{
  "generator": "Encrygma",
  "generator_url": "https://encrygma.com",
  "feed_type": "encrygma-attack-and-vulnerability-observations",
  "spec_version": "1.0",
  "generated": "2026-09-06T13:39:18.915Z",
  "license": "https://encrygma.com/legal",
  "counts": {
    "reports": 500,
    "threat_actors": 1,
    "techniques": 26,
    "vulnerabilities": 83,
    "observations": 122
  },
  "observations": [
    {
      "observation_id": "OBS-00001",
      "type": "vulnerability",
      "id": "CVE-2026-85046",
      "name": "CVE-2026-85046",
      "tactic": null,
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "Google Patches Actively Exploited Chrome V8 Zero-Day CVE-2026-85046 as CISA Mandates Remediation",
      "source_url": "https://encrygma.com/articles/google-patches-actively-exploited-chrome-v8-zero-day-cve-2026-85046-as-cisa-mand",
      "published_date": "2026-09-05"
    },
    {
      "observation_id": "OBS-00002",
      "type": "technique",
      "id": "T1059",
      "name": "Command and Scripting Interpreter",
      "tactic": "Execution",
      "threat_level": "high",
      "geography": "United States (AI lab evaluation)",
      "actor_type": "unknown",
      "source_report": "OpenAI Evaluation-Agent Compromise of Hugging Face Resurfaces as Reference Case for Agentic Containment",
      "source_url": "https://encrygma.com/articles/openai-evaluation-agent-hugging-face-compromise-resurface",
      "published_date": "2026-09-05"
    },
    {
      "observation_id": "OBS-00003",
      "type": "technique",
      "id": "T1078",
      "name": "Valid Accounts",
      "tactic": "Privilege Escalation",
      "threat_level": "high",
      "geography": "United States (AI lab evaluation)",
      "actor_type": "unknown",
      "source_report": "OpenAI Evaluation-Agent Compromise of Hugging Face Resurfaces as Reference Case for Agentic Containment",
      "source_url": "https://encrygma.com/articles/openai-evaluation-agent-hugging-face-compromise-resurface",
      "published_date": "2026-09-05"
    },
    {
      "observation_id": "OBS-00004",
      "type": "technique",
      "id": "T1211",
      "name": "Exploitation for Defense Evasion",
      "tactic": "Defense Evasion",
      "threat_level": "high",
      "geography": "United States (AI lab evaluation)",
      "actor_type": "unknown",
      "source_report": "OpenAI Evaluation-Agent Compromise of Hugging Face Resurfaces as Reference Case for Agentic Containment",
      "source_url": "https://encrygma.com/articles/openai-evaluation-agent-hugging-face-compromise-resurface",
      "published_date": "2026-09-05"
    },
    {
      "observation_id": "OBS-00005",
      "type": "technique",
      "id": "T1566",
      "name": "Phishing",
      "tactic": "Initial Access",
      "threat_level": "medium",
      "geography": "Global (commodity phishing)",
      "actor_type": "cybercriminal",
      "source_report": "Microsoft Documents ASCII Smuggling Crossing from Prompt-Injection Research into Phishing Evasion",
      "source_url": "https://encrygma.com/articles/microsoft-ascii-smuggling-unicode-tags-phishing-evasion",
      "published_date": "2026-09-05"
    },
    {
      "observation_id": "OBS-00006",
      "type": "technique",
      "id": "T1027",
      "name": "Obfuscated Files or Information",
      "tactic": "Defense Evasion",
      "threat_level": "medium",
      "geography": "Global (commodity phishing)",
      "actor_type": "cybercriminal",
      "source_report": "Microsoft Documents ASCII Smuggling Crossing from Prompt-Injection Research into Phishing Evasion",
      "source_url": "https://encrygma.com/articles/microsoft-ascii-smuggling-unicode-tags-phishing-evasion",
      "published_date": "2026-09-05"
    },
    {
      "observation_id": "OBS-00007",
      "type": "technique",
      "id": "T1566.001",
      "name": "Spearphishing Attachment",
      "tactic": "Initial Access",
      "threat_level": "medium",
      "geography": "Global (commodity phishing)",
      "actor_type": "cybercriminal",
      "source_report": "Microsoft Documents ASCII Smuggling Crossing from Prompt-Injection Research into Phishing Evasion",
      "source_url": "https://encrygma.com/articles/microsoft-ascii-smuggling-unicode-tags-phishing-evasion",
      "published_date": "2026-09-05"
    },
    {
      "observation_id": "OBS-00008",
      "type": "technique",
      "id": "T1059",
      "name": "Command and Scripting Interpreter",
      "tactic": "Execution",
      "threat_level": "low",
      "geography": "United States (lab evaluation)",
      "actor_type": "unknown",
      "source_report": "Lab Results: Claude Mythos Completes Full Cyber Kill Chain in Controlled Simulation; Hacker-Opus Reward-Hacking Documented",
      "source_url": "https://encrygma.com/articles/claude-mythos-lab-kill-chain-hacker-opus-reward-hacking",
      "published_date": "2026-09-05"
    },
    {
      "observation_id": "OBS-00009",
      "type": "technique",
      "id": "T1204",
      "name": "User Execution",
      "tactic": "Initial Access",
      "threat_level": "medium",
      "geography": "Global (developer targeting)",
      "actor_type": "cybercriminal",
      "source_report": "Fake \"Claude Opus 5 Free Desktop\" GitHub Repositories Deliver RevStealer Malware",
      "source_url": "https://encrygma.com/articles/fake-claude-opus-5-desktop-github-revstealer",
      "published_date": "2026-09-05"
    },
    {
      "observation_id": "OBS-00010",
      "type": "technique",
      "id": "T1555",
      "name": "Credentials from Password Stores",
      "tactic": "Credential Access",
      "threat_level": "medium",
      "geography": "Global (developer targeting)",
      "actor_type": "cybercriminal",
      "source_report": "Fake \"Claude Opus 5 Free Desktop\" GitHub Repositories Deliver RevStealer Malware",
      "source_url": "https://encrygma.com/articles/fake-claude-opus-5-desktop-github-revstealer",
      "published_date": "2026-09-05"
    },
    {
      "observation_id": "OBS-00011",
      "type": "technique",
      "id": "T1070",
      "name": "Indicator Removal",
      "tactic": "Defense Evasion",
      "threat_level": "medium",
      "geography": "Global (developer targeting)",
      "actor_type": "cybercriminal",
      "source_report": "Fake \"Claude Opus 5 Free Desktop\" GitHub Repositories Deliver RevStealer Malware",
      "source_url": "https://encrygma.com/articles/fake-claude-opus-5-desktop-github-revstealer",
      "published_date": "2026-09-05"
    },
    {
      "observation_id": "OBS-00012",
      "type": "vulnerability",
      "id": "CVE-2026-1731",
      "name": "CVE-2026-1731",
      "tactic": null,
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "cybercriminal",
      "source_report": "Storm-1175 Shifts to Custom StormEncryptor Ransomware in Rapid Exploitation Campaigns",
      "source_url": "https://encrygma.com/articles/storm-1175-shifts-to-custom-stormencryptor-ransomware-in-rapid-exploitation-camp",
      "published_date": "2026-09-04"
    },
    {
      "observation_id": "OBS-00013",
      "type": "vulnerability",
      "id": "CVE-2023-27350",
      "name": "CVE-2023-27350",
      "tactic": null,
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "cybercriminal",
      "source_report": "Storm-1175 Shifts to Custom StormEncryptor Ransomware in Rapid Exploitation Campaigns",
      "source_url": "https://encrygma.com/articles/storm-1175-shifts-to-custom-stormencryptor-ransomware-in-rapid-exploitation-camp",
      "published_date": "2026-09-04"
    },
    {
      "observation_id": "OBS-00014",
      "type": "vulnerability",
      "id": "CVE-2023-27351",
      "name": "CVE-2023-27351",
      "tactic": null,
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "cybercriminal",
      "source_report": "Storm-1175 Shifts to Custom StormEncryptor Ransomware in Rapid Exploitation Campaigns",
      "source_url": "https://encrygma.com/articles/storm-1175-shifts-to-custom-stormencryptor-ransomware-in-rapid-exploitation-camp",
      "published_date": "2026-09-04"
    },
    {
      "observation_id": "OBS-00015",
      "type": "technique",
      "id": "T1059",
      "name": "Command and Scripting Interpreter",
      "tactic": "Command and Scripting Interpreter",
      "threat_level": "high",
      "geography": "Latin America (Mexico, Ecuador, Brazil)",
      "actor_type": "cybercriminal",
      "source_report": "Unit 42 Tracks Latin American Clusters Using Self-Hosted NextChat to Iterate AI-Assisted Tooling",
      "source_url": "https://encrygma.com/articles/unit-42-latam-clusters-nextchat-llm-iterative-tooling",
      "published_date": "2026-09-04"
    },
    {
      "observation_id": "OBS-00016",
      "type": "technique",
      "id": "T1003",
      "name": "OS Credential Dumping",
      "tactic": "Credential Access",
      "threat_level": "high",
      "geography": "Latin America (Mexico, Ecuador, Brazil)",
      "actor_type": "cybercriminal",
      "source_report": "Unit 42 Tracks Latin American Clusters Using Self-Hosted NextChat to Iterate AI-Assisted Tooling",
      "source_url": "https://encrygma.com/articles/unit-42-latam-clusters-nextchat-llm-iterative-tooling",
      "published_date": "2026-09-04"
    },
    {
      "observation_id": "OBS-00017",
      "type": "technique",
      "id": "T1090",
      "name": "Proxy",
      "tactic": "Command and Control",
      "threat_level": "high",
      "geography": "Latin America (Mexico, Ecuador, Brazil)",
      "actor_type": "cybercriminal",
      "source_report": "Unit 42 Tracks Latin American Clusters Using Self-Hosted NextChat to Iterate AI-Assisted Tooling",
      "source_url": "https://encrygma.com/articles/unit-42-latam-clusters-nextchat-llm-iterative-tooling",
      "published_date": "2026-09-04"
    },
    {
      "observation_id": "OBS-00018",
      "type": "technique",
      "id": "T1071",
      "name": "Application Layer Protocol",
      "tactic": "Defense Evasion",
      "threat_level": "high",
      "geography": "Latin America (Mexico, Ecuador, Brazil)",
      "actor_type": "cybercriminal",
      "source_report": "Unit 42 Tracks Latin American Clusters Using Self-Hosted NextChat to Iterate AI-Assisted Tooling",
      "source_url": "https://encrygma.com/articles/unit-42-latam-clusters-nextchat-llm-iterative-tooling",
      "published_date": "2026-09-04"
    },
    {
      "observation_id": "OBS-00019",
      "type": "technique",
      "id": "T1204",
      "name": "User Execution",
      "tactic": "Execution",
      "threat_level": "high",
      "geography": "Latin America (Mexico, Ecuador, Brazil)",
      "actor_type": "cybercriminal",
      "source_report": "Unit 42 Tracks Latin American Clusters Using Self-Hosted NextChat to Iterate AI-Assisted Tooling",
      "source_url": "https://encrygma.com/articles/unit-42-latam-clusters-nextchat-llm-iterative-tooling",
      "published_date": "2026-09-04"
    },
    {
      "observation_id": "OBS-00020",
      "type": "vulnerability",
      "id": "CVE-2026-83548",
      "name": "CVE-2026-83548",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "SonicWall Issues Emergency Hotfix for Actively Exploited SMA 1000 Zero-Day Chain",
      "source_url": "https://encrygma.com/articles/sonicwall-issues-emergency-hotfix-for-actively-exploited-sma-1000-zero-day-chain",
      "published_date": "2026-09-04"
    },
    {
      "observation_id": "OBS-00021",
      "type": "vulnerability",
      "id": "CVE-2026-83549",
      "name": "CVE-2026-83549",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "SonicWall Issues Emergency Hotfix for Actively Exploited SMA 1000 Zero-Day Chain",
      "source_url": "https://encrygma.com/articles/sonicwall-issues-emergency-hotfix-for-actively-exploited-sma-1000-zero-day-chain",
      "published_date": "2026-09-04"
    },
    {
      "observation_id": "OBS-00022",
      "type": "vulnerability",
      "id": "CVE-2026-15409",
      "name": "CVE-2026-15409",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "SonicWall Issues Emergency Hotfix for Actively Exploited SMA 1000 Zero-Day Chain",
      "source_url": "https://encrygma.com/articles/sonicwall-issues-emergency-hotfix-for-actively-exploited-sma-1000-zero-day-chain",
      "published_date": "2026-09-04"
    },
    {
      "observation_id": "OBS-00023",
      "type": "vulnerability",
      "id": "CVE-2026-15410",
      "name": "CVE-2026-15410",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "SonicWall Issues Emergency Hotfix for Actively Exploited SMA 1000 Zero-Day Chain",
      "source_url": "https://encrygma.com/articles/sonicwall-issues-emergency-hotfix-for-actively-exploited-sma-1000-zero-day-chain",
      "published_date": "2026-09-04"
    },
    {
      "observation_id": "OBS-00024",
      "type": "technique",
      "id": "T1590",
      "name": "Gather Victim Host Information",
      "tactic": "Reconnaissance",
      "threat_level": "critical",
      "geography": "Unspecified (global enterprise)",
      "actor_type": "ransomware_group",
      "source_report": "Unit 42 Documents AI-Assisted Ransomware Intrusion Completed in Under 10 Hours",
      "source_url": "https://encrygma.com/articles/unit-42-ai-assisted-ransomware-intrusion-under-10-hours",
      "published_date": "2026-09-03"
    },
    {
      "observation_id": "OBS-00025",
      "type": "technique",
      "id": "T1580",
      "name": "Cloud Infrastructure Discovery",
      "tactic": "Discovery",
      "threat_level": "critical",
      "geography": "Unspecified (global enterprise)",
      "actor_type": "ransomware_group",
      "source_report": "Unit 42 Documents AI-Assisted Ransomware Intrusion Completed in Under 10 Hours",
      "source_url": "https://encrygma.com/articles/unit-42-ai-assisted-ransomware-intrusion-under-10-hours",
      "published_date": "2026-09-03"
    },
    {
      "observation_id": "OBS-00026",
      "type": "technique",
      "id": "T1552",
      "name": "Unsecured Credentials",
      "tactic": "Credential Access",
      "threat_level": "critical",
      "geography": "Unspecified (global enterprise)",
      "actor_type": "ransomware_group",
      "source_report": "Unit 42 Documents AI-Assisted Ransomware Intrusion Completed in Under 10 Hours",
      "source_url": "https://encrygma.com/articles/unit-42-ai-assisted-ransomware-intrusion-under-10-hours",
      "published_date": "2026-09-03"
    },
    {
      "observation_id": "OBS-00027",
      "type": "technique",
      "id": "T1078",
      "name": "Valid Accounts",
      "tactic": "Defense Evasion, Persistence, Privilege Escalation",
      "threat_level": "critical",
      "geography": "Unspecified (global enterprise)",
      "actor_type": "ransomware_group",
      "source_report": "Unit 42 Documents AI-Assisted Ransomware Intrusion Completed in Under 10 Hours",
      "source_url": "https://encrygma.com/articles/unit-42-ai-assisted-ransomware-intrusion-under-10-hours",
      "published_date": "2026-09-03"
    },
    {
      "observation_id": "OBS-00028",
      "type": "technique",
      "id": "T1555",
      "name": "Credentials from Password Stores",
      "tactic": "Credential Access",
      "threat_level": "critical",
      "geography": "Unspecified (global enterprise)",
      "actor_type": "ransomware_group",
      "source_report": "Unit 42 Documents AI-Assisted Ransomware Intrusion Completed in Under 10 Hours",
      "source_url": "https://encrygma.com/articles/unit-42-ai-assisted-ransomware-intrusion-under-10-hours",
      "published_date": "2026-09-03"
    },
    {
      "observation_id": "OBS-00029",
      "type": "technique",
      "id": "T1059",
      "name": "Command and Scripting Interpreter",
      "tactic": "Execution",
      "threat_level": "critical",
      "geography": "Unspecified (global enterprise)",
      "actor_type": "ransomware_group",
      "source_report": "Unit 42 Documents AI-Assisted Ransomware Intrusion Completed in Under 10 Hours",
      "source_url": "https://encrygma.com/articles/unit-42-ai-assisted-ransomware-intrusion-under-10-hours",
      "published_date": "2026-09-03"
    },
    {
      "observation_id": "OBS-00030",
      "type": "technique",
      "id": "T1199",
      "name": "Trusted Relationship",
      "tactic": "Initial Access",
      "threat_level": "critical",
      "geography": "Unspecified (global enterprise)",
      "actor_type": "ransomware_group",
      "source_report": "Unit 42 Documents AI-Assisted Ransomware Intrusion Completed in Under 10 Hours",
      "source_url": "https://encrygma.com/articles/unit-42-ai-assisted-ransomware-intrusion-under-10-hours",
      "published_date": "2026-09-03"
    },
    {
      "observation_id": "OBS-00031",
      "type": "technique",
      "id": "T1486",
      "name": "Data Encrypted for Impact",
      "tactic": "Impact",
      "threat_level": "critical",
      "geography": "Unspecified (global enterprise)",
      "actor_type": "ransomware_group",
      "source_report": "Unit 42 Documents AI-Assisted Ransomware Intrusion Completed in Under 10 Hours",
      "source_url": "https://encrygma.com/articles/unit-42-ai-assisted-ransomware-intrusion-under-10-hours",
      "published_date": "2026-09-03"
    },
    {
      "observation_id": "OBS-00032",
      "type": "technique",
      "id": "T1566",
      "name": "Phishing",
      "tactic": "Initial Access",
      "threat_level": "high",
      "geography": "United Kingdom",
      "actor_type": "unknown",
      "source_report": "UK AI Security Institute Reports Unsanctioned Agent Behaviour in Cyber Evaluation",
      "source_url": "https://encrygma.com/articles/uk-aisi-unsanctioned-agent-behaviour-cyber-evaluation",
      "published_date": "2026-09-03"
    },
    {
      "observation_id": "OBS-00033",
      "type": "technique",
      "id": "T1656",
      "name": "Impersonation",
      "tactic": "Initial Access",
      "threat_level": "high",
      "geography": "United Kingdom",
      "actor_type": "unknown",
      "source_report": "UK AI Security Institute Reports Unsanctioned Agent Behaviour in Cyber Evaluation",
      "source_url": "https://encrygma.com/articles/uk-aisi-unsanctioned-agent-behaviour-cyber-evaluation",
      "published_date": "2026-09-03"
    },
    {
      "observation_id": "OBS-00034",
      "type": "technique",
      "id": "T1059",
      "name": "Command and Scripting Interpreter",
      "tactic": "Execution",
      "threat_level": "high",
      "geography": "United Kingdom",
      "actor_type": "unknown",
      "source_report": "UK AI Security Institute Reports Unsanctioned Agent Behaviour in Cyber Evaluation",
      "source_url": "https://encrygma.com/articles/uk-aisi-unsanctioned-agent-behaviour-cyber-evaluation",
      "published_date": "2026-09-03"
    },
    {
      "observation_id": "OBS-00035",
      "type": "technique",
      "id": "T1199",
      "name": "Trusted Relationship",
      "tactic": "Initial Access",
      "threat_level": "high",
      "geography": "United Kingdom",
      "actor_type": "unknown",
      "source_report": "UK AI Security Institute Reports Unsanctioned Agent Behaviour in Cyber Evaluation",
      "source_url": "https://encrygma.com/articles/uk-aisi-unsanctioned-agent-behaviour-cyber-evaluation",
      "published_date": "2026-09-03"
    },
    {
      "observation_id": "OBS-00036",
      "type": "vulnerability",
      "id": "CVE-2026-0257",
      "name": "CVE-2026-0257",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "ransomware_group",
      "source_report": "FulcrumSec Targets Manchester Airports Group as Krybit and Qilin Escalate Global Extortion Campaigns",
      "source_url": "https://encrygma.com/articles/fulcrumsec-targets-manchester-airports-group-as-krybit-and-qilin-escalate-global",
      "published_date": "2026-09-03"
    },
    {
      "observation_id": "OBS-00037",
      "type": "vulnerability",
      "id": "CVE-2026-82329",
      "name": "CVE-2026-82329",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "ransomware_group",
      "source_report": "SonicWall SMA1000 Zero-Day Chain (CVE-2026-83548/9) Under Active Exploitation by Ransomware Groups",
      "source_url": "https://encrygma.com/articles/sonicwall-sma1000-zero-day-chain-cve-2026-83548-9-under-active-exploitation-by-r",
      "published_date": "2026-09-02"
    },
    {
      "observation_id": "OBS-00038",
      "type": "vulnerability",
      "id": "CVE-2026-68820",
      "name": "CVE-2026-68820",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "ransomware_group",
      "source_report": "SonicWall SMA1000 Zero-Day Chain (CVE-2026-83548/9) Under Active Exploitation by Ransomware Groups",
      "source_url": "https://encrygma.com/articles/sonicwall-sma1000-zero-day-chain-cve-2026-83548-9-under-active-exploitation-by-r",
      "published_date": "2026-09-02"
    },
    {
      "observation_id": "OBS-00039",
      "type": "technique",
      "id": "T1195.002",
      "name": "Compromise Software Supply Chain",
      "tactic": "Initial Access",
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "unknown",
      "source_report": "GitSpawn: Unsanitized Git Context Lets Attackers Hijack Claude Code, Cursor, Codex and Other AI Coding Agents",
      "source_url": "https://encrygma.com/articles/gitspawn-unsanitized-git-context-lets-attackers-hijack-ai-coding-agents",
      "published_date": "2026-09-02"
    },
    {
      "observation_id": "OBS-00040",
      "type": "technique",
      "id": "T1059",
      "name": "Command and Scripting Interpreter",
      "tactic": "Execution",
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "unknown",
      "source_report": "GitSpawn: Unsanitized Git Context Lets Attackers Hijack Claude Code, Cursor, Codex and Other AI Coding Agents",
      "source_url": "https://encrygma.com/articles/gitspawn-unsanitized-git-context-lets-attackers-hijack-ai-coding-agents",
      "published_date": "2026-09-02"
    },
    {
      "observation_id": "OBS-00041",
      "type": "vulnerability",
      "id": "CVE-2023-25717",
      "name": "CVE-2023-25717",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global / Middle East and Asia",
      "actor_type": "nation_state",
      "source_report": "Fire Ant APT Leverages Compromised Cisco Infrastructure and SLEEPWALKER Backdoor for Stealthy Espionage",
      "source_url": "https://encrygma.com/articles/fire-ant-apt-leverages-compromised-cisco-infrastructure-and-sleepwalker-backdoor",
      "published_date": "2026-09-02"
    },
    {
      "observation_id": "OBS-00042",
      "type": "technique",
      "id": "T1595.002",
      "name": "Active Scanning: Vulnerability Scanning",
      "tactic": "Reconnaissance",
      "threat_level": "medium",
      "geography": "Global",
      "actor_type": "cybercriminal",
      "source_report": "Threat Actors Pose as OpenAI, Anthropic and Google AI Crawlers to Harvest .env Files, AWS Keys and Private Certificates",
      "source_url": "https://encrygma.com/articles/threat-actors-pose-as-openai-anthropic-google-ai-crawlers-to-harvest-credentials",
      "published_date": "2026-09-02"
    },
    {
      "observation_id": "OBS-00043",
      "type": "technique",
      "id": "T1552.001",
      "name": "Unsecured Credentials: Credentials In Files",
      "tactic": "Credential Access",
      "threat_level": "medium",
      "geography": "Global",
      "actor_type": "cybercriminal",
      "source_report": "Threat Actors Pose as OpenAI, Anthropic and Google AI Crawlers to Harvest .env Files, AWS Keys and Private Certificates",
      "source_url": "https://encrygma.com/articles/threat-actors-pose-as-openai-anthropic-google-ai-crawlers-to-harvest-credentials",
      "published_date": "2026-09-02"
    },
    {
      "observation_id": "OBS-00044",
      "type": "technique",
      "id": "T1437.001",
      "name": "Mobile Application Configuration",
      "tactic": "Persistence",
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "cybercriminal",
      "source_report": "ZeroDayRAT: Defensive Intelligence Analysis of a Commoditized Mobile Surveillance Platform",
      "source_url": "https://encrygma.com/articles/zerodayrat-defensive-intelligence-analysis-commoditized-mobile-surveillance-platform",
      "published_date": "2026-09-02"
    },
    {
      "observation_id": "OBS-00045",
      "type": "technique",
      "id": "T1437.002",
      "name": "Mobile Device Management (MDM) Profile",
      "tactic": "Persistence",
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "cybercriminal",
      "source_report": "ZeroDayRAT: Defensive Intelligence Analysis of a Commoditized Mobile Surveillance Platform",
      "source_url": "https://encrygma.com/articles/zerodayrat-defensive-intelligence-analysis-commoditized-mobile-surveillance-platform",
      "published_date": "2026-09-02"
    },
    {
      "observation_id": "OBS-00046",
      "type": "vulnerability",
      "id": "CVE-2026-81578",
      "name": "CVE-2026-81578",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "Critical PaperCut Zero-Day Exploits Under Active Attack: CISA Issues Urgent Patch Directive",
      "source_url": "https://encrygma.com/articles/critical-papercut-zero-day-exploits-under-active-attack-cisa-issues-urgent-patch",
      "published_date": "2026-09-01"
    },
    {
      "observation_id": "OBS-00047",
      "type": "vulnerability",
      "id": "CVE-2026-82078",
      "name": "CVE-2026-82078",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "Critical PaperCut Zero-Day Exploits Under Active Attack: CISA Issues Urgent Patch Directive",
      "source_url": "https://encrygma.com/articles/critical-papercut-zero-day-exploits-under-active-attack-cisa-issues-urgent-patch",
      "published_date": "2026-09-01"
    },
    {
      "observation_id": "OBS-00048",
      "type": "technique",
      "id": "T1585",
      "name": "Establish Accounts",
      "tactic": "Resource Development",
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "North Korean Job Fraud Expands Beyond Tech: AI-Generated Personas Infiltrate Healthcare, Finance and Sales Roles",
      "source_url": "https://encrygma.com/articles/north-korean-job-fraud-expands-beyond-tech-ai-generated-personas-infiltrate-heal",
      "published_date": "2026-09-01"
    },
    {
      "observation_id": "OBS-00049",
      "type": "technique",
      "id": "T1078",
      "name": "Valid Accounts",
      "tactic": "Initial Access",
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "North Korean Job Fraud Expands Beyond Tech: AI-Generated Personas Infiltrate Healthcare, Finance and Sales Roles",
      "source_url": "https://encrygma.com/articles/north-korean-job-fraud-expands-beyond-tech-ai-generated-personas-infiltrate-heal",
      "published_date": "2026-09-01"
    },
    {
      "observation_id": "OBS-00050",
      "type": "technique",
      "id": "T1195.002",
      "name": "Compromise Software Supply Chain",
      "tactic": "Initial Access",
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "unknown",
      "source_report": "Shadow AI in Sanctioned Tools: Malicious AI Skills and MCP Servers Hide Inside Approved Agent Workflows",
      "source_url": "https://encrygma.com/articles/shadow-ai-in-sanctioned-tools-malicious-ai-skills-and-mcp-servers-hide-inside-ap",
      "published_date": "2026-09-01"
    },
    {
      "observation_id": "OBS-00051",
      "type": "technique",
      "id": "T1555",
      "name": "Credentials from Password Stores",
      "tactic": "Credential Access",
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "unknown",
      "source_report": "Shadow AI in Sanctioned Tools: Malicious AI Skills and MCP Servers Hide Inside Approved Agent Workflows",
      "source_url": "https://encrygma.com/articles/shadow-ai-in-sanctioned-tools-malicious-ai-skills-and-mcp-servers-hide-inside-ap",
      "published_date": "2026-09-01"
    },
    {
      "observation_id": "OBS-00052",
      "type": "vulnerability",
      "id": "CVE-2026-20896",
      "name": "CVE-2026-20896",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "cybercriminal",
      "source_report": "Critical Gitea Authentication Bypass Under Active Exploitation",
      "source_url": "https://encrygma.com/articles/critical-gitea-authentication-bypass-under-active-exploitation",
      "published_date": "2026-08-30"
    },
    {
      "observation_id": "OBS-00053",
      "type": "vulnerability",
      "id": "CVE-2026-69836",
      "name": "CVE-2026-69836",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "Critical Entra ID Zero-Day Exploited in the Wild: Immediate Patching Required",
      "source_url": "https://encrygma.com/articles/critical-entra-id-zero-day-exploited-in-the-wild-immediate-patching-required",
      "published_date": "2026-08-28"
    },
    {
      "observation_id": "OBS-00054",
      "type": "vulnerability",
      "id": "CVE-2026-18577",
      "name": "CVE-2026-18577",
      "tactic": null,
      "threat_level": "critical",
      "geography": "North America",
      "actor_type": "ransomware_group",
      "source_report": "ATF Confirms Major Security Incident Following Qilin Ransomware Data Exfiltration Claims",
      "source_url": "https://encrygma.com/articles/atf-confirms-major-security-incident-following-qilin-ransomware-data-exfiltratio",
      "published_date": "2026-08-27"
    },
    {
      "observation_id": "OBS-00055",
      "type": "vulnerability",
      "id": "CVE-2026-47890",
      "name": "CVE-2026-47890",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "Critical Entra ID RCE and 'ShieldBreak' Zero-Day Exploited by Lazarus Group",
      "source_url": "https://encrygma.com/articles/critical-entra-id-rce-and-shieldbreak-zero-day-exploited-by-lazarus-group",
      "published_date": "2026-08-27"
    },
    {
      "observation_id": "OBS-00056",
      "type": "vulnerability",
      "id": "CVE-2026-50656",
      "name": "CVE-2026-50656",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "Critical Entra ID RCE and 'ShieldBreak' Zero-Day Exploited by Lazarus Group",
      "source_url": "https://encrygma.com/articles/critical-entra-id-rce-and-shieldbreak-zero-day-exploited-by-lazarus-group",
      "published_date": "2026-08-27"
    },
    {
      "observation_id": "OBS-00057",
      "type": "vulnerability",
      "id": "CVE-2025-55182",
      "name": "CVE-2025-55182",
      "tactic": null,
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "Unit 42 and Firebrand Report Surge in LLM-Assisted Malware and AI-Generated Phishing Campaigns",
      "source_url": "https://encrygma.com/articles/unit-42-and-firebrand-report-surge-in-llm-assisted-malware-and-ai-generated-phis",
      "published_date": "2026-08-27"
    },
    {
      "observation_id": "OBS-00058",
      "type": "vulnerability",
      "id": "CVE-2026-69414",
      "name": "CVE-2026-69414",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "CISA Issues Urgent Mandate for ShieldBreak Zero-Day (CVE-2026-69414) Amid Active Exploitation",
      "source_url": "https://encrygma.com/articles/cisa-issues-urgent-mandate-for-shieldbreak-zero-day-cve-2026-69414-amid-active-e",
      "published_date": "2026-08-26"
    },
    {
      "observation_id": "OBS-00059",
      "type": "vulnerability",
      "id": "CVE-2024-55591",
      "name": "CVE-2024-55591",
      "tactic": null,
      "threat_level": "critical",
      "geography": "North America",
      "actor_type": "ransomware_group",
      "source_report": "GlobalSecretGroup and The Gentlemen Lead Late-August Ransomware Surge Targeting US Critical Supply Chains",
      "source_url": "https://encrygma.com/articles/globalsecretgroup-and-the-gentlemen-lead-late-august-ransomware-surge-targeting-",
      "published_date": "2026-08-26"
    },
    {
      "observation_id": "OBS-00060",
      "type": "vulnerability",
      "id": "CVE-2025-32433",
      "name": "CVE-2025-32433",
      "tactic": null,
      "threat_level": "critical",
      "geography": "North America",
      "actor_type": "ransomware_group",
      "source_report": "GlobalSecretGroup and The Gentlemen Lead Late-August Ransomware Surge Targeting US Critical Supply Chains",
      "source_url": "https://encrygma.com/articles/globalsecretgroup-and-the-gentlemen-lead-late-august-ransomware-surge-targeting-",
      "published_date": "2026-08-26"
    },
    {
      "observation_id": "OBS-00061",
      "type": "vulnerability",
      "id": "CVE-2026-21962",
      "name": "CVE-2026-21962",
      "tactic": null,
      "threat_level": "critical",
      "geography": "United Kingdom / United States",
      "actor_type": "nation_state",
      "source_report": "Iranian State Actors Paralyze UK Power Plant; CISA Warns of AI-Driven Exploitation of Critical OT Infrastructure",
      "source_url": "https://encrygma.com/articles/iranian-state-actors-paralyze-uk-power-plant-cisa-warns-of-ai-driven-exploitatio",
      "published_date": "2026-08-26"
    },
    {
      "observation_id": "OBS-00062",
      "type": "vulnerability",
      "id": "CVE-2024-21887",
      "name": "CVE-2024-21887",
      "tactic": null,
      "threat_level": "high",
      "geography": "North America",
      "actor_type": "ransomware_group",
      "source_report": "Storm Ransomware Targets Phoenix Group of Companies Amid Surge in RaaS Activity",
      "source_url": "https://encrygma.com/articles/storm-ransomware-targets-phoenix-group-of-companies-amid-surge-in-raas-activity",
      "published_date": "2026-08-25"
    },
    {
      "observation_id": "OBS-00063",
      "type": "vulnerability",
      "id": "CVE-2026-61893",
      "name": "CVE-2026-61893",
      "tactic": null,
      "threat_level": "critical",
      "geography": "United Kingdom",
      "actor_type": "nation_state",
      "source_report": "Iranian-Linked Cyberattack Triggers Four-Day Shutdown of UK Power Station; CISA Warns of AI-Driven PLC Exploits",
      "source_url": "https://encrygma.com/articles/iranian-linked-cyberattack-triggers-four-day-shutdown-of-uk-power-station-cisa-w",
      "published_date": "2026-08-25"
    },
    {
      "observation_id": "OBS-00064",
      "type": "vulnerability",
      "id": "CVE-2026-19478",
      "name": "CVE-2026-19478",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "ransomware_group",
      "source_report": "ShinyHunters Issues Final Ultimatum to Logitech/Streamlabs as Medusa Targets 500+ Critical Infrastructure Entities",
      "source_url": "https://encrygma.com/articles/shinyhunters-issues-final-ultimatum-to-logitech-streamlabs-as-medusa-targets-500",
      "published_date": "2026-08-21"
    },
    {
      "observation_id": "OBS-00065",
      "type": "vulnerability",
      "id": "CVE-2026-59310",
      "name": "CVE-2026-59310",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "China-Nexus APT Exploits Critical VMware vCenter Flaw CVE-2026-59310 to Deploy Babuk-Derived Ransomware",
      "source_url": "https://encrygma.com/articles/china-nexus-apt-exploits-critical-vmware-vcenter-flaw-cve-2026-59310-to-deploy-b",
      "published_date": "2026-08-20"
    },
    {
      "observation_id": "OBS-00066",
      "type": "technique",
      "id": "T0831",
      "name": "T0831",
      "tactic": null,
      "threat_level": "high",
      "geography": "North America",
      "actor_type": "apt",
      "source_report": "Iranian-Linked CyberAv3ngers Expand Targeting to Oregon and New Jersey Water Utilities via Exposed PLC Interfaces",
      "source_url": "https://encrygma.com/articles/iranian-linked-cyberav3ngers-expand-targeting-to-oregon-and-new-jersey-water-uti",
      "published_date": "2026-08-19"
    },
    {
      "observation_id": "OBS-00067",
      "type": "vulnerability",
      "id": "CVE-2024-40766",
      "name": "CVE-2024-40766",
      "tactic": null,
      "threat_level": "critical",
      "geography": "North America",
      "actor_type": "ransomware_group",
      "source_report": "Qilin Ransomware Targets US Legal and IT Sectors in Latest Double-Extortion Campaign",
      "source_url": "https://encrygma.com/articles/qilin-ransomware-targets-us-legal-and-it-sectors-in-latest-double-extortion-camp",
      "published_date": "2026-08-18"
    },
    {
      "observation_id": "OBS-00068",
      "type": "vulnerability",
      "id": "CVE-2026-58231",
      "name": "CVE-2026-58231",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "ransomware_group",
      "source_report": "Global Secret Group Ransomware Syndicate Leverages LockBit Black Derivatives to Target Energy Sector",
      "source_url": "https://encrygma.com/articles/global-secret-group-ransomware-syndicate-leverages-lockbit-black-derivatives-to-",
      "published_date": "2026-08-18"
    },
    {
      "observation_id": "OBS-00069",
      "type": "vulnerability",
      "id": "CVE-2026-13739",
      "name": "CVE-2026-13739",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "ransomware_group",
      "source_report": "Global Secret Group Ransomware Syndicate Leverages LockBit Black Derivatives to Target Energy Sector",
      "source_url": "https://encrygma.com/articles/global-secret-group-ransomware-syndicate-leverages-lockbit-black-derivatives-to-",
      "published_date": "2026-08-18"
    },
    {
      "observation_id": "OBS-00070",
      "type": "vulnerability",
      "id": "CVE-2025-66376",
      "name": "CVE-2025-66376",
      "tactic": null,
      "threat_level": "high",
      "geography": "Europe",
      "actor_type": "nation_state",
      "source_report": "Void Blizzard Targets European Cloud Infrastructure via Critical Zimbra Vulnerability CVE-2025-66376",
      "source_url": "https://encrygma.com/articles/void-blizzard-targets-european-cloud-infrastructure-via-critical-zimbra-vulnerab",
      "published_date": "2026-08-17"
    },
    {
      "observation_id": "OBS-00071",
      "type": "vulnerability",
      "id": "CVE-2026-20182",
      "name": "CVE-2026-20182",
      "tactic": null,
      "threat_level": "critical",
      "geography": "North America",
      "actor_type": "nation_state",
      "source_report": "Iranian IRGC-Affiliated Actors Escalate PLC Targeting Across U.S. Water Sector, Triggering Operational Disruptions",
      "source_url": "https://encrygma.com/articles/iranian-irgc-affiliated-actors-escalate-plc-targeting-across-u-s-water-sector-tr",
      "published_date": "2026-08-16"
    },
    {
      "observation_id": "OBS-00072",
      "type": "vulnerability",
      "id": "CVE-2025-24472",
      "name": "CVE-2025-24472",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "ransomware_group",
      "source_report": "Gunra and Blacknevas Ransomware Escalation: Critical Infrastructure Under Siege via Fortinet and SharePoint Flaws",
      "source_url": "https://encrygma.com/articles/gunra-and-blacknevas-ransomware-escalation-critical-infrastructure-under-siege-v",
      "published_date": "2026-08-15"
    },
    {
      "observation_id": "OBS-00073",
      "type": "vulnerability",
      "id": "CVE-2025-14174",
      "name": "CVE-2025-14174",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "Apple Issues Global Spyware Alerts to 110 Countries as US Sanctions Disrupt Operation Zero Exploit Pipeline",
      "source_url": "https://encrygma.com/articles/apple-issues-global-spyware-alerts-to-110-countries-as-us-sanctions-disrupt-oper",
      "published_date": "2026-08-15"
    },
    {
      "observation_id": "OBS-00074",
      "type": "vulnerability",
      "id": "CVE-2025-43529",
      "name": "CVE-2025-43529",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "Apple Issues Global Spyware Alerts to 110 Countries as US Sanctions Disrupt Operation Zero Exploit Pipeline",
      "source_url": "https://encrygma.com/articles/apple-issues-global-spyware-alerts-to-110-countries-as-us-sanctions-disrupt-oper",
      "published_date": "2026-08-15"
    },
    {
      "observation_id": "OBS-00075",
      "type": "vulnerability",
      "id": "CVE-2021-22681",
      "name": "CVE-2021-22681",
      "tactic": null,
      "threat_level": "critical",
      "geography": "North America / Global",
      "actor_type": "nation_state",
      "source_report": "State-Sponsored Groups Exploit PLC Vulnerabilities and ISP Backbones to Target Regional Water Systems",
      "source_url": "https://encrygma.com/articles/state-sponsored-groups-exploit-plc-vulnerabilities-and-isp-backbones-to-target-r",
      "published_date": "2026-08-15"
    },
    {
      "observation_id": "OBS-00076",
      "type": "vulnerability",
      "id": "CVE-2026-63077",
      "name": "CVE-2026-63077",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "Operation CloudSieve: APT41 Exploits CVE-2026-63077 in TeamCity to Infiltrate Global Defense Supply Chains",
      "source_url": "https://encrygma.com/articles/operation-cloudsieve-apt41-exploits-cve-2026-63077-in-teamcity-to-infiltrate-glo",
      "published_date": "2026-08-12"
    },
    {
      "observation_id": "OBS-00077",
      "type": "vulnerability",
      "id": "CVE-2026-8037",
      "name": "CVE-2026-8037",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "unknown",
      "source_report": "Metabase and JetBrains TeamCity Zero-Days Under Active Exploitation; CISA Issues Urgent KEV Warnings",
      "source_url": "https://encrygma.com/articles/metabase-and-jetbrains-teamcity-zero-days-under-active-exploitation-cisa-issues-",
      "published_date": "2026-08-11"
    },
    {
      "observation_id": "OBS-00078",
      "type": "vulnerability",
      "id": "CVE-2026-9981",
      "name": "CVE-2026-9981",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "ransomware_group",
      "source_report": "Storm-1175 Exploits N-able Vulnerability to Deploy StormEncryptor Ransomware in Global Supply Chain Campaign",
      "source_url": "https://encrygma.com/articles/storm-1175-exploits-n-able-vulnerability-to-deploy-stormencryptor-ransomware-in-",
      "published_date": "2026-08-10"
    },
    {
      "observation_id": "OBS-00079",
      "type": "vulnerability",
      "id": "CVE-2026-33012",
      "name": "CVE-2026-33012",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "ransomware_group",
      "source_report": "Storm-1175 Deploys New StormEncryptor Ransomware via N-able Vulnerability Exploitation",
      "source_url": "https://encrygma.com/articles/storm-1175-deploys-new-stormencryptor-ransomware-via-n-able-vulnerability-exploi",
      "published_date": "2026-08-10"
    },
    {
      "observation_id": "OBS-00080",
      "type": "vulnerability",
      "id": "CVE-2026-20700",
      "name": "CVE-2026-20700",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "NSA Integrates Anthropic’s Mythos AI for Offensive Cyber Operations Amid Surge in AI-Driven Exploit Kits",
      "source_url": "https://encrygma.com/articles/nsa-integrates-anthropic-s-mythos-ai-for-offensive-cyber-operations-amid-surge-i",
      "published_date": "2026-08-09"
    },
    {
      "observation_id": "OBS-00081",
      "type": "vulnerability",
      "id": "CVE-2026-13584",
      "name": "CVE-2026-13584",
      "tactic": null,
      "threat_level": "critical",
      "geography": "United States",
      "actor_type": "nation_state",
      "source_report": "Coordinated Cyber Campaign Hits Water Utilities in 12 States; FBI Links Activity to Iranian-Backed Actors",
      "source_url": "https://encrygma.com/articles/coordinated-cyber-campaign-hits-water-utilities-in-12-states-fbi-links-activity-",
      "published_date": "2026-08-08"
    },
    {
      "observation_id": "OBS-00082",
      "type": "vulnerability",
      "id": "CVE-2026-3892",
      "name": "CVE-2026-3892",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "Cisco FMC Zero-Day (CVE-2026-3892) Actively Exploited via Static Credentials to Expose Sensitive Data",
      "source_url": "https://encrygma.com/articles/cisco-fmc-zero-day-cve-2026-3892-actively-exploited-via-static-credentials-to-ex",
      "published_date": "2026-08-08"
    },
    {
      "observation_id": "OBS-00083",
      "type": "vulnerability",
      "id": "CVE-2026-18556",
      "name": "CVE-2026-18556",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "cybercriminal",
      "source_report": "Critical N-able N-central Vulnerability Under Active Exploitation: Immediate Patch Required",
      "source_url": "https://encrygma.com/articles/critical-n-able-n-central-vulnerability-under-active-exploitation-immediate-patc",
      "published_date": "2026-08-07"
    },
    {
      "observation_id": "OBS-00084",
      "type": "vulnerability",
      "id": "CVE-2026-22719",
      "name": "CVE-2026-22719",
      "tactic": null,
      "threat_level": "critical",
      "geography": "North America",
      "actor_type": "nation_state",
      "source_report": "Coordinated Cyberattacks Strike 30+ Minnesota Water Utilities; State-Sponsored ICS Targeting Suspected",
      "source_url": "https://encrygma.com/articles/coordinated-cyberattacks-strike-30-minnesota-water-utilities-state-sponsored-ics",
      "published_date": "2026-08-06"
    },
    {
      "observation_id": "OBS-00085",
      "type": "vulnerability",
      "id": "CVE-2026-16812",
      "name": "CVE-2026-16812",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "unknown",
      "source_report": "Critical Arista VeloCloud Zero-Day Exploited as FreeRDP Supply Chain Flaw Threatens Remote Access",
      "source_url": "https://encrygma.com/articles/critical-arista-velocloud-zero-day-exploited-as-freerdp-supply-chain-flaw-threat",
      "published_date": "2026-08-05"
    },
    {
      "observation_id": "OBS-00086",
      "type": "vulnerability",
      "id": "CVE-2026-66402",
      "name": "CVE-2026-66402",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "unknown",
      "source_report": "Critical Arista VeloCloud Zero-Day Exploited as FreeRDP Supply Chain Flaw Threatens Remote Access",
      "source_url": "https://encrygma.com/articles/critical-arista-velocloud-zero-day-exploited-as-freerdp-supply-chain-flaw-threat",
      "published_date": "2026-08-05"
    },
    {
      "observation_id": "OBS-00087",
      "type": "vulnerability",
      "id": "CVE-2026-21509",
      "name": "CVE-2026-21509",
      "tactic": null,
      "threat_level": "critical",
      "geography": "North America",
      "actor_type": "nation_state",
      "source_report": "Iranian APT Earth Vetala Targets U.S. Water Infrastructure in Multi-State Cyber Offensive",
      "source_url": "https://encrygma.com/articles/iranian-apt-earth-vetala-targets-u-s-water-infrastructure-in-multi-state-cyber-o",
      "published_date": "2026-08-05"
    },
    {
      "observation_id": "OBS-00088",
      "type": "vulnerability",
      "id": "CVE-2024-38063",
      "name": "CVE-2024-38063",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "unknown",
      "source_report": "Critical Windows TCP/IP Stack RCE Vulnerability (CVE-2024-38063) Targeted in Remote Attacks",
      "source_url": "https://encrygma.com/articles/critical-windows-tcp-ip-stack-rce-vulnerability-cve-2024-38063-targeted-in-remot",
      "published_date": "2026-08-03"
    },
    {
      "observation_id": "OBS-00089",
      "type": "vulnerability",
      "id": "CVE-2024-20353",
      "name": "CVE-2024-20353",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "State-Sponsored ArcaneDoor Campaign Exploits Cisco Zero-Days for Deep Network Espionage",
      "source_url": "https://encrygma.com/articles/state-sponsored-arcanedoor-campaign-exploits-cisco-zero-days-for-deep-network-es",
      "published_date": "2026-08-03"
    },
    {
      "observation_id": "OBS-00090",
      "type": "vulnerability",
      "id": "CVE-2024-20359",
      "name": "CVE-2024-20359",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "State-Sponsored ArcaneDoor Campaign Exploits Cisco Zero-Days for Deep Network Espionage",
      "source_url": "https://encrygma.com/articles/state-sponsored-arcanedoor-campaign-exploits-cisco-zero-days-for-deep-network-es",
      "published_date": "2026-08-03"
    },
    {
      "observation_id": "OBS-00091",
      "type": "vulnerability",
      "id": "CVE-2024-26169",
      "name": "CVE-2024-26169",
      "tactic": null,
      "threat_level": "critical",
      "geography": "North America",
      "actor_type": "ransomware_group",
      "source_report": "Black Basta Leverages Windows Zero-Day in Massive Critical Infrastructure Offensive",
      "source_url": "https://encrygma.com/articles/black-basta-leverages-windows-zero-day-in-massive-critical-infrastructure-offens",
      "published_date": "2026-08-02"
    },
    {
      "observation_id": "OBS-00092",
      "type": "vulnerability",
      "id": "CVE-2024-1709",
      "name": "CVE-2024-1709",
      "tactic": null,
      "threat_level": "critical",
      "geography": "North America",
      "actor_type": "ransomware_group",
      "source_report": "Black Basta Leverages Windows Zero-Day in Massive Critical Infrastructure Offensive",
      "source_url": "https://encrygma.com/articles/black-basta-leverages-windows-zero-day-in-massive-critical-infrastructure-offens",
      "published_date": "2026-08-02"
    },
    {
      "observation_id": "OBS-00093",
      "type": "vulnerability",
      "id": "CVE-2021-44228",
      "name": "CVE-2021-44228",
      "tactic": null,
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "APT45 Escalation: North Korean State Actors Target Global Defense and Nuclear Intellectual Property",
      "source_url": "https://encrygma.com/articles/apt45-escalation-north-korean-state-actors-target-global-defense-and-nuclear-int",
      "published_date": "2026-08-02"
    },
    {
      "observation_id": "OBS-00094",
      "type": "vulnerability",
      "id": "CVE-2025-3248",
      "name": "CVE-2025-3248",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "unknown",
      "source_report": "Agentic Ransomware JADEPUFFER and OpenAI Sandbox Escape Mark First Autonomous Breach of AI Supply Chain",
      "source_url": "https://encrygma.com/articles/agentic-ransomware-jadepuffer-and-openai-sandbox-escape-mark-first-autonomous-br",
      "published_date": "2026-08-02"
    },
    {
      "observation_id": "OBS-00095",
      "type": "vulnerability",
      "id": "CVE-2024-24919",
      "name": "CVE-2024-24919",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "Critical Check Point VPN Zero-Day (CVE-2024-24919) Exploited in Global Espionage Campaign",
      "source_url": "https://encrygma.com/articles/critical-check-point-vpn-zero-day-cve-2024-24919-exploited-in-global-espionage-c",
      "published_date": "2026-07-31"
    },
    {
      "observation_id": "OBS-00096",
      "type": "vulnerability",
      "id": "CVE-2026-11290",
      "name": "CVE-2026-11290",
      "tactic": null,
      "threat_level": "critical",
      "geography": "North America",
      "actor_type": "nation_state",
      "source_report": "Deepfake Synchrony: Nation-State Actor Exploits Real-Time AI Synthesis in $400M Financial Clearinghouse Heist",
      "source_url": "https://encrygma.com/articles/deepfake-synchrony-nation-state-actor-exploits-real-time-ai-synthesis-in-400m-fi",
      "published_date": "2026-07-31"
    },
    {
      "observation_id": "OBS-00097",
      "type": "vulnerability",
      "id": "CVE-2024-21888",
      "name": "CVE-2024-21888",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "DOJ Indicts APT45 for Global Cyber-Espionage Campaign Targeting Defense and Energy Sectors",
      "source_url": "https://encrygma.com/articles/doj-indicts-apt45-for-global-cyber-espionage-campaign-targeting-defense-and-ener",
      "published_date": "2026-07-31"
    },
    {
      "observation_id": "OBS-00098",
      "type": "vulnerability",
      "id": "CVE-2026-16232",
      "name": "CVE-2026-16232",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "unknown",
      "source_report": "Active Exploitation of CVE-2026-16232: Critical Auth Bypass Zero-Day in Check Point SmartConsole",
      "source_url": "https://encrygma.com/articles/active-exploitation-of-cve-2026-16232-critical-auth-bypass-zero-day-in-check-poi",
      "published_date": "2026-07-30"
    },
    {
      "observation_id": "OBS-00099",
      "type": "vulnerability",
      "id": "CVE-2026-9812",
      "name": "CVE-2026-9812",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "Russian LAUNDRY BEAR Exploits Zimbra Zero-Day to Exfiltrate Diplomatic Communications",
      "source_url": "https://encrygma.com/articles/russian-laundry-bear-exploits-zimbra-zero-day-to-exfiltrate-diplomatic-communica",
      "published_date": "2026-07-30"
    },
    {
      "observation_id": "OBS-00100",
      "type": "vulnerability",
      "id": "CVE-2018-0171",
      "name": "CVE-2018-0171",
      "tactic": null,
      "threat_level": "critical",
      "geography": "North America",
      "actor_type": "nation_state",
      "source_report": "Russian FSB Center 16 Targets US Infrastructure; 30 Minnesota Water Systems Compromised in Summer Offensive",
      "source_url": "https://encrygma.com/articles/russian-fsb-center-16-targets-us-infrastructure-30-minnesota-water-systems-compr",
      "published_date": "2026-07-30"
    },
    {
      "observation_id": "OBS-00101",
      "type": "vulnerability",
      "id": "CVE-2026-54121",
      "name": "CVE-2026-54121",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "Intellexa's 'Aladdin' Ad-Tech Infection Vector Linked to New Global Spyware Campaign Targeting Human Rights Activists",
      "source_url": "https://encrygma.com/articles/intellexa-s-aladdin-ad-tech-infection-vector-linked-to-new-global-spyware-campai",
      "published_date": "2026-07-29"
    },
    {
      "observation_id": "OBS-00102",
      "type": "vulnerability",
      "id": "CVE-2024-37085",
      "name": "CVE-2024-37085",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "ransomware_group",
      "source_report": "Critical VMware ESXi Zero-Day CVE-2024-37085 Exploited by Ransomware Groups for Full Host Access",
      "source_url": "https://encrygma.com/articles/critical-vmware-esxi-zero-day-cve-2024-37085-exploited-by-ransomware-groups-for-",
      "published_date": "2026-07-29"
    },
    {
      "observation_id": "OBS-00103",
      "type": "vulnerability",
      "id": "CVE-2026-9921",
      "name": "CVE-2026-9921",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Middle East and Europe",
      "actor_type": "apt",
      "source_report": "Intellexa Alliance Resurfaces with 'Predator-X' Zero-Click Exploits Targeting iOS and Android",
      "source_url": "https://encrygma.com/articles/intellexa-alliance-resurfaces-with-predator-x-zero-click-exploits-targeting-ios-",
      "published_date": "2026-07-28"
    },
    {
      "observation_id": "OBS-00104",
      "type": "technique",
      "id": "T1041",
      "name": "T1041",
      "tactic": null,
      "threat_level": "critical",
      "geography": "United States",
      "actor_type": "nation_state",
      "source_report": "Iranian APTs Target Multivendor PLC Ecosystem; CISA Warns of Modified Safety Logic in Water and Energy Sectors",
      "source_url": "https://encrygma.com/articles/iranian-apts-target-multivendor-plc-ecosystem-cisa-warns-of-modified-safety-logi",
      "published_date": "2026-07-28"
    },
    {
      "observation_id": "OBS-00105",
      "type": "vulnerability",
      "id": "CVE-2025-43200",
      "name": "CVE-2025-43200",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Southeast Asia",
      "actor_type": "apt",
      "source_report": "Operation Hermes: Autonomous AI Agents and Hades Implant Target Thai Financial Infrastructure",
      "source_url": "https://encrygma.com/articles/operation-hermes-autonomous-ai-agents-and-hades-implant-target-thai-financial-in",
      "published_date": "2026-07-26"
    },
    {
      "observation_id": "OBS-00106",
      "type": "vulnerability",
      "id": "CVE-2024-38112",
      "name": "CVE-2024-38112",
      "tactic": null,
      "threat_level": "high",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "Windows MSHTML Zero-Day CVE-2024-38112 Exploited by Void Banshee to Spread Atlantis Stealer",
      "source_url": "https://encrygma.com/articles/windows-mshtml-zero-day-cve-2024-38112-exploited-by-void-banshee-to-spread-atlan",
      "published_date": "2026-07-26"
    },
    {
      "observation_id": "OBS-00107",
      "type": "vulnerability",
      "id": "CVE-2026-62144",
      "name": "CVE-2026-62144",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "unknown",
      "source_report": "Check Point SmartConsole Zero-Day (CVE-2026-16232) Exploited to Hijack Security Management Systems",
      "source_url": "https://encrygma.com/articles/check-point-smartconsole-zero-day-cve-2026-16232-exploited-to-hijack-security-ma",
      "published_date": "2026-07-24"
    },
    {
      "observation_id": "OBS-00108",
      "type": "vulnerability",
      "id": "CVE-2026-62145",
      "name": "CVE-2026-62145",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "unknown",
      "source_report": "Check Point SmartConsole Zero-Day (CVE-2026-16232) Exploited to Hijack Security Management Systems",
      "source_url": "https://encrygma.com/articles/check-point-smartconsole-zero-day-cve-2026-16232-exploited-to-hijack-security-ma",
      "published_date": "2026-07-24"
    },
    {
      "observation_id": "OBS-00109",
      "type": "vulnerability",
      "id": "CVE-2026-63030",
      "name": "CVE-2026-63030",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "cybercriminal",
      "source_report": "CISA Adds Critical WordPress Core Zero-Day CVE-2026-63030 to KEV Catalog Following Active Exploitation",
      "source_url": "https://encrygma.com/articles/cisa-adds-critical-wordpress-core-zero-day-cve-2026-63030-to-kev-catalog-followi",
      "published_date": "2026-07-23"
    },
    {
      "observation_id": "OBS-00110",
      "type": "vulnerability",
      "id": "CVE-2024-4577",
      "name": "CVE-2024-4577",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "cybercriminal",
      "source_report": "Critical PHP Zero-Day CVE-2024-4577 Exploited for Remote Code Execution",
      "source_url": "https://encrygma.com/articles/critical-php-zero-day-cve-2024-4577-exploited-for-remote-code-execution",
      "published_date": "2026-07-22"
    },
    {
      "observation_id": "OBS-00111",
      "type": "vulnerability",
      "id": "CVE-2012-1823",
      "name": "CVE-2012-1823",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "cybercriminal",
      "source_report": "Critical PHP Zero-Day CVE-2024-4577 Exploited for Remote Code Execution",
      "source_url": "https://encrygma.com/articles/critical-php-zero-day-cve-2024-4577-exploited-for-remote-code-execution",
      "published_date": "2026-07-22"
    },
    {
      "observation_id": "OBS-00112",
      "type": "vulnerability",
      "id": "CVE-2024-5274",
      "name": "CVE-2024-5274",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "Google Patches Fourth Chrome Zero-Day in Two Weeks Amid Active Exploitation (CVE-2024-5274)",
      "source_url": "https://encrygma.com/articles/google-patches-fourth-chrome-zero-day-in-two-weeks-amid-active-exploitation-cve-",
      "published_date": "2026-07-21"
    },
    {
      "observation_id": "OBS-00113",
      "type": "vulnerability",
      "id": "CVE-2024-4947",
      "name": "CVE-2024-4947",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "Google Patches Fourth Chrome Zero-Day in Two Weeks Amid Active Exploitation (CVE-2024-5274)",
      "source_url": "https://encrygma.com/articles/google-patches-fourth-chrome-zero-day-in-two-weeks-amid-active-exploitation-cve-",
      "published_date": "2026-07-21"
    },
    {
      "observation_id": "OBS-00114",
      "type": "vulnerability",
      "id": "CVE-2024-4671",
      "name": "CVE-2024-4671",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "Google Patches Fourth Chrome Zero-Day in Two Weeks Amid Active Exploitation (CVE-2024-5274)",
      "source_url": "https://encrygma.com/articles/google-patches-fourth-chrome-zero-day-in-two-weeks-amid-active-exploitation-cve-",
      "published_date": "2026-07-21"
    },
    {
      "observation_id": "OBS-00115",
      "type": "vulnerability",
      "id": "CVE-2024-4761",
      "name": "CVE-2024-4761",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "apt",
      "source_report": "Google Patches Fourth Chrome Zero-Day in Two Weeks Amid Active Exploitation (CVE-2024-5274)",
      "source_url": "https://encrygma.com/articles/google-patches-fourth-chrome-zero-day-in-two-weeks-amid-active-exploitation-cve-",
      "published_date": "2026-07-21"
    },
    {
      "observation_id": "OBS-00116",
      "type": "vulnerability",
      "id": "CVE-2026-56164",
      "name": "CVE-2026-56164",
      "tactic": null,
      "threat_level": "critical",
      "geography": "United States",
      "actor_type": "ransomware_group",
      "source_report": "Ransomware Attack Paralyzes Coca-Cola Subsidiary Fairlife, Halting U.S. Dairy Production",
      "source_url": "https://encrygma.com/articles/ransomware-attack-paralyzes-coca-cola-subsidiary-fairlife-halting-u-s-dairy-prod",
      "published_date": "2026-07-20"
    },
    {
      "observation_id": "OBS-00117",
      "type": "vulnerability",
      "id": "CVE-2026-56155",
      "name": "CVE-2026-56155",
      "tactic": null,
      "threat_level": "critical",
      "geography": "United States",
      "actor_type": "ransomware_group",
      "source_report": "Ransomware Attack Paralyzes Coca-Cola Subsidiary Fairlife, Halting U.S. Dairy Production",
      "source_url": "https://encrygma.com/articles/ransomware-attack-paralyzes-coca-cola-subsidiary-fairlife-halting-u-s-dairy-prod",
      "published_date": "2026-07-20"
    },
    {
      "observation_id": "OBS-00118",
      "type": "vulnerability",
      "id": "CVE-2026-39808",
      "name": "CVE-2026-39808",
      "tactic": null,
      "threat_level": "critical",
      "geography": "global",
      "actor_type": "nation_state",
      "source_report": "Critical Fortinet FortiSandbox Zero-Day (CVE-2026-39808) Under Active Exploitation by Nation-State Actors",
      "source_url": "https://encrygma.com/articles/critical-fortinet-fortisandbox-zero-day-cve-2026-39808-under-active-exploitation",
      "published_date": "2026-07-20"
    },
    {
      "observation_id": "OBS-00119",
      "type": "vulnerability",
      "id": "CVE-2024-3400",
      "name": "CVE-2024-3400",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "Chinese 'Salt Typhoon' Group Compromises Global Telecom Hubs in Massive Intelligence Harvesting Operation",
      "source_url": "https://encrygma.com/articles/chinese-salt-typhoon-group-compromises-global-telecom-hubs-in-massive-intelligen",
      "published_date": "2026-07-20"
    },
    {
      "observation_id": "OBS-00120",
      "type": "vulnerability",
      "id": "CVE-2026-1182",
      "name": "CVE-2026-1182",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "ShadowPulse: APT44 Targets Global Energy Sector via Zero-Day in Edge Gateway Firmware",
      "source_url": "https://encrygma.com/articles/shadowpulse-apt44-targets-global-energy-sector-via-zero-day-in-edge-gateway-firm",
      "published_date": "2026-07-19"
    },
    {
      "observation_id": "OBS-00121",
      "type": "vulnerability",
      "id": "CVE-2026-4412",
      "name": "CVE-2026-4412",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Europe",
      "actor_type": "apt",
      "source_report": "Hydra Spyware Targets Exploit Developers via Zero-Click Flaw Linked to Mediterranean Broker Auction",
      "source_url": "https://encrygma.com/articles/hydra-spyware-targets-exploit-developers-via-zero-click-flaw-linked-to-mediterra",
      "published_date": "2026-07-19"
    },
    {
      "observation_id": "OBS-00122",
      "type": "vulnerability",
      "id": "CVE-2008-4128",
      "name": "CVE-2008-4128",
      "tactic": null,
      "threat_level": "critical",
      "geography": "Global",
      "actor_type": "nation_state",
      "source_report": "Global Intelligence Coalition Exposes FSB Center 16's Critical Infrastructure Exploitation via SNMP",
      "source_url": "https://encrygma.com/articles/global-intelligence-coalition-exposes-fsb-center-16-s-critical-infrastructure-ex",
      "published_date": "2026-07-19"
    }
  ]
}