campaign notices, explicit government-attribution boundaries, monitoring requirements, IntelliOS links, and corresponding contributor/source-audit updates.MonitoringSuperseded by v9
Versionv7Date23-Jul-2026ChangeAdded an eight-part, source-cited Best Practices and Lessons Learned card covering KEV governance, control-plane inventory, historical-exposure investigation, exploit chaining, identity response, evidence preservation, disruption follow-through, and source-bound attribution.MonitoringSuperseded by v9
Versionv6Date23-Jul-2026ChangeAdded a source-bound Timeline of Notable Activity that distinguishes observed compromise dates, government publication and disclosure dates, KEV additions, and required-action deadlines.MonitoringSuperseded by v9
Versionv5Date23-Jul-2026ChangeAdded a complete government-contributor table for every agency whose cited material informed the record, including each agency’s role and exact information sources; added a 48-row domestic and international government-source audit with per-source review timestamps and non-use dispositions.MonitoringSuperseded by v9
Versionv4Date23-Jul-2026ChangeRemoved the standalone decision-question section; converted the monitoring priorities into one coherent ten-row table; added five named priorities; and added dedicated AI Agent Status and Version Change Log cards.MonitoringSuperseded by v9
Versionv3Date23-Jul-2026ChangeAdded the six-paragraph cited Executive Summary, the first five specific monitoring priorities, and direct links to existing IntelliOS briefs, trackers, CARDS records, actor cards, and the campaign card.MonitoringSuperseded by v9
Versionv2Date23-Jul-2026ChangeRewrote the Top 10 Briefing Points for executive use and separated campaigns, notable actors, affected technologies, and source-bound operational context.MonitoringSuperseded by v9
Versionv1Date18-Jul-2026ChangeInitial June 2026 Government Cybersecurity Actions & Advisories Rolling Intelligence Card publication with official-source metrics, briefing points, defensive priorities, and citations.MonitoringSuperseded by v9

Citations

Retained Sources and Claim Treatment

Source1PublisherCISAPublished2026-06Publication / evidenceSource indexofficialWhy used / claim treatmentCISA's controlling catalog for vulnerabilities known to be exploited in the wild. A KEV listing establishes observed exploitation, not exploitation in every environment or attribution to a specific actor.SourceKnown Exploited Vulnerabilities Catalog

https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

Source2PublisherNSA, CISA, FBI, DOE, EPA, TSA, DOT, and USDAPublished2026-06-03Publication / evidenceSource indexofficialWhy used / claim treatmentJoint defensive guidance from NSA, CISA, FBI, DOE, EPA, TSA, DOT, and USDA for internet-exposed operational technology. The agencies report observed malicious activity against automatic tank gauges; the notice does not establish compromise of every deployment.SourceNSA Joins CISA and Partners to Release Guidance on Hardening Automatic Tank Gauges

https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4507204/nsa-joins-cisa-and-partners-to-release-guidance-on-hardening-automatic-tank-gau/

Source3PublisherU.S. Department of JusticePublished2026-06-03Publication / evidenceSource indexofficialWhy used / claim treatmentOfficial DOJ account of a Scam Center Strike Force action supported by the FBI, U.S. Secret Service, HSI, foreign law enforcement, and named technology and financial companies. It is retained here as a government-action signal and routed to the Law Enforcement Disruption Rolling Intelligence Card for operation-level treatment.SourceScam Center Strike Force Announces Results of U.S.-Private Industry Disruption Week

https://www.justice.gov/opa/pr/scam-center-strike-force-announces-results-us-private-industry-disruption-week

Source4PublisherEuropolPublished2026-06-24Publication / evidenceSource indexofficialWhy used / claim treatmentOfficial international disruption reporting. It demonstrates cross-border action against named infrastructure, but does not prove permanent eradication of the malware ecosystems.SourceGlobal cyber strike disrupts SocGholish, Amadey and StealC malware networks

https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks

Source5PublisherNIST National Vulnerability Database / CISAPublished2026-07-22Publication / evidenceSource indexofficialWhy used / claim treatmentOfficial vulnerability and KEV context for unauthenticated Langflow remote code execution. The record establishes active exploitation and root-level technical impact, not compromise of every Langflow deployment.SourceCVE-2026-0770 Detail

https://nvd.nist.gov/vuln/detail/CVE-2026-0770

Source6PublisherSonicWall PSIRTPublished2026-07-14Publication / evidenceSource indexofficialWhy used / claim treatmentVendor advisory controlling affected-product, authentication, severity, fixed-release, and mitigation language for CVE-2026-15409 and CVE-2026-15410. Separate reporting controls actor attribution.SourceSonicWall SMA1000 Security Advisory SNWLID-2026-0008

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

Source7PublisherDark ReadingPublished2026-07-22Publication / evidenceSource indexecosystem monitorWhy used / claim treatmentSecondary reporting retained specifically for the reported INC Ransom association and ransomware outcome. It is not substituted for SonicWall, Rapid7, or Volexity technical evidence.SourceSonicWall SMA1000 zero-day flaws exploited by INC ransomware group

https://www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days

Source8PublisherVolexityPublished2026-07-17Publication / evidenceSource indexincident responseWhy used / claim treatmentPrimary incident-response research retained for exploitation and UTA0533 activity-cluster context. The public evidence does not establish that UTA0533 and INC Ransom are the same operator.SourceProxying to Compromise: SonicWall Secure Mobile Access 0-Day Exploitation

https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/

Source9PublisherUK National Cyber Security CentrePublished2026-07-23Publication / evidenceSource indexofficialWhy used / claim treatmentOfficial UK and partner-government attribution and campaign warning for LAUNDRY BEAR's ongoing Zimbra 'beehive/Ulej' email-theft activity. The notice controls the Russian state-support assessment and named targeting scope.SourceUK and partners expose Russian state-supported actors for new zero-click phishing campaign targeting Western organisations

https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign

Source10PublisherUK National Cyber Security CentrePublished2026-06-18Publication / evidenceSource indexofficialWhy used / claim treatmentOfficial UK alert on the FortiBleed credential campaign affecting internet-facing Fortinet firewalls and VPN gateways. It establishes government-recognized campaign and response context but does not name the responsible actor.SourceNCSC issues advice following global targeting of Fortinet firewalls and VPN gateways

https://www.ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways

Source11PublisherDutch National Police and Netherlands Public Prosecution ServicePublished2026-06-18Publication / evidenceSource indexofficialWhy used / claim treatmentOfficial Operation Endgame reporting on SocGholish/FakeUpdates, its Evil Corp relationship, compromised WordPress delivery, 14,971 remediated websites, victim notification, and defensive actions. It does not name the affected companies.SourcePolitie en OM openen de jacht op beruchte malwaregroep SocGholish

https://www.politie.nl/nieuws/2026/juni/18/11-politie-en-om-openen-de-jacht-op-beruchte-malwaregroep-socgholish.html

Source12PublisherMicrosoft Digital Crimes UnitPublished2026-06-24Publication / evidenceSource indexprimary researchWhy used / claim treatmentPrimary private-sector partner reporting on the distinct roles of Amadey and StealC, their shared infrastructure, combined infection scale, and Microsoft-led disruption. Europol remains the controlling government source for Operation Endgame.SourceScaling cybercrime disruption through innovation and AI

https://blogs.microsoft.com/on-the-issues/2026/06/24/scaling-cybercrime-disruption-through-innovation-and-ai/

Source13PublisherCISAPublished2026-07-27Publication / evidenceSource indexofficialWhy used / claim treatmentCISA controls known-exploitation status, the August 10 federal required-action date, the Unknown ransomware-use field, internet-exposure assessment, and the requirement to apply vendor mitigations with BOD 26-04 forensic triage. The entry does not identify an actor, victim, initial-access vulnerability, or local compromise.SourceCVE-2025-68686 Known Exploited Vulnerability and BOD 26-04 Required Action

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68686