Skip to content
The Nexus
For threat-intel & security teams

Ransomware postings, exploited CVEs, and breach reporting, tracked from the primary sources, daily.

Threat-intel analysts and security leaders need the leak-site postings, the actively-exploited vulnerabilities, and the advisories before they surface on a tech blog: synthesized, timestamped, and cited back to the source.

1,683actively-exploited vulnerabilities (CISA KEV)
5,380ransomware victim postings tracked
57,712live malware IOCs (abuse.ch ThreatFox)
138,867CVEs indexed
Live counts from the Nexus corpus. Updated continuously.
We don't collapse it to one answer

Every story shows every outlet that covered it. We don't synthesize away the differences. You see them.

Every claim is cited

Each line links to the primary source. Read the original yourself.

No verdicts

We never label a claim true or false. We show what the sources reported.

The corpus

The primary sources you already check, in one place

Recent ransomware activity
Recently exploited vulnerabilities
Recent malware IOCs (via abuse.ch ThreatFox)
Recent CISA advisories
CISA Advisory WatchSynthesis by The Nexus

What CISA is warning about

CISA is currently tracking active threats from multiple nation-state actors, with Russian state-sponsored actors conducting phishing campaigns against Zimbra Collaboration Suite users and targeting poorly secured routers, while pro-Russia hacktivists continue opportunistic attacks against U.S. and global critical infrastructure [AA26-204A, AA26-194A, AA25-343A]. Iran-affiliated actors are actively exploiting programmable logic controllers across U.S. critical infrastructure, and a separate threat is actively targeting Siemens S7 Series PLCs, signaling sustained adversarial focus on operational technology environments [AA26-097A, AA26-231A]. China-nexus actors are leveraging covert networks of compromised devices and conducting broad network compromises to support a global espionage system [AA26-113A, AA25-239A]. Ransomware remains an ongoing concern with Gunra ransomware under active warning, and recent proactive threat hunts and incident response engagements continue to surface foundational cyber hygiene gaps across critical infrastructure sectors [AA26-222A, AA25-212A, AA25-266A].

Each advisory links to the CISA original. The agency’s own findings, distilled. No verdicts.

In practice

How a workflow runs

01

Track an actor or campaign

Watchlist a ransomware group, threat actor, CVE, or your own vendors. Get alerted when a new leak-site posting, advisory, or piece of reporting lands, without refreshing five dashboards.

02

Prioritize what's real

See which vulnerabilities are confirmed exploited (CISA KEV) alongside the reporting, so you can separate the genuinely urgent from the noise.

03

Synthesize the picture

Pull a cited briefing across leak sites, advisories, enforcement, and news for an actor or sector. Every claim links to where it came from.

Cross-source, timestamped, and cited. The Nexus shows you what the sources reported and links you straight to them. No hype, no verdicts: you assess the threat.