KEV deadline cycle
June opens with an exploited Oracle WebLogic vulnerability
CISA added CVE-2024-21182 to KEV with a June 4 required-action date, establishing the month’s first three-day federal remediation window.[1]
AI-generated, AI-updated weekly, AI quality-checked, and source-cited, this 90-day Rolling Intelligence Card reviews CISA, FBI, NSA, DOJ, UK NCSC, Europol, ASD ACSC, sector agencies, partner governments, and qualified supporting reporting. It reconciles overlapping notices and promotes only exploited technologies, threat actors, campaigns, victimology, deadlines, and government actions that materially change company risk.
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | Government cybersecurity advisories, exploited technologies, official publications, disruption actions, and government-flagged threat actor campaigns that materially change company risk during the active rolling 90-day window. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | Which exploited technologies, KEV deadlines, named actors and campaigns, victim patterns, hardening notices, and government disruption actions matter most to U.S. organizations? Which claims are authoritative, which are corroborating, what remains uncertain, and what should executives and operational owners decide now? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | The retained evidence supports five concrete decision lanes. CISA’s KEV catalog establishes active-exploitation and remediation urgency; the July 27 CVE-2025-68686 addition adds a FortiOS post-compromise persistence case that explicitly requires forensic triage as well as a fixed release; NSA, CISA, FBI, and sector agencies identify exposed automatic tank gauges as an operational-technology risk; DOJ and the FBI describe public-private disruption of scam infrastructure and funds; and Europol’s Operation Endgame identifies SocGholish, Amadey, and StealC infrastructure that should be hunted locally. UK NCSC campaign notices, SonicWall and Fortinet vendor guidance, Volexity incident-response observations, and Dark Reading’s INC Ransom reporting add source-specific actor, victimology, technical, and attribution context. The record does not convert exposure or targeting into an unsupported local-compromise conclusion.[1][2][3][4][6][7][8][9][10][11][12][13]First cited source Jun 2026 · Latest cited source Jul 27, 2026 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
Complete Tier 0–8 counts are shown here. The 13 retained sources and their claim treatment are identified in Citations. Planned integrations are not counted as checked or selected. |
Reporting-Period Statistics
At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.
Period Coverage
90 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.
Coverage model
One cumulative window advances daily across CISA, FBI, NSA, DOJ, UK NCSC, Europol, partner-government, vendor, and retained research sourcesFirst cited source Jun 2026 · Latest cited source Jul 23, 2026
Weekly[1][2][3][4][6][7][8][9]
Collection cadence
Official U.S. and international sources are reviewed every Thursday; qualifying vendor, incident-response, and corroborating evidence is retained with source roles preservedFirst cited source Jun 2026 · Latest cited source Jul 23, 2026
Continuous[1]
KEV operating model
Each new CISA KEV enters asset discovery, exposure, ownership, remediation, and—when historical reachability exists—incident investigationEvidence dated Jun 2026
18
sources
Retained evidence source mix
Official government and vendor publications dominate the retained record; supporting research is preserved as a separate evidence class.[1][2][3][4][5][6][7][8][9][10][11][12][13]First cited source Jun 2026 · Latest cited source Jul 27, 2026
Intended Reader and Decision Context
Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.
| Audience Field | Assessment |
|---|---|
| Audience fieldPrimary audience | AssessmentU.S.-based executives, board and risk leaders, CISOs, CIOs, security directors, and operational owners who need a decision-ready view of government-reported cyber activity. |
| Audience fieldOrganization profile | AssessmentDesigned first for small and midsize businesses and midmarket organizations, while remaining applicable to enterprises, critical-infrastructure operators, managed service providers, and organizations with internet-facing IT or operational-technology control systems. |
| Audience fieldGeographic orientation | AssessmentU.S.-oriented in its executive decisions, KEV implications, and company-risk framing. International government reporting is incorporated when it identifies campaigns, actors, exploited technologies, victim patterns, or disruption activity relevant to U.S. organizations. |
| Audience fieldFunctional readers | AssessmentExecutive leadership; vulnerability and exposure management; security operations; incident response; IT and OT operations; identity teams; vendor and third-party risk; legal, compliance, communications, and insurance stakeholders. |
| Audience fieldDecision perspective | AssessmentWritten to translate government notices into company-specific exposure, investigation, ownership, monitoring, and escalation decisions—not to reproduce an agency-news digest or provide a federal-only compliance checklist. |
| Audience fieldExpected use | AssessmentUse the brief to turn specific notices—such as a CISA KEV addition, an FBI/NSA/CISA joint warning, a DOJ disruption, or a UK NCSC campaign attribution—into asset priorities, accountable owners, incident-response thresholds, internal telemetry requirements, and connected IntelliOS products. |
Chronology and Decision Milestones
Observed activity, public disclosure, KEV catalog action, and required-action deadlines are labeled separately. Later reporting is not backdated to imply that it was public on the underlying activity date.
KEV deadline cycle
CISA added CVE-2024-21182 to KEV with a June 4 required-action date, establishing the month’s first three-day federal remediation window.[1]
Critical-infrastructure guidance
NSA, CISA, FBI, DOE, EPA, TSA, DOT, and USDA warned that unattributed actors had compromised and modified internet-exposed automatic tank gauges, then called for owners to identify, isolate, and harden these operational-technology systems.[2]
Public-private disruption
DOJ announced that FBI, Secret Service, and HSI target information—combined with foreign-law-enforcement and named private-sector action—helped disrupt more than 1.4 million accounts and freeze more than $3.8 million in cryptocurrency.[3]
Enterprise application KEV
CISA added CVE-2026-35273 to KEV with a June 15 required-action date. The exploited HTTP-takeover condition affects PeopleSoft PeopleTools, a platform commonly trusted with HR, finance, identity, and administrative workflows; asset ownership and prior internet exposure therefore matter as much as the patch ticket.[1]
Network control-plane KEV
CISA added Cisco Catalyst SD-WAN Manager CVE-2026-20262 and LiteSpeed cPanel Plugin CVE-2026-54420. The Cisco flaw permits arbitrary file write in a distributed network control plane, while the LiteSpeed entry raises privilege and shared-hosting concerns; both reinforce that trusted administrative reach should drive priority.[1]
Government campaign warning
The NCSC described a global campaign using brute force, dictionary attacks, credential stuffing, and leaked credential material against internet-facing FortiGate firewalls and SSL VPN gateways. The notice creates a credential-rotation, session-review, MFA, and management-interface decision—not merely a firmware check.[10]
Operation Endgame precursor
Dutch police and prosecutors described SocGholish/FakeUpdates delivery through compromised WordPress sites, its relationship to Evil Corp, and remediation of 14,971 infected websites. That victim-notification and website-remediation context explains the infrastructure targeted in the broader June 24 Operation Endgame action.[11]
Observed compromise
Volexity identified June 22 as the earliest sign of compromise in the activity it tracks as UTA0533, including rootrun execution associated with the KNUCKLEBALL backdoor. The observed chain included appliance compromise, credential and session access, and follow-on activity; June 22 is an activity date, not the later public-disclosure date.[8]
Largest June KEV batch
CISA added four vulnerabilities—the window’s largest single-day retained batch—including Lantronix EDS5000 and three Ubiquiti UniFi OS entries, all with June 26 required-action dates. The three-day window concentrated asset discovery, public-interface validation, configuration review, and remediation across industrial and distributed network-management systems.[1]
International disruption
Europol and international partners announced action against servers, domains, infected websites, credentials, and criminal assets supporting SocGholish, Amadey, and StealC. Microsoft separately described the distinct delivery, credential-theft, fraud, and ransomware-enablement roles of Amadey and StealC. The action created a retro-hunting and credential-reset window; it did not establish permanent eradication.[4][11][12]
Remote-management KEV
CISA added SimpleHelp CVE-2026-48558 with a July 2 required-action date. Because one remote-support server can administer many endpoints or customer environments, the required response includes administrator and session review, endpoint fan-out analysis, and investigation of the historical exposure window.[1]
Disclosure and KEV escalation
SonicWall published its advisory and CISA added CVE-2026-15409 and CVE-2026-15410 with a July 17 deadline. The chain uses unauthenticated server-side request forgery to reach a privileged internal workflow, then abuses the authenticated-administrator hotfix-removal path for traversal and command execution as root. The second flaw is post-authentication when considered alone.[1][6]
Technical disclosure
Volexity documented the SMA1000 exploitation path, root-level execution, KNUCKLEBALL and related tooling, credential, session, and TOTP access, and appliance-sourced follow-on activity. The report preserves UTA0533 as a source-specific cluster label and does not equate it with INC Ransom.[8]
AI infrastructure KEV
The unauthenticated remote-code-execution vulnerability received a July 24 required-action date. Because affected Langflow servers can run in a root context and may hold model credentials, API keys, secrets, data connectors, and trusted automation, organizations need both immediate remediation and investigation of prior public exposure.[1][5]
Ransomware reporting
Dark Reading reported that Rapid7 tied the SMA1000 activity to INC Ransom and observed a ransomware outcome. IntelliOS preserves that secondary attribution separately from Volexity’s UTA0533 label because the retained public evidence does not establish that the two names identify the same operator.[7][8]
Joint government attribution
UK NCSC and a 15-country partner group described an ongoing Russian state-supported campaign in which viewing a malicious message on a vulnerable Zimbra deployment can trigger zero-click email theft. The notice names defence, government, education, energy, law-enforcement, media, NGO, and technology targeting and says AI assisted development of the campaign’s simple codebase.[9]
Required-action deadline
CISA’s required-action date for CVE-2026-0770 arrives. Organizations should be able to demonstrate Langflow asset discovery, ownership, internet-exposure assessment, remediation or isolation, secret and connector review, and investigation of any prior public reachability; a current fixed version does not by itself prove the server was not previously compromised.[1][5]
FortiOS KEV and forensic triage
CISA added CVE-2025-68686 with an August 10 required-action date and explicitly referenced BOD 26-04 Forensics Triage Requirements. Fortinet says exploitation requires prior filesystem-level compromise through another vulnerability, so owners must apply 7.6.2+ or 7.4.7+ and determine whether attacker-controlled state, credentials, configuration, or downstream access survived.[13]
Bottom Line Up Front
New FortiOS action: CISA added CVE-2025-68686 on July 27 with an August 10 federal deadline and a requirement for vendor mitigation plus BOD 26-04 forensic triage. Fortinet says the flaw bypasses a fix for symbolic-link persistence after an attacker already achieved filesystem-level compromise; previously exposed devices therefore need a fixed release and a retrospective integrity investigation.[13]Evidence dated Jul 27, 2026
Immediate priority: Do not treat this as a routine patch list. CISA’s KEV catalog says the listed vulnerabilities are being exploited. The most urgent checks in this record include internet-facing Langflow servers affected by CVE-2026-0770, SonicWall SMA1000 appliances affected by CVE-2026-15409 and CVE-2026-15410, and exposed management products such as Cisco SD-WAN Manager, SimpleHelp, Check Point gateways, Oracle PeopleSoft, Ubiquiti UniFi OS, and Lantronix EDS5000.[1][5][6]First cited source Jun 2026 · Latest cited source Jul 22, 2026
Why these systems matter: These products sit in trusted positions: they manage remote access, networks, endpoints, enterprise applications, or automated AI workflows. A successful attacker may inherit that trust, steal credentials or sessions, reach connected systems, and move farther into the organization. The risk is therefore larger than damage to one vulnerable server.[1][5][6][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026
Physical operations are in scope: NSA, CISA, FBI, DOE, EPA, TSA, DOT, and USDA reported that attackers compromised internet-exposed automatic tank gauges and changed them through remote commands. Companies that store fuel or other liquids should verify gauge ownership and internet exposure because bad readings or unavailable systems can affect inventory, leak detection, safety, environmental obligations, and operations.[2]Evidence dated Jun 3, 2026
Government disruption creates local hunting work: Europol’s action against SocGholish, Amadey, and StealC reduced criminal infrastructure; it did not prove that earlier infections, stolen passwords, or surviving operators disappeared. DOJ’s scam-center disruption likewise shows why companies must be ready to preserve evidence and coordinate quickly with technology providers, banks, and law enforcement when accounts or funds are at risk.[3][4]First cited source Jun 3, 2026 · Latest cited source Jun 24, 2026
Keep attribution honest: CISA and SonicWall establish that the two SMA1000 vulnerabilities were exploited, Volexity tracks overlapping activity as UTA0533, and Dark Reading reports an INC Ransom connection and a ransomware outcome. Those labels should be monitored together but not merged into one actor identity without stronger public evidence.[1][6][7][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026
Executive decision: Require proof for each exposed asset: who owns it, whether it was fixed or isolated, whether prior exposure was investigated, whether relevant credentials and sessions were reset, and who accepted any deadline exception. If the system was exposed and reliable historical logs are missing, treat that uncertainty as a possible incident—not as evidence that nothing happened.[1][2][5][6][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026
Decision Context
The July 27 addition of FortiOS CVE-2025-68686 sharpens the difference between vulnerability closure and incident closure. CISA now confirms exploitation and requires vendor action plus BOD 26-04 forensic triage by August 10 for federal civilian agencies. Fortinet describes the issue as a patch bypass for a symbolic-link persistence mechanism observed after an attacker already obtained filesystem-level control through another vulnerability. A previously exposed FortiOS device therefore needs a fixed release, preserved evidence, historical hunting, and a defensible integrity decision; a changed version number alone cannot answer whether attacker-controlled state survived.[13]Evidence dated Jul 27, 2026
The current rolling 90-day government cybersecurity record should be read as an executive decision framework, not as a digest of agency announcements. Across the retained window, CISA repeatedly added actively exploited vulnerabilities with required-action dates measured in days rather than normal monthly patch cycles. The practical consequence is that ownership, internet exposure, exception authority, and evidence of completion must be visible at the asset level whenever new KEV evidence enters the window.[1]Evidence dated Jun 2026
The most consequential exposures are not necessarily the systems with the largest user populations; they are the systems that administer, connect, or authenticate other systems. CISA’s retained KEV entries include Langflow AI workflow servers, SonicWall SMA1000 remote-access appliances, Cisco SD-WAN Manager, Oracle PeopleSoft, Check Point VPN gateways, SimpleHelp remote-support servers, and Ubiquiti or Lantronix management interfaces. Compromise of one of these control planes can give an attacker inherited trust across customers, sites, identities, and internal environments, turning a vulnerability-management failure into an incident-response and business-continuity event.[1]Evidence dated Jun 2026
Government guidance also pushed operational technology into the same executive exposure conversation. NSA, CISA, FBI, DOE, EPA, TSA, DOT, and USDA reported malicious actors compromising internet-exposed automatic tank gauges and modifying them through command execution. For operators in energy, chemical, food and agriculture, or transportation environments, this is not merely a software issue: altered readings or unavailable gauges can affect physical inventory, leak detection, safety, environmental obligations, and continuity of operations.[2]Evidence dated Jun 3, 2026
The retained window also demonstrates that public-private disruption is becoming an operational defensive instrument. DOJ’s Scam Center Disruption Week used information from the FBI, U.S. Secret Service, and HSI with foreign law enforcement and companies including Apple, Coinbase, Google, Meta, Microsoft, SpaceX, and others; the announced results included disruption across more than 1.4 million accounts and the freezing of more than $3.8 million in cryptocurrency. Executives should ensure their organizations can rapidly preserve evidence, act on trusted indicators, and coordinate with providers or financial institutions when government action creates a narrow intervention window.[3]Evidence dated Jun 3, 2026
Operation Endgame illustrates the other side of the same model: ecosystem disruption can reduce adversary capacity without eliminating the underlying threat. Europol and partners acted against infrastructure supporting SocGholish, Amadey, and StealC, including servers, domains, infected websites, credentials, and criminal assets. Defenders should convert the operation into retro-hunting, credential review, and successor-infrastructure monitoring rather than assume that previously stolen access or surviving operator capability disappeared.[4]Evidence dated Jun 24, 2026
The executive decision is therefore broader than whether individual KEV tickets were closed. Leadership should require a continuing watchlist that joins new deadlines to exposed-asset ownership, links named campaigns and actors to internal telemetry, and identifies when remediation must become investigation. Current Langflow and SonicWall exploitation illustrate why that operating model must persist: both concern internet-reachable control software, active exploitation, compressed response expectations, and the need to assess historical exposure—not only current version status.[1][5][6][7][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026
Executive Briefing Priorities
FortiOS CVE-2025-68686 makes forensic triage part of the required action — The July 27 KEV entry is not a stand-alone initial-access story. Fortinet says the patch bypass applies after another vulnerability already produced filesystem-level compromise. Owners must identify affected 7.6, 7.4, 7.2, 7.0, and 6.4 devices, move to a documented fixed branch, preserve evidence, and determine whether persistence, configuration changes, credentials, or downstream trust survived.[13]Evidence dated Jul 27, 2026
CISA KEV turns vulnerability management into deadline governance — CISA’s catalog confirms exploitation in the wild and repeatedly imposed action windows measured in days: Oracle WebLogic and PeopleSoft received three-day windows, while Langflow CVE-2026-0770 received a July 24 deadline. Executives need an accountable technical and business owner for every matched asset, exception, and compensating control.[1][5]First cited source Jun 2026 · Latest cited source Jul 22, 2026
Control-plane technologies deserve priority over raw CVSS sorting — CISA’s retained KEV entries include Cisco SD-WAN Manager, SonicWall SMA1000, Check Point VPN gateways, SimpleHelp remote support, Langflow AI workflows, and Oracle PeopleSoft. These systems administer networks, identities, endpoints, data, or automation; compromise can inherit trusted reach far beyond the vulnerable server.[1][5][6]First cited source Jun 2026 · Latest cited source Jul 22, 2026
“Known ransomware use: Unknown” does not lower a KEV remediation deadline — CISA uses “Unknown” when its catalog does not identify a ransomware connection for that vulnerability. The entry still represents confirmed exploitation in the wild and keeps its required-action date. For SMA1000, review CISA and SonicWall for the exploited CVEs, Volexity for UTA0533 activity, and the separate INC Ransom reporting before making an attribution.[1][6][7][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026
FBI, NSA, CISA, and sector agencies elevated exposed tank gauges into a physical-risk issue — The joint warning says unattributed actors compromised internet-exposed automatic tank gauges and modified them through command execution. DOE, EPA, TSA, DOT, and USDA participation reflects the potential consequences to fuel and liquid inventory, leak detection, safety, environmental obligations, and transportation or agricultural continuity.[2]Evidence dated Jun 3, 2026
A patch closes a path; it does not prove the asset remained trustworthy — CISA and vendor remediation establish what must be fixed now. Volexity’s SMA1000 incident-response evidence shows why leaders must also ask whether the appliance was exposed before disclosure, whether logs exist, and whether credentials, sessions, TOTP material, or downstream systems require investigation.[1][6][8]First cited source Jun 2026 · Latest cited source Jul 17, 2026
DOJ and FBI disruption reporting should become a company response trigger — DOJ’s Scam Center Disruption Week used FBI, Secret Service, HSI, foreign-law-enforcement, and private-sector information to disrupt more than 1.4 million accounts and freeze more than $3.8 million. Companies should be ready to preserve evidence, validate named infrastructure, protect customers and payment workflows, and respond quickly to trusted provider or law-enforcement requests.[3]Evidence dated Jun 3, 2026
Europol’s Operation Endgame creates a hunting window, not an all-clear — Europol named SocGholish, Amadey, and StealC and reported action against servers, domains, infected websites, credentials, and criminal assets. Defenders should retro-hunt those ecosystems, review already stolen credentials, and monitor replacement infrastructure because disruption does not erase surviving access or operator capability.[4]Evidence dated Jun 24, 2026
UK NCSC campaign warnings add actor, victimology, and technology context — The NCSC and partner governments identify LAUNDRY BEAR’s Zimbra beehive/Ulej email-theft campaign and separately warn about the FortiBleed credential campaign against Fortinet gateways. Those notices should drive Zimbra mailbox and authentication hunting, FortiGate credential rotation and session review, and careful preservation of each notice’s attribution boundary.[9][10]First cited source Jun 18, 2026 · Latest cited source Jul 23, 2026
Every government instrument carries a different executive decision — A CISA KEV deadline requires remediation governance; an FBI/NSA/CISA joint advisory requires exposure scoping and hardening; a DOJ or Europol disruption creates hunting and evidence-preservation opportunities; a UK NCSC attribution changes intelligence and communications context. Treating these instruments as interchangeable discards their operational meaning.[1][2][3][4][9]First cited source Jun 2026 · Latest cited source Jul 23, 2026
Boards need named evidence, not a generic count of closed tickets — A defensible briefing should show which CISA KEVs map to owned assets, which FBI/NSA/CISA OT warnings match real equipment, which DOJ or Europol indicators were hunted, where logging is missing, what incident findings exist, and how recovery was tested. Aggregate patch percentages cannot answer those questions.[1][2][3][4]First cited source Jun 2026 · Latest cited source Jun 24, 2026
Company Exposure and Exploitability
Specific products and control interfaces elevated by the retained government record. Each row explains the exploitable condition, which companies should care, the business consequence, and the evidence a defender should monitor.
| Technology and exploitable condition | Company exposure and business risk | Monitoring and IntelliOS coverage |
|---|---|---|
| Technology Fortinet FortiOS · CVE-2025-68686[13]Evidence dated Jul 27, 2026 Exploitable conditionCISA confirms exploitation of a remote unauthenticated bypass of the patch for a symbolic-link persistence mechanism seen in some post-exploit cases. Fortinet says the attacker must first have compromised FortiOS at filesystem level through another vulnerability. | Which companies should care Organizations and MSPs operating FortiGate appliances on affected FortiOS 7.6, 7.4, 7.2, 7.0, or 6.4 branches, especially devices with prior internet-reachable administration or VPN exposure. Business riskA perimeter control plane may appear patched while attacker-controlled filesystem state, configuration, credentials, sessions, or internal reach remains relevant. | What to monitor Exact version and exposure history; unexpected symbolic links or filesystem changes; administrative sessions and accounts; configuration drift; HA peer state; outbound and internal connections; reachable secrets and downstream access. IntelliOS coverage |
| Technology Langflow AI workflow servers · CVE-2026-0770[1][5]First cited source Jun 2026 · Latest cited source Jul 22, 2026 Exploitable conditionCISA’s KEV catalog and the NIST NVD record identify internet-reachable Langflow deployments exposed to unauthenticated remote code execution through the exec_globals handling path, with execution possible in the server’s root context. | Which companies should care Companies operating self-hosted AI workflow, agent, integration, or automation infrastructure—especially systems holding API keys, secrets, data connectors, or privileged service access. Business riskRemote takeover can expose model and application secrets, enable data theft, create a launch point into connected services, and alter trusted AI workflows. | What to monitor Owned Langflow instances, version and mitigation status, validate-endpoint requests, unexpected child processes, outbound connections, credential access, and changes to flows or secrets. IntelliOS coverage |
| Technology SonicWall SMA1000 · CVE-2026-15409 and CVE-2026-15410[1][6][7][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026 Exploitable conditionSonicWall’s PSIRT advisory and Volexity’s incident-response research describe a chain that uses unauthenticated server-side request forgery to reach a privileged internal workflow, then abuses an authenticated-administrator hotfix-removal path for path traversal and command execution as root. | Which companies should care Organizations using SMA1000 6210, 7210, or 8200v appliances for remote access, including enterprises, service providers, and environments where the appliance brokers identity and internal connectivity. Business riskAppliance compromise can expose credentials, sessions, authentication material, internal services, and downstream systems; public reporting includes a ransomware outcome. | What to monitor Internet-facing SMA1000 assets, fixed-release status, historical WorkPlace and localhost-control activity, appliance configuration changes, credential or TOTP exposure, and appliance-sourced lateral movement. IntelliOS coverage |
| Technology Zimbra Collaboration servers · LAUNDRY BEAR beehive/Ulej activity[9]Evidence dated Jul 23, 2026 Exploitable conditionUK NCSC and partner governments describe a zero-click email-theft path in which viewing a malicious message on a vulnerable Zimbra deployment can trigger compromise without a user clicking a link or opening an attachment. | Which companies should care Organizations operating Zimbra for sensitive government, defence, education, energy, law-enforcement, media, NGO, or technology communications. Business riskMailbox compromise can expose strategic communications, authentication material, relationships, and intelligence useful for follow-on espionage or intrusion. | What to monitor Zimbra version and exposure, suspicious message rendering, anomalous mailbox exports, authentication changes, new persistence, and evidence of access predating remediation. IntelliOS coverageNo dedicated product yet |
| Technology Fortinet FortiGate firewalls and SSL VPN gateways · FortiBleed[10]Evidence dated Jun 18, 2026 Exploitable conditionUK NCSC says a global campaign used brute force, dictionary attacks, credential stuffing, and leaked credential material against internet-facing FortiGate and VPN authentication portals. | Which companies should care Companies using Fortinet firewalls or SSL VPN services, particularly where credentials were reused, MFA was incomplete, management interfaces were exposed, or older sessions remained valid. Business riskSuccessful access can bypass the perimeter, expose administrative control, enable internal reconnaissance, and create an access path for data theft or ransomware. | What to monitor Owned domains in trusted exposure checks, unusual FortiGate or VPN authentication, unauthorized accounts, active sessions, credential reuse, and management-interface exposure. IntelliOS coverage |
| Technology Cisco Catalyst SD-WAN Manager · CVE-2026-20262[1]Evidence dated Jun 2026 Exploitable conditionCISA lists an exploited arbitrary file-write vulnerability affecting Cisco’s platform for centrally administering distributed network infrastructure. | Which companies should care Enterprises and service providers using Cisco SD-WAN Manager to control branch, cloud, or wide-area network policy and connectivity. Business riskCompromise of a network control plane can affect many managed devices, alter trusted configuration, and create broad downstream reach. | What to monitor Internet exposure, fixed-version status, unusual management requests, unexpected file creation or processes, configuration changes, and administrator activity from unfamiliar sources. IntelliOS coverage |
| Technology Oracle PeopleSoft PeopleTools · CVE-2026-35273[1]Evidence dated Jun 2026 Exploitable conditionCISA lists an exploited HTTP takeover path affecting Oracle PeopleSoft PeopleTools, an enterprise application platform that commonly carries HR, finance, identity, and administrative workflows. | Which companies should care Organizations running internet-facing or partner-accessible PeopleSoft and PeopleTools deployments. Business riskApplication takeover can expose regulated business data, privileged functions, trusted sessions, and a path into administrative systems. | What to monitor Owned PeopleSoft instances, update status, abnormal HTTP requests, authentication or session anomalies, unexpected web-accessible files, process creation, and configuration changes. IntelliOS coverage |
| Technology Check Point security gateways using IKEv1 · CVE-2026-50751[1]Evidence dated Jun 2026 Exploitable conditionCISA lists an exploited VPN authentication-bypass condition affecting Check Point remote-access and security-gateway trust paths; the connected CARDS record captures known ransomware campaign use. | Which companies should care Companies with Check Point gateways where IKEv1 remains enabled or remote-access exposure is not fully inventoried. Business riskAuthentication bypass at the security edge can create unauthorized remote access, privileged network position, and downstream ransomware or data-theft opportunity. | What to monitor Affected gateways, IKEv1 enablement, fixed-version status, unexpected VPN sessions, new remote-access identities, configuration changes, and gateway-originated internal activity. IntelliOS coverage |
| Technology SimpleHelp remote-support servers · CVE-2026-48558[1]Evidence dated Jun 2026 Exploitable conditionCISA’s KEV catalog identifies an exploited SimpleHelp authentication-bypass vulnerability in remote-support infrastructure. | Which companies should care Managed service providers, internal IT teams, and organizations whose SimpleHelp deployment can administer many endpoints or customer environments. Business riskOne compromised support server can inherit trusted reach across numerous endpoints, customers, credentials, and administrative sessions. | What to monitor Internet-facing SimpleHelp servers, version status, new administrators, unusual support sessions, endpoint fan-out, remote execution, and access during the historical exposure window. IntelliOS coverageNo dedicated product yet |
| Technology Ubiquiti UniFi OS and Lantronix EDS5000 management interfaces[1]Evidence dated Jun 2026 Exploitable conditionCISA added four exploited vulnerabilities on June 23, concentrating urgent remediation in Ubiquiti UniFi OS and Lantronix EDS5000 industrial or network-management interfaces with internet-reachable control paths. | Which companies should care Organizations operating distributed network, industrial, branch, facility, or vendor-managed infrastructure built on the affected platforms. Business riskCompromised management interfaces can alter connectivity, disrupt operations, weaken segmentation, and provide a trusted path toward internal assets. | What to monitor Asset ownership, public administration interfaces, firmware status, configuration drift, new accounts, unexpected management traffic, and evidence of access before patching. IntelliOS coverage |
| Technology Internet-accessible automatic tank gauges and connected OT[2]Evidence dated Jun 3, 2026 Exploitable conditionNSA, CISA, FBI, DOE, EPA, TSA, DOT, and USDA reported malicious activity against internet-exposed gauges and warned that public interfaces, weak credentials, unsupported equipment, or permissive vendor access can allow compromise and command-based modification. | Which companies should care Energy, chemical, food, agriculture, transportation, retail-fuel, and other operators that depend on connected gauges for physical inventory and operational decisions. Business riskManipulated or unavailable readings can affect safety, environmental obligations, inventory integrity, dispatch, billing, and continuity of physical operations. | What to monitor Publicly reachable gauge interfaces, default or shared credentials, unsupported models, vendor access, segmentation gaps, unexplained level or configuration changes, and tested manual recovery. IntelliOS coverage |
Source-Bound Exposure and Targeting
This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.
| Victim / exposure population | Sectors | Geography | Confirmation status | How companies should use it |
|---|---|---|---|---|
| Victim / exposure populationWestern organizations exposed to LAUNDRY BEAR’s Zimbra beehive/Ulej campaign[9]Evidence dated Jul 23, 2026 | SectorsDefence, government, education, energy, law enforcement, media, NGOs, and technology | GeographyWestern organizations; the joint notice is international | Confirmation statusUK NCSC and partner governments provide category-level targeting for LAUNDRY BEAR; they do not publish a named-victim list in the retained notice. | How companies should use itUse the NCSC warning to prioritize Zimbra discovery, version validation, mailbox hunting, and evidence review in the named sectors. Do not describe an organization as compromised without first-party or incident evidence. |
| Victim / exposure populationOrganizations using internet-facing Fortinet FortiGate and SSL VPN services[10]Evidence dated Jun 18, 2026 | SectorsCross-industry, including public-sector and critical-service environments | GeographyGlobal campaign with potential UK impact | Confirmation statusUK NCSC defines the exposed Fortinet population but does not publish a confirmed named-victim list or name the operator. | How companies should use itUse owned-domain and device validation, credential rotation, session review, and historical authentication analysis before making impact claims. |
| Victim / exposure populationOrganizations exposed through SocGholish-infected websites, Amadey, StealC, or already stolen credentials[4]Evidence dated Jun 24, 2026 | SectorsCross-industry malware-delivery, credential-theft, and ransomware exposure | GeographyInternational | Confirmation statusEuropol provides ecosystem-scale victimology for Operation Endgame; its release does not establish that every affected organization, infected website, or stolen credential was remediated. | How companies should use itRetro-hunt the named malware ecosystems, review reused credentials, and watch for replacement infrastructure rather than treating the takedown as eradication. |
| Victim / exposure populationCompanies operating internet-facing Langflow or SonicWall SMA1000 infrastructure[5][6][7][8]First cited source Jul 14, 2026 · Latest cited source Jul 22, 2026 | SectorsAI/software operations, enterprises, service providers, and remote-access-dependent organizations | GeographyGlobal technology exposure; SMA1000 incident reporting includes observed compromise but no reliable public named-victim list | Confirmation statusCISA and NIST define the Langflow exposure; SonicWall defines affected SMA1000 products; Volexity supplies incident-response observations; Dark Reading reports one ransomware outcome and the INC Ransom association. IntelliOS does not infer impact for every exposed deployment. | How companies should use itUse asset ownership and historical exposure to decide which systems require incident investigation, credential response, and downstream hunting—not just patch confirmation. |
Named and Source-Bound Government Signals
Specific actors and campaigns identified or described in official government notices. Attribution language is preserved exactly: a row is not presented as government-attributed when the issuing authority did not name an operator.
| Government notice | Actor or campaign | What the government source establishes | What to monitor | IntelliOS coverage |
|---|---|---|---|---|
| Government notice 23 Jul 2026 UK NCSC and a 15-country joint advisory | Actor or campaign LAUNDRY BEAR — “beehive/Ulej” Zimbra zero-click email theft[9]Evidence dated Jul 23, 2026 | What the government source establishesThe government notice attributes an ongoing espionage campaign to LAUNDRY BEAR, assesses it as almost certainly supported by the Russian state, and says vulnerable Zimbra users can be compromised by viewing a malicious email without clicking. The campaign has targeted Western defence, government, education, energy, law-enforcement, media, NGO, and technology organizations. | What to monitorZimbra version and exposure; suspicious message rendering; anomalous mailbox, export, or authentication activity; persistence around mail infrastructure; evidence of access predating remediation. | IntelliOS coverageNo dedicated IntelliOS record yet |
| Government notice 18 Jun 2026 UK NCSC alert | Actor or campaign FortiBleed global Fortinet firewall and VPN credential campaign[10]Evidence dated Jun 18, 2026 | What the government source establishesThe NCSC says a threat actor targeted internet-facing FortiGate and VPN portals through brute-force, dictionary, and credential-stuffing attempts and that a resulting credential database was leaked. The government alert recognizes the campaign and potential UK impact but does not name the responsible actor. | What to monitorOwned domains in trusted exposure checkers; unauthorized accounts; unusual FortiGate or SSL VPN authentication; stale or reused credentials; active sessions; management-interface exposure; device and downstream network activity. | IntelliOS coverage |
| Government notice 24 Jun 2026 Europol Operation Endgame release | Actor or campaign SocGholish, Amadey, and StealC malware-delivery and credential-theft ecosystems[4]Evidence dated Jun 24, 2026 | What the government source establishesEuropol identifies the three named malware ecosystems as targets of an international operation against infrastructure supporting ransomware delivery, credential theft, and cybercrime. The action disrupted servers, domains, infected websites, and criminal assets without establishing permanent eradication. | What to monitorReplacement domains and servers; renewed compromised-website delivery; Amadey or StealC execution; reuse of already stolen credentials; downstream ransomware; infrastructure migration after takedown activity. | IntelliOS coverage |
Source-Bound Actor Context
Europol’s Operation Endgame release names SocGholish as a malware-delivery ecosystem targeted through server, domain, and infected-website disruption. Defenders should retro-hunt web and endpoint activity and watch for successor infrastructure rather than assume the delivery path disappeared.[4]Evidence dated Jun 24, 2026
Europol identifies Amadey infrastructure within the coordinated international action. The official release supports disruption context and follow-on hunting, but it does not resolve the identity behind every Amadey infection or prove the ecosystem was eradicated.[4]Evidence dated Jun 24, 2026
Europol names StealC as a targeted credential-theft ecosystem. Existing credential exposure remains consequential even when law enforcement removes portions of delivery infrastructure, so identity telemetry and credential reuse remain priority checks.[4]Evidence dated Jun 24, 2026
DOJ’s disruption record—supported by FBI, Secret Service, HSI, foreign-law-enforcement, and named private-sector actions—describes a distributed cyber-enabled fraud ecosystem spanning social-media and email accounts, hosting, telecommunications, scam platforms, and cryptocurrency. It is not a complete actor census.[3]Evidence dated Jun 3, 2026
CISA’s KEV catalog establishes observed exploitation but often does not identify the responsible actor. IntelliOS keeps remediation urgency separate from actor attribution unless CISA, another government authority, a vendor, or source-bound incident research establishes the relationship.[1]Evidence dated Jun 2026
Malware, Implants, and Intrusion Tooling
Source-backed malware and malicious tooling named in the retained campaigns. The table distinguishes malware families, open-source tools, custom implants, exploit or collection tooling, and reported outcomes that lack a publicly identified sample.
| Malware / tooling | Classification and campaign | Capability and potential impact | What defenders should monitor |
|---|---|---|---|
| Malware / toolingSocGholish / FakeUpdates[4][11]First cited source Jun 18, 2026 · Latest cited source Jun 24, 2026 | Classification and campaignJavaScript loader and initial-access malwareOperation Endgame; Dutch National Police, RCMP, Europol, and partner reporting link the ecosystem to Evil Corp. | Capability and potential impactCompromises legitimate WordPress sites and presents fake browser or software updates to visitors. Successful execution gives the operator an initial foothold that can deliver additional malware, steal access, or lead to ransomware. | What defenders should monitorUnauthorized WordPress code or accounts; injected update prompts; browser-launched script or executable activity; new scheduled persistence; outbound connections to replacement infrastructure; credentials associated with compromised sites. |
| Malware / toolingAmadey[4][12]Evidence dated Jun 24, 2026 | Classification and campaignBot, loader, and access-enablement malwareOperation Endgame; Europol and Microsoft Digital Crimes Unit reporting describe Amadey and StealC as distinct tools that shared infrastructure. | Capability and potential impactHelps attackers gain and maintain access to infected devices, collect system information, and retrieve additional payloads. Microsoft reports that Amadey and StealC were linked to more than 140,000 infected computers during the first two weeks of May 2026. | What defenders should monitorKnown Amadey detections and command-and-control; suspicious downloader behavior; scheduled tasks or startup persistence; system discovery; secondary payload retrieval; credentials or sessions used after the endpoint infection. |
| Malware / toolingStealC[4][12]Evidence dated Jun 24, 2026 | Classification and campaignInformation stealer with dropper capabilityOperation Endgame; investigated by Europol EC3, European law enforcement, Microsoft DCU, IBM X-Force, Proofpoint, and other partners. | Capability and potential impactExtracts passwords, browser cookies, session tokens, stored access data, and digital identities for resale or fraudulent use. It can also support follow-on payload delivery, making an apparently contained endpoint infection an identity and cloud-access incident. | What defenders should monitorStealer detections; access to browser credential and cookie stores; unusual archive creation; outbound credential exfiltration; new logins using stolen cookies or tokens; follow-on fraud, mailbox, VPN, or cloud activity. |
| Malware / toolingROOTRUN / xzfind[8]Evidence dated Jul 17, 2026 | Classification and campaignSMA1000 privilege-escalation utilityUTA0533 SonicWall SMA1000 exploitation; named and analyzed by Volexity. | Capability and potential impactA setuid ELF binary written to /usr/bin/xzfind that invokes setuid to elevate itself and execute attacker-supplied commands through the Bash shell as root. | What defenders should monitor/usr/bin/xzfind; unexpected setuid binaries; the ROOTRUN usage string; root command execution from appliance service contexts; file creation or modification around the historical compromise window. |
| Malware / toolingKNUCKLEBALL / deploy_new.py[8]Evidence dated Jul 17, 2026 | Classification and campaignSMA1000 loader, injector, and persistence scriptUTA0533 SonicWall SMA1000 exploitation; Volexity-assigned malware name. | Capability and potential impactInjects two embedded Java agents into a legitimate SonicWall process, clears temporary agent logs, deletes staged JARs, modifies NGINX Unit routes, and persists through the legitimate workplace startup script. | What defenders should monitor/usr/lib/python3.11/site-packages/deploy_new.py; /tmp/agent_wp8.jar or agent_wp9.jar; .attach_pid or .java_pid artifacts; the workplace init script launching deploy_new.py; unexpected changes to /var/lib/unit/conf.json. |
| Malware / toolingSuo5 / agent_wp8.jar[8]Evidence dated Jul 17, 2026 | Classification and campaignModified open-source HTTP forwarding proxyEmbedded in KNUCKLEBALL during the UTA0533 SMA1000 intrusion and injected into a legitimate appliance Java process. | Capability and potential impactCreates an attacker-controlled proxy path through the compromised appliance, allowing traffic forwarding and concealed access through a trusted internet-facing remote-access system. | What defenders should monitor/tmp/agent_wp8.jar; /workplace/error.jsp; NGINX routes rewriting /__api__/login; proxying to 127.0.0.1:8085; the impossible Chrome 149 / Windows 11 user-agent string documented by Volexity. |
| Malware / toolingORANGETAIL / agent_wp9.jar[8]Evidence dated Jul 17, 2026 | Classification and campaignCustom Java webshellEmbedded in KNUCKLEBALL during the UTA0533 SMA1000 intrusion; Volexity describes it as Behinder-like. | Capability and potential impactAccepts encrypted attacker-supplied Java through an HTTP POST parameter, dynamically loads it into the appliance process, and returns encrypted responses—providing a durable command-execution channel behind legitimate web paths. | What defenders should monitor/tmp/agent_wp9.jar; /workplace/dialogs/errorDialog.jsp; NGINX routes rewriting /__api__/logout; repeated encrypted POST requests; the documented impossible user agent; unexplained Java class loading in the workplace process. |
| Malware / toolingBeehive / Ulej[9]Evidence dated Jul 23, 2026 | Classification and campaignZimbra exploit and email-collection tooling—not a standalone malware familyLAUNDRY BEAR campaign identified by UK NCSC and partner governments. | Capability and potential impactA malicious email can execute when viewed in a vulnerable Zimbra web client, enabling collection of recent email, directory data, authentication material, and other sensitive mailbox information without a conventional link click or attachment open. | What defenders should monitorVulnerable Zimbra versions; suspicious message rendering; anomalous mailbox searches or bulk exports; unusual access to address-book data; credential or token changes; persistence and outbound transfers from mail infrastructure. |
| Malware / toolingRansomware payload in the reported SMA1000 case[7][8]First cited source Jul 17, 2026 · Latest cited source Jul 22, 2026 | Classification and campaignReported outcome; malware family or sample not publicly characterizedDark Reading reports that Rapid7 associated activity with INC Ransom and that one investigated case progressed to ransomware. The retained Volexity report uses UTA0533 and does not identify a ransomware sample. | Capability and potential impactThe retained secondary reporting supports a reported ransomware outcome but not a specific payload name, hash, encryption implementation, or proof that every SMA1000 intrusion produced ransomware. The gap should remain visible rather than be filled by inference. | What defenders should monitorPost-appliance lateral movement; remote execution or administrative tooling; backup or security-control tampering; mass file changes; ransom notes; data staging or exfiltration; new primary reporting that identifies the payload. |
Current Carry-Forward Watchlist
Prioritized CVEs, KEVs, actors, and campaigns that convert the government-action record into named operational monitoring requirements.
| # | Threat / Category | Why It Matters | What to Monitor | IntelliOS Coverage |
|---|---|---|---|---|
| 1 | Threat / Category CVE / KEV · AI infrastructure CVE-2026-0770 — Langflow unauthenticated root RCE[1][5]First cited source Jun 2026 · Latest cited source Jul 22, 2026 | Why it mattersCISA added this Langflow vulnerability to KEV on July 21 with a July 24 required-action date. It permits remote code execution without authentication through the exec_globals handling path and can execute in the context of root. | What to monitorInternet-exposed Langflow servers; versions and mitigations against current project guidance; requests to the validate endpoint; unexpected child processes, outbound connections, credential access, or changes to flows and secrets. | IntelliOS coverage |
| 2 | Threat / Category CVEs / KEVs · Edge appliance campaign CVE-2026-15409 and CVE-2026-15410 — SonicWall SMA1000 exploitation[1][6][7][8]First cited source Jun 2026 · Latest cited source Jul 22, 2026 | Why it mattersSonicWall’s PSIRT advisory defines the two CVEs and affected appliances; CISA places both in KEV; Volexity documents the exploitation chain and UTA0533 activity; Dark Reading reports the INC Ransom association and a ransomware outcome. The chain moves from unauthenticated access to an authenticated-administrator workflow and root execution, but the actor labels remain separate. | What to monitorInternet-facing SMA1000 6210, 7210, and 8200v appliances; fixed-release status; historical WorkPlace and localhost-control activity; appliance configuration changes; credential, session, and TOTP exposure; appliance-sourced lateral movement. | IntelliOS coverage |
| 3 | Threat / Category Actors · Attribution boundary INC Ransom and UTA0533 — related reporting, not a merged identity[7][8]First cited source Jul 17, 2026 · Latest cited source Jul 22, 2026 | Why it mattersDark Reading reports an INC Ransom connection and a ransomware outcome, while Volexity tracks overlapping SMA1000 exploitation as UTA0533. The public record supports monitoring both labels but does not prove they represent the same operator. | What to monitorNew primary reporting that resolves attribution; INC victim or access claims; UTA0533 infrastructure and tooling; overlap in SMA1000 artifacts; ransomware deployment after edge-appliance compromise. | IntelliOS coverage |
| 4 | Threat / Category Campaign · Malware delivery ecosystem Operation Endgame — SocGholish, Amadey, and StealC reconstitution[4]Evidence dated Jun 24, 2026 | Why it mattersEuropol’s Operation Endgame release names SocGholish, Amadey, and StealC and reports action against infrastructure supporting delivery, credential theft, fraud, and ransomware enablement. The intervention raises adversary cost but does not invalidate credentials already stolen or prevent operators from rebuilding. | What to monitorReplacement domains and servers; renewed SocGholish website infections; Amadey or StealC delivery changes; reuse of exposed credentials; downstream ransomware activity; further Operation Endgame actions. | IntelliOS coverage |
| 5 | Threat / Category Campaign · Cyber-enabled fraud DOJ / FBI Scam Center Disruption Week — account, infrastructure, and financial displacement[3]Evidence dated Jun 3, 2026 | Why it mattersDOJ reports that Scam Center Disruption Week, with FBI, Secret Service, HSI, foreign-law-enforcement, and private-sector support, disrupted accounts, network access, hosting, scam platforms, and cryptocurrency laundering. The scale of action makes migration and reconstitution across providers a continuing monitoring concern. | What to monitorSuccessor scam accounts and platforms; malicious IP and hosting migration; cryptocurrency laundering changes; provider or law-enforcement requests; fraud targeting employees, customers, and payment workflows. | IntelliOS coverage |
| 6 | Threat / Category CVE / KEV · Network control plane CVE-2026-20262 — Cisco Catalyst SD-WAN Manager arbitrary file write[1]Evidence dated Jun 2026 | Why it mattersCISA’s KEV catalog identifies exploitation of Cisco Catalyst SD-WAN Manager CVE-2026-20262, an arbitrary file-write flaw in a platform that controls distributed network infrastructure. Its administrative reach makes it urgent even when a base score appears less dramatic than the business consequence. | What to monitorInternet exposure, fixed-version status, unusual web-management requests, unexpected file creation, configuration changes, new processes, and administrative activity from unfamiliar sources. | IntelliOS coverage |
| 7 | Threat / Category CVE / KEV · Enterprise application CVE-2026-35273 — Oracle PeopleSoft PeopleTools HTTP takeover[1]Evidence dated Jun 2026 | Why it mattersCISA’s KEV catalog identifies exploitation of Oracle PeopleSoft PeopleTools CVE-2026-35273. Because PeopleSoft commonly supports HR, financial, identity, and administrative workflows, HTTP takeover can expose sensitive business data and privileged functions while blending into normal web traffic. | What to monitorInternet-facing PeopleSoft and PeopleTools instances, vendor update status, abnormal HTTP requests, authentication or session anomalies, unexpected web-accessible files, process creation, and changes to application configuration. | IntelliOS coverage |
| 8 | Threat / Category CVE / KEV · Remote access CVE-2026-50751 — Check Point IKEv1 VPN authentication bypass[1]Evidence dated Jun 2026 | Why it mattersCISA’s KEV catalog establishes exploitation of Check Point CVE-2026-50751, while the connected CARDS record captures known ransomware campaign use. The authentication-bypass condition affects remote-access and security-gateway trust paths, raising it above ordinary perimeter patching. | What to monitorAffected Check Point gateways, IKEv1 enablement, fixed-version status, unexpected VPN sessions, anomalous authentication, new remote-access identities, configuration changes, and downstream activity originating from the gateway. | IntelliOS coverage |
| 9 | Threat / Category Operational technology · Exposed control interface Internet-accessible automatic tank gauges[2]Evidence dated Jun 3, 2026 | Why it mattersNSA, CISA, FBI, DOE, EPA, TSA, DOT, and USDA reported malicious actors compromising and modifying internet-exposed automatic tank gauges through command execution. The risk extends beyond confidentiality to fuel or liquid inventory integrity, leak detection, safety, environmental obligations, and continuity. | What to monitorPublicly reachable gauge interfaces, default or shared credentials, unsupported models, vendor remote access, segmentation gaps, unexplained level or configuration changes, and tested manual recovery procedures. | IntelliOS coverage |
| 10 | Threat / Category KEV cohort · Exposure governance Rolling KEV exposure and remediation backlog[1]Evidence dated Jun 2026 | Why it mattersEach new KEV entry retained inside the rolling window creates an asset-discovery, ownership, exposure, remediation, and—where prior reachability exists—investigation requirement. The threat is not only an unpatched CVE; it is an unknown or ownerless exposed asset that never enters the emergency workflow. | What to monitorAsset-to-CVE coverage, internet exposure, business and technical ownership, remediation deadlines, expiring exceptions, compensating controls, missing logs, and evidence that previously exposed systems were assessed for compromise. | IntelliOS coverage |
Operational Standards from the Evidence
The practices below convert the retained public evidence into repeatable executive standards. Each lesson remains bounded to its cited sources.
Best Practice
Lesson Learned
CISA’s three-day Oracle WebLogic and PeopleSoft windows and the Langflow July 24 deadline show that a conventional monthly patch cycle is too slow for vulnerabilities already known to be exploited.
Minimum Operating Standard
Every KEV-matched asset has a named technical owner, business owner, exposure decision, completion evidence, and a time-limited exception approved at the appropriate risk level.
Best Practice
Lesson Learned
CISA’s Cisco SD-WAN, Check Point, SimpleHelp, and PeopleSoft entries—and the FBI/NSA/CISA automatic-tank-gauge warning—show that the highest-consequence system may be the one that administers, authenticates, or connects many other systems.
Minimum Operating Standard
Maintain an asset-level inventory of internet-reachable IT and OT management interfaces, including vendor-managed, forgotten, and third-party-hosted deployments, with emergency isolation options documented.
Best Practice
Lesson Learned
A patched version proves that a known vulnerability is closed now; it does not prove that the system, its credentials, or connected environments remained trustworthy before remediation. The SMA1000 activity began before public disclosure.
Minimum Operating Standard
Prior exposure, missing logs, unexplained administrative activity, credential access, or appliance-sourced lateral movement automatically triggers scoped investigation rather than ticket closure alone.
Best Practice
Lesson Learned
CVE-2026-15410 requires authenticated administrative access when considered alone, but the reported chain uses CVE-2026-15409 to reach the privileged workflow needed to exploit it. An authentication prerequisite is not a risk discount when another flaw can supply that access.
Minimum Operating Standard
Risk reviews document prerequisites, reachable services, privilege transitions, and plausible combinations with other vulnerabilities before accepting a lower-severity or post-authentication characterization.
Best Practice
Lesson Learned
An edge or remote-access appliance is part of the organization’s trust fabric. Volexity’s findings included credential, session, and authentication-material access, so replacing software alone may leave attacker-held access valid.
Minimum Operating Standard
Response plans define when to rotate administrator and service credentials, revoke sessions, replace exposed authentication seeds, validate identity-provider activity, and investigate downstream access.
Best Practice
Lesson Learned
Emergency patching, rebooting, reimaging, or removing an appliance can eliminate the logs, configuration state, files, and volatile artifacts needed to determine whether exploitation occurred and what the attacker reached.
Minimum Operating Standard
Teams have a preapproved evidence-capture sequence for exposed control systems, with log export, configuration preservation, artifact collection, time synchronization, custody, and escalation responsibilities.
Best Practice
Lesson Learned
DOJ and FBI’s Scam Center Disruption Week reporting and Europol’s Operation Endgame release show meaningful disruption of accounts, funds, domains, servers, and criminal infrastructure, but neither action invalidates stolen credentials or proves that operators and successor infrastructure disappeared.
Minimum Operating Standard
Official disruption reporting triggers indicator ingestion, retro-hunting, credential review, evidence preservation, provider coordination, and monitoring for migration or reconstitution.
Best Practice
Lesson Learned
A KEV entry, vendor advisory, incident-response cluster, media-reported ransomware association, seizure, and international disruption each establish different facts. Combining those facts without preserving their boundaries can overstate confidence and misdirect response.
Minimum Operating Standard
Executive, legal, and public reporting identifies which source supports each claim, separates INC Ransom from Volexity’s UTA0533 label unless new evidence resolves the relationship, and preserves the government’s exact action language.
Source Attribution and Institutional Context
Every government body below contributed to material actually used and cited. Co-authors are listed individually so the institutional contribution is visible rather than hidden behind “and partners.”
| Government Contributor | Mandate and Role | Contribution to This Record | Sources Used |
|---|---|---|---|
| United States Cybersecurity and Infrastructure Security Agency (CISA) | Mandate and role The operational lead for federal civilian cybersecurity and the national coordinator for reducing cyber and physical risk to critical infrastructure. | Contribution to this record Controls the rolling KEV evidence stream and co-authored the automatic-tank-gauge guidance; its KEV action also appears in the Langflow vulnerability record.[1][2][5]First cited source Jun 2026 · Latest cited source Jul 22, 2026 | Sources used |
| United States National Security Agency (NSA) | Mandate and role A U.S. Intelligence Community and defense-support agency responsible for foreign signals intelligence and cybersecurity support for National Security Systems and the Defense Industrial Base. | Contribution to this record Published and co-authored the defensive guidance on malicious activity targeting internet-exposed automatic tank gauges.[2]Evidence dated Jun 3, 2026 | Sources used |
| United States Federal Bureau of Investigation (FBI) | Mandate and role The principal federal investigative and domestic-intelligence bureau for threats including cybercrime, nation-state activity, fraud, and attacks on critical infrastructure. | Contribution to this record Co-authored the automatic-tank-gauge guidance and supplied federal investigative context for the observed malicious activity; FBI personnel also provided target information during DOJ’s Scam Center Disruption Week.[2][3]Evidence dated Jun 3, 2026 | Sources used |
| United States Department of Energy (DOE) | Mandate and role The federal department responsible for U.S. energy policy, science, nuclear security, and resilience of energy infrastructure; CESER leads sector cybersecurity and emergency-response work. | Contribution to this record Co-authored the automatic-tank-gauge guidance and supplied energy-sector and critical-infrastructure context.[2]Evidence dated Jun 3, 2026 | Sources used |
| United States Environmental Protection Agency (EPA) | Mandate and role The federal environmental regulator responsible for protecting human health and the environment, with cybersecurity responsibilities touching water and chemical-sector resilience. | Contribution to this record Co-authored the automatic-tank-gauge guidance and contributed environmental, chemical, leak-monitoring, and operational-risk context.[2]Evidence dated Jun 3, 2026 | Sources used |
| United States Transportation Security Administration (TSA) | Mandate and role The Department of Homeland Security agency responsible for protecting U.S. transportation systems and issuing security requirements for regulated transportation operators. | Contribution to this record Co-authored the automatic-tank-gauge guidance and contributed transportation-sector security and operational-continuity context.[2]Evidence dated Jun 3, 2026 | Sources used |
| United States Department of Transportation (DOT) | Mandate and role The federal department responsible for transportation policy, safety, mobility, and coordination across national transportation systems. | Contribution to this record Co-authored the automatic-tank-gauge guidance and contributed transportation-system ownership and sector context.[2]Evidence dated Jun 3, 2026 | Sources used |
| United States Department of Agriculture (USDA) | Mandate and role The federal department responsible for food, agriculture, natural resources, rural development, and programs supporting the resilience of the food-and-agriculture sector. | Contribution to this record Co-authored the automatic-tank-gauge guidance and contributed food-and-agriculture sector context for exposed fuel and liquid-storage monitoring systems.[2]Evidence dated Jun 3, 2026 | Sources used |
| United States Department of Justice (DOJ) | Mandate and role The federal department responsible for enforcing federal law, prosecuting federal crimes, protecting civil rights, and coordinating national and international law-enforcement action. | Contribution to this record Provided the official account, scope, and legal characterization of Scam Center Disruption Week.[3]Evidence dated Jun 3, 2026 | Sources used |
| European Union European Union Agency for Law Enforcement Cooperation (Europol) | Mandate and role The EU law-enforcement cooperation agency that supports member states with criminal intelligence, analysis, coordination, and cross-border operational support. | Contribution to this record Provided the official Operation Endgame account and the source-bound infrastructure, malware-family, and disruption totals used in the record.[4]Evidence dated Jun 24, 2026 | Sources used |
| Netherlands Dutch National Police and Netherlands Public Prosecution Service | Mandate and role The Netherlands Police investigate national and transnational cybercrime and organized crime; the Public Prosecution Service directs criminal investigations and prosecutes criminal offenses under Dutch law. | Contribution to this record Provided official Operation Endgame evidence on SocGholish/FakeUpdates, its relationship to Evil Corp, compromised WordPress delivery, 14,971 remediated websites, victim notification, and recommended recovery actions.[11]Evidence dated Jun 18, 2026 | Sources used |
| United Kingdom National Cyber Security Centre (NCSC) | Mandate and role The United Kingdom's national technical authority for cyber security and a part of GCHQ, responsible for threat assessment, incident support, public guidance, and national cyber resilience. | Contribution to this record Provided official campaign warnings covering LAUNDRY BEAR's Zimbra email-theft activity, APT28 router and DNS hijacking, Russian-aligned hacktivist disruption, and global Fortinet firewall and VPN credential targeting.[9][10]First cited source Jun 18, 2026 · Latest cited source Jul 23, 2026 | Sources used |
| United States National Institute of Standards and Technology / National Vulnerability Database (NIST NVD) | Mandate and role NIST is the federal measurement and standards laboratory; its NVD is the U.S. government repository that enriches CVE records with standards-based vulnerability-management data. | Contribution to this record Provided the official CVE-2026-0770 vulnerability record and its linked CISA KEV context for the Langflow monitoring priority.[5]Evidence dated Jul 22, 2026 | Sources used |
Source-Audit Transparency
Domestic, international, national-CSIRT, law-enforcement, regulator, and intergovernmental publication streams reviewed for relevance. These sources support no claim on this page and therefore do not appear in the Citations card.
| Government Source | Publication Stream | Last Checked | Review Disposition |
|---|---|---|---|
| United States CISA | Publication streamCybersecurity Advisories | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionPublication stream screened; no additional in-window item was needed beyond the retained KEV catalog and joint guidance. |
| United States CISA | Publication streamIndustrial Control Systems Advisories | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionScreened for in-window OT actions; no separate item was used to support a claim in this record. |
| United States CISA | Publication streamCybersecurity Directives | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionChecked for an in-window emergency or binding directive; none was retained for the rolling-window narrative. |
| United States FBI | Publication streamCyber News | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionEndpoint check encountered publisher access controls; no FBI news claim was imported. FBI’s used contribution remains limited to the joint guidance cited as [2]. |
| United States FBI Internet Crime Complaint Center | Publication streamPublic Service Announcements | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionStream screened; no in-window PSA was necessary to substantiate the retained executive claims. |
| United States NSA | Publication streamCybersecurity Advisories & Guidance Library | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionIndex endpoint was access-controlled during automated review; no item beyond the retained joint ATG release was used. |
| United States U.S. Cyber Command | Publication streamNews | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionEndpoint was access-controlled during automated review; no claim from this stream was retained. |
| United States Department of the Treasury / OFAC | Publication streamRecent Actions | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionSanctions and recent-action stream screened; no additional in-window action was used in the final four-lane narrative. |
| United States Financial Crimes Enforcement Network | Publication streamNewsroom | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionFinancial-crime publication stream screened; no separate FinCEN evidence was needed for a retained claim. |
| United States HHS Health Sector Cybersecurity Coordination Center | Publication streamHC3 Products | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionEndpoint was access-controlled during automated review; no health-sector product was used in this record. |
| United States Department of Energy | Publication streamCESER Cybersecurity and Emergency Response | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionProgram stream screened; DOE’s used contribution remains limited to its co-authorship of citation [2]. |
| United States Environmental Protection Agency | Publication streamCybersecurity for the Water Sector | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionSector guidance screened; no separate EPA water-sector page was used. EPA’s cited contribution remains the joint ATG guidance. |
| United States Securities and Exchange Commission | Publication streamPress Releases | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionEndpoint was access-controlled during automated review; no SEC action was used in this card. |
| United States Federal Communications Commission | Publication streamCybersecurity | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionEndpoint was access-controlled during automated review; no FCC evidence was retained. |
| United States NIST Computer Security Resource Center | Publication streamNews | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionNews stream screened; no additional in-window item was used beyond the NVD record cited as [5]. |
| United States NIST National Cybersecurity Center of Excellence | Publication streamNews & Insights | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionEndpoint was access-controlled during automated review; no NCCoE claim was retained. |
| United Kingdom National Crime Agency | Publication streamNews | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionEndpoint was access-controlled during automated review; no NCA claim was retained. |
| Canada Canadian Centre for Cyber Security | Publication streamAlerts and Advisories | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionNational alert stream screened; no additional in-window item was needed to support the retained claims. |
| Canada Royal Canadian Mounted Police | Publication streamCybercrime | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionFederal cybercrime stream screened; no distinct in-window operation was used. |
| Australia Australian Federal Police | Publication streamNews Centre | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionLaw-enforcement news stream screened; no separate in-window cyber operation was retained. |
| New Zealand National Cyber Security Centre | Publication streamNews | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionNational publication stream screened; no item was used in the final record. |
| European Union European Union Agency for Cybersecurity (ENISA) | Publication streamNews | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionEU cybersecurity stream screened; no ENISA item was necessary for a retained claim. |
| European Union CERT-EU | Publication streamPublications | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionEU-institutional CSIRT publications screened; no separate product was retained. |
| International INTERPOL | Publication streamCybercrime | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionEndpoint was access-controlled during automated review; no INTERPOL claim was imported. |
| Germany CERT-Bund / Federal Office for Information Security | Publication streamShort-form Warnings | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionFederal warning stream screened; no item was used in this record. |
| France CERT-FR / ANSSI | Publication streamAdvisories and Alerts | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionNational CSIRT stream screened; no additional in-window item was retained. |
| France ANSSI | Publication streamNews | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionNational cybersecurity news stream screened; no separate claim was used. |
| Netherlands National Cyber Security Centre | Publication streamSecurity Advisories | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionAdvisory stream screened; relevant vulnerability notices were not used because this card’s vulnerability claims are controlled by retained CISA/NVD sources. |
| Switzerland National Cyber Security Centre | Publication streamCurrent Focus | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionNational publication stream screened; no Swiss item was retained. |
| Norway National Security Authority / National Cyber Security Centre | Publication streamNational Cyber Security Centre | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionNational cyber stream screened; no additional in-window source was used. |
| Sweden CERT-SE / Swedish Civil Contingencies Agency | Publication streamCERT-SE | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionNational CSIRT stream screened; no item was retained. |
| Finland National Cyber Security Centre Finland / Traficom | Publication streamAlerts | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionNational alert stream screened; no item was used in this record. |
| Denmark Centre for Cyber Security / Danish Agency for Societal Security | Publication streamCyber Threats | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionLegacy publication route was checked and redirected to the current agency; no Danish claim was retained. |
| Estonia Information System Authority / CERT-EE | Publication streamSituation in Cyberspace — June 2026 | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionJune situational report reviewed; Estonia-specific incident statistics and events were outside the retained four-lane executive narrative and support no claim on this page. |
| Latvia CERT.LV | Publication streamNational CSIRT Portal | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionEndpoint timed out during review; no Latvian content or claim was imported. |
| Lithuania National Cyber Security Centre | Publication streamNational Cyber Security Centre Portal | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionEndpoint was access-controlled during automated review; no Lithuanian claim was imported. |
| Poland CERT Polska / NASK | Publication streamCERT Polska | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionNational CSIRT stream screened; no item was retained. |
| Japan National Cybersecurity Office | Publication streamInternational Outreach and Joint Advisories | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionGovernment coordination stream screened; no additional Japan-specific in-window item was used. |
| Japan JPCERT Coordination Center | Publication streamAlerts and Advisories | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionNational coordination-center stream screened; no item was retained. |
| Singapore Cyber Security Agency of Singapore | Publication streamAlerts and Advisories | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionEndpoint was access-controlled during automated review; no Singaporean claim was imported. |
| India CERT-In | Publication streamVulnerability Notes and Advisories | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionNational CSIRT advisory stream screened; no item was retained. |
| South Korea KrCERT/CC | Publication streamNotices | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionNational coordination-center stream screened; no item was used. |
| Israel Israel National Cyber Directorate | Publication streamCyber Alerts | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionEndpoint was access-controlled during automated review; no Israeli claim was imported. |
| Saudi Arabia National Cybersecurity Authority | Publication streamCybersecurity Alerts | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionNational alert stream screened; no item was retained. |
| Americas Organization of American States / CSIRTAmericas | Publication streamRegional CSIRT Portal | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionIntergovernmental regional stream screened; no item was used. |
| International United Nations Office on Drugs and Crime | Publication streamCybercrime | Last checked23-Jul-2026, 10:11 PM EDT | Review dispositionIntergovernmental cybercrime stream screened; no additional operational in-window claim was retained. |
Automation Transparency
| Agent | Government Agencies Rolling Intelligence Card Publisher |
|---|---|
| Status | Active · production automation verified July 23, 2026 |
| Cadence | Weekly on Thursday at midday ET across U.S. and international government source streams, with one cumulative rolling 90-day analysis. Each run adds qualifying new evidence and removes evidence that has aged beyond the active window. |
| Previous run | July 23, 2026 at 12:00 PM ET · Run #527 |
| Previous result | Successful daily cron run. The rolling 90-day record remained publication-ready and the automation recorded a material revision. |
| What the previous run found |
|
| Next run | July 30, 2026 at midday ET, derived from the verified weekly Thursday production cadence. |
| Sources monitored |
|
| Publication and alert policy | Maintain one cumulative rolling 90-day IntelliOS synthesis, publish material source-backed changes after the weekly evidence gate passes, and issue Page Alerts only for a material revision. Routine no-change checks and date-only window movement do not generate subscriber notifications. |
Related Intelligence and CARDS Records
PANDA CVE Watch Brief
Affected releases, fixed branches, KEV deadline, post-compromise prerequisite, hunting questions, and incident-response actions.
Open productPANDA Flash Threat Brief
Executive and technical treatment of the FortiOS patch bypass, historical exposure, evidence preservation, and trust recovery.
Open productPANDA Flash Threat Brief
Executive and technical treatment of CVE-2026-0770, related Langflow vulnerabilities, active exploitation, response priorities, and source boundaries.
Open productPANDA Flash Threat Brief
Source-bound treatment of CVE-2026-15409, CVE-2026-15410, the reported ransomware outcome, UTA0533, containment, and recovery.
Open productCARDS Campaign Record
Campaign timeline, affected products, reported activity, source agreement, actors, tools, CVEs, and attribution boundaries.
Open productFORGE Intelligence Tracker
Continuing coverage of Operation Endgame, DOJ / FBI scam-center disruption activity, infrastructure actions, actor pressure, and reconstitution.
Open productCARDS Actor Record
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS Actor Record
Connected actor intelligence, source-bound attribution context, behaviors, relationships, and defensive relevance.
Open productCARDS CVE / KEV Record
Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.
Open productCARDS CVE / KEV Record
Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.
Open productCARDS CVE / KEV Record
Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.
Open productCARDS CVE / KEV Record
Connected vulnerability intelligence covering exploitation status, affected technology, remediation, and campaign relationships.
Open productPublication History
| Version | Date | Change | Monitoring |
|---|---|---|---|
| Versionv32 | Date28-Jul-2026 | ChangeAdded CISA’s July 27 KEV action for FortiOS CVE-2025-68686, Fortinet’s affected and fixed releases, the August 10 federal deadline, and the requirement to pair remediation with BOD 26-04 forensic triage. Linked the new CVE Watch and Flash Threat Briefs. | MonitoringDaily KEV check plus weekly Thursday rolling 90-day review |
| Versionv31 | Date26-Jul-2026 | ChangeReplaced the abstract KEV ransomware-status wording with a concrete operating conclusion: an “Unknown” ransomware-use field does not lower the remediation deadline, change the confirmed-exploitation status, or support an all-clear. The revised point also names the separate sources that control SMA1000 exploitation, activity-cluster, and ransomware-attribution claims. | MonitoringWeekly Thursday rolling 90-day check and material-change publication |
| Versionv30 | Date24-Jul-2026 | ChangeAdded the PETRA report database to the Tier 6 discovery audit and weekly source monitor. The Apr 26–Jul 24 publication-date query returned no qualifying report, so PETRA is disclosed as checked but not used. | MonitoringWeekly Thursday rolling 90-day check and material-change publication |
| Versionv29 | Date24-Jul-2026 | ChangeEmbedded the complete Tier 0–Tier 8 source audit in Research Framing, including all retained sources, the 46 government publication streams checked but not used, and the role of internal source-audit tooling. | MonitoringWeekly Thursday rolling 90-day check and material-change publication |
| Versionv28 | Date24-Jul-2026 | ChangeAdded a source-cited evidence-mix donut chart distinguishing official government publications from retained primary research, incident-response reporting, and ecosystem monitoring. | MonitoringWeekly Thursday rolling 90-day check and material-change publication |
| Versionv27 | Date24-Jul-2026 | ChangeMoved Timeline of Notable Activity ahead of BLUF and expanded it to 17 source-backed milestones covering KEV additions and deadlines, government warnings about Fortinet and Zimbra campaigns, automatic-tank-gauge guidance, Scam Center Disruption Week, SocGholish and Operation Endgame, and the SonicWall and Langflow exploitation timelines. | MonitoringDaily rolling 90-day collection and material-change publication |
| Versionv26 | Date24-Jul-2026 | ChangeLocked BLUF and Executive Summary as mandatory cards and ensured both remain visible and expanded by default regardless of prior optional-card preferences. | MonitoringDaily rolling 90-day collection and cumulative publication |
| Versionv25 | Date24-Jul-2026 | ChangeChanged Rolling 90-Day Intelligence Snapshot from a locked default card to an optional drawer-controlled card that is hidden and collapsed on a fresh load, making BLUF the first visible briefing card. | MonitoringDaily rolling 90-day collection and cumulative publication |
| Versionv24 | Date24-Jul-2026 | ChangeAdded a six-point, source-cited BLUF before Executive Summary; made BLUF visible, locked, and open by default; and made Persona / Audience optional, hidden, and collapsed by default. | MonitoringDaily rolling 90-day collection and cumulative publication |
| Versionv23 | Date24-Jul-2026 | ChangeChanged Research Framing from a locked default card to an optional drawer-controlled card that is hidden and collapsed on a fresh page load. | MonitoringDaily rolling 90-day collection and cumulative publication |
| Versionv22 | Date24-Jul-2026 | ChangeMoved Other IntelliOS Products ahead of Version Change Log in both the Rolling Intelligence Card stack and right-side Cards drawer, while retaining AI Agent Run Status before both and Citations as the final card. | MonitoringDaily rolling 90-day collection and cumulative publication |
| Versionv21 | Date24-Jul-2026 | ChangeAdded a source-backed Malware Summary table covering SocGholish/FakeUpdates, Amadey, StealC, ROOTRUN, KNUCKLEBALL, Suo5, ORANGETAIL, Beehive/Ulej, and the reported but publicly uncharacterized ransomware payload; added Dutch Police and Microsoft DCU evidence and the Dutch government contributor record. | MonitoringDaily rolling 90-day collection and cumulative publication |
| Versionv20 | Date24-Jul-2026 | ChangeCompleted a card-by-card specificity pass: named CISA, FBI, NSA, DOJ, Europol, UK NCSC, partner agencies, vendors, incident responders, and reporting roles in the analysis; added concrete CVE, technology, campaign, victimology, and disruption examples; and strengthened source-attribution boundaries throughout. | MonitoringDaily rolling 90-day collection and cumulative publication |
| Versionv19 | Date24-Jul-2026 | ChangeAdded Research Framing as card 1 with the user topic, interpreted questions, initial source-bound observations, a tiered source-coverage ledger, and the evidence boundary; shifted every existing Government Rolling Intelligence Card section number up by one. | MonitoringDaily rolling 90-day collection and cumulative publication |
| Versionv18 | Date24-Jul-2026 | ChangeRemoved June-only counts and month-bound conclusions from the rolling government analysis; reframed KEV governance, monitoring, best-practice, actor, and snapshot language around the active 90-day evidence window while retaining dated June events that remain inside coverage. | MonitoringDaily rolling 90-day collection and cumulative publication |
| Versionv17 | Date24-Jul-2026 | ChangeConverted every Rolling Intelligence Card from a hard-coded monthly edition to a daily rolling 90-day snapshot; added dynamic coverage dates; excluded sources, timeline events, government campaigns, source checks, and change-log entries outside the active window; and changed the Rolling Intelligence Cards home page default to two result rows. | MonitoringDaily rolling 90-day collection and cumulative publication |
| Versionv16 | Date24-Jul-2026 | ChangeAdded a Persona / Audience card defining the U.S., executive, SMB and midmarket, enterprise, critical-infrastructure, and functional-reader orientation; made every Rolling Intelligence Card section collapsible; and set cards 1, 2, 3, 4, 6, 7, 8, and 9 open by default. | MonitoringDaily collection; monthly cumulative publication |
| Versionv15 | Date24-Jul-2026 | ChangeNumbered every Rolling Intelligence Card section and added the right-side Cards drawer with jump navigation, section visibility controls, and drag reordering. | MonitoringDaily collection; monthly cumulative publication |
| Versionv14 | Date24-Jul-2026 | ChangeConverted Government Sources Checked but Not Used into a responsive four-column source-audit table covering government source, linked publication stream, last-checked date, and review disposition. | MonitoringDaily collection; monthly cumulative publication |
| Versionv13 | Date24-Jul-2026 | ChangeConverted Government Contributors Used in This Record into a responsive four-column comparison table covering each contributor, institutional mandate, contribution to the record, and sources used. | MonitoringDaily collection; monthly cumulative publication |
| Versionv12 | Date24-Jul-2026 | ChangeRebuilt Exploitable Technologies for Companies as a true three-column comparison table at standard desktop widths, grouping each technology with its exploit condition, company exposure and business risk, and monitoring plus IntelliOS coverage. | MonitoringDaily collection; monthly cumulative publication |
| Versionv11 | Date23-Jul-2026 | ChangeConsolidated the four standalone reporting-period metric tiles into a single Monthly Intelligence Snapshot card with a responsive internal statistics grid and clearer source context. | MonitoringDaily collection; monthly cumulative publication; next run 24-Jul-2026 |
| Versionv10 | Date23-Jul-2026 | ChangeRemoved the standalone Connected CARDS card and rolled its actor, campaign, and CVE/KEV relationships into the renamed Other IntelliOS Products card, with duplicate destinations suppressed. | MonitoringDaily collection; monthly cumulative publication; next run 24-Jul-2026 |
| Versionv9 | Date23-Jul-2026 | ChangeReframed the product as the monthly cumulative output of a daily multi-government AI-agent review; added a ten-row Exploitable Technologies for Companies table and an eight-row source-bound Victimology Matrix; reordered the page; moved related IntelliOS products near the end; removed the generic signals/impact/priorities card; and retired the redundant standalone CISA weekly page and agent. | MonitoringDaily collection; monthly cumulative publication; next run 24-Jul-2026 |
| Versionv8 | Date23-Jul-2026 | ChangeRemoved the generic Campaigns & Government Operations card and replaced it with a seven-row Government-Flagged Threat Actor Campaigns table. Added retained NCSC and ACSC campaign notices, explicit government-attribution boundaries, monitoring requirements, IntelliOS links, and corresponding contributor/source-audit updates. | MonitoringSuperseded by v9 |
| Versionv7 | Date23-Jul-2026 | ChangeAdded an eight-part, source-cited Best Practices and Lessons Learned card covering KEV governance, control-plane inventory, historical-exposure investigation, exploit chaining, identity response, evidence preservation, disruption follow-through, and source-bound attribution. | MonitoringSuperseded by v9 |
| Versionv6 | Date23-Jul-2026 | ChangeAdded a source-bound Timeline of Notable Activity that distinguishes observed compromise dates, government publication and disclosure dates, KEV additions, and required-action deadlines. | MonitoringSuperseded by v9 |
| Versionv5 | Date23-Jul-2026 | ChangeAdded a complete government-contributor table for every agency whose cited material informed the record, including each agency’s role and exact information sources; added a 48-row domestic and international government-source audit with per-source review timestamps and non-use dispositions. | MonitoringSuperseded by v9 |
| Versionv4 | Date23-Jul-2026 | ChangeRemoved the standalone decision-question section; converted the monitoring priorities into one coherent ten-row table; added five named priorities; and added dedicated AI Agent Status and Version Change Log cards. | MonitoringSuperseded by v9 |
| Versionv3 | Date23-Jul-2026 | ChangeAdded the six-paragraph cited Executive Summary, the first five specific monitoring priorities, and direct links to existing IntelliOS briefs, trackers, CARDS records, actor cards, and the campaign card. | MonitoringSuperseded by v9 |
| Versionv2 | Date23-Jul-2026 | ChangeRewrote the Top 10 Briefing Points for executive use and separated campaigns, notable actors, affected technologies, and source-bound operational context. | MonitoringSuperseded by v9 |
| Versionv1 | Date18-Jul-2026 | ChangeInitial June 2026 Government Cybersecurity Actions & Advisories Rolling Intelligence Card publication with official-source metrics, briefing points, defensive priorities, and citations. | MonitoringSuperseded by v9 |
Retained Sources and Claim Treatment
| # | Publisher | Published | Publication / Evidence | Why Used / Claim Treatment | Source |
|---|---|---|---|---|---|
| Source1 | PublisherCISA | Published2026-06 | Publication / evidenceSource indexofficial | Why used / claim treatmentCISA's controlling catalog for vulnerabilities known to be exploited in the wild. A KEV listing establishes observed exploitation, not exploitation in every environment or attribution to a specific actor. | SourceKnown Exploited Vulnerabilities Catalog https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json |
| Source2 | PublisherNSA, CISA, FBI, DOE, EPA, TSA, DOT, and USDA | Published2026-06-03 | Publication / evidenceSource indexofficial | Why used / claim treatmentJoint defensive guidance from NSA, CISA, FBI, DOE, EPA, TSA, DOT, and USDA for internet-exposed operational technology. The agencies report observed malicious activity against automatic tank gauges; the notice does not establish compromise of every deployment. | SourceNSA Joins CISA and Partners to Release Guidance on Hardening Automatic Tank Gauges https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4507204/nsa-joins-cisa-and-partners-to-release-guidance-on-hardening-automatic-tank-gau/ |
| Source3 | PublisherU.S. Department of Justice | Published2026-06-03 | Publication / evidenceSource indexofficial | Why used / claim treatmentOfficial DOJ account of a Scam Center Strike Force action supported by the FBI, U.S. Secret Service, HSI, foreign law enforcement, and named technology and financial companies. It is retained here as a government-action signal and routed to the Law Enforcement Disruption Rolling Intelligence Card for operation-level treatment. | SourceScam Center Strike Force Announces Results of U.S.-Private Industry Disruption Week https://www.justice.gov/opa/pr/scam-center-strike-force-announces-results-us-private-industry-disruption-week |
| Source4 | PublisherEuropol | Published2026-06-24 | Publication / evidenceSource indexofficial | Why used / claim treatmentOfficial international disruption reporting. It demonstrates cross-border action against named infrastructure, but does not prove permanent eradication of the malware ecosystems. | SourceGlobal cyber strike disrupts SocGholish, Amadey and StealC malware networks https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks |
| Source5 | PublisherNIST National Vulnerability Database / CISA | Published2026-07-22 | Publication / evidenceSource indexofficial | Why used / claim treatmentOfficial vulnerability and KEV context for unauthenticated Langflow remote code execution. The record establishes active exploitation and root-level technical impact, not compromise of every Langflow deployment. | SourceCVE-2026-0770 Detail https://nvd.nist.gov/vuln/detail/CVE-2026-0770 |
| Source6 | PublisherSonicWall PSIRT | Published2026-07-14 | Publication / evidenceSource indexofficial | Why used / claim treatmentVendor advisory controlling affected-product, authentication, severity, fixed-release, and mitigation language for CVE-2026-15409 and CVE-2026-15410. Separate reporting controls actor attribution. | SourceSonicWall SMA1000 Security Advisory SNWLID-2026-0008 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 |
| Source7 | PublisherDark Reading | Published2026-07-22 | Publication / evidenceSource indexecosystem monitor | Why used / claim treatmentSecondary reporting retained specifically for the reported INC Ransom association and ransomware outcome. It is not substituted for SonicWall, Rapid7, or Volexity technical evidence. | SourceSonicWall SMA1000 zero-day flaws exploited by INC ransomware group https://www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days |
| Source8 | PublisherVolexity | Published2026-07-17 | Publication / evidenceSource indexincident response | Why used / claim treatmentPrimary incident-response research retained for exploitation and UTA0533 activity-cluster context. The public evidence does not establish that UTA0533 and INC Ransom are the same operator. | SourceProxying to Compromise: SonicWall Secure Mobile Access 0-Day Exploitation https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/ |
| Source9 | PublisherUK National Cyber Security Centre | Published2026-07-23 | Publication / evidenceSource indexofficial | Why used / claim treatmentOfficial UK and partner-government attribution and campaign warning for LAUNDRY BEAR's ongoing Zimbra 'beehive/Ulej' email-theft activity. The notice controls the Russian state-support assessment and named targeting scope. | SourceUK and partners expose Russian state-supported actors for new zero-click phishing campaign targeting Western organisations https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign |
| Source10 | PublisherUK National Cyber Security Centre | Published2026-06-18 | Publication / evidenceSource indexofficial | Why used / claim treatmentOfficial UK alert on the FortiBleed credential campaign affecting internet-facing Fortinet firewalls and VPN gateways. It establishes government-recognized campaign and response context but does not name the responsible actor. | SourceNCSC issues advice following global targeting of Fortinet firewalls and VPN gateways https://www.ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways |
| Source11 | PublisherDutch National Police and Netherlands Public Prosecution Service | Published2026-06-18 | Publication / evidenceSource indexofficial | Why used / claim treatmentOfficial Operation Endgame reporting on SocGholish/FakeUpdates, its Evil Corp relationship, compromised WordPress delivery, 14,971 remediated websites, victim notification, and defensive actions. It does not name the affected companies. | SourcePolitie en OM openen de jacht op beruchte malwaregroep SocGholish https://www.politie.nl/nieuws/2026/juni/18/11-politie-en-om-openen-de-jacht-op-beruchte-malwaregroep-socgholish.html |
| Source12 | PublisherMicrosoft Digital Crimes Unit | Published2026-06-24 | Publication / evidenceSource indexprimary research | Why used / claim treatmentPrimary private-sector partner reporting on the distinct roles of Amadey and StealC, their shared infrastructure, combined infection scale, and Microsoft-led disruption. Europol remains the controlling government source for Operation Endgame. | SourceScaling cybercrime disruption through innovation and AI https://blogs.microsoft.com/on-the-issues/2026/06/24/scaling-cybercrime-disruption-through-innovation-and-ai/ |
| Source13 | PublisherCISA | Published2026-07-27 | Publication / evidenceSource indexofficial | Why used / claim treatmentCISA controls known-exploitation status, the August 10 federal required-action date, the Unknown ransomware-use field, internet-exposure assessment, and the requirement to apply vendor mitigations with BOD 26-04 forensic triage. The entry does not identify an actor, victim, initial-access vulnerability, or local compromise. | SourceCVE-2025-68686 Known Exploited Vulnerability and BOD 26-04 Required Action https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-68686 |