Ransomware postings, exploited CVEs, and breach reporting, tracked from the primary sources, daily.
Threat-intel analysts and security leaders need the leak-site postings, the actively-exploited vulnerabilities, and the advisories before they surface on a tech blog: synthesized, timestamped, and cited back to the source.
Every story shows every outlet that covered it. We don't synthesize away the differences. You see them.
Each line links to the primary source. Read the original yourself.
We never label a claim true or false. We show what the sources reported.
The primary sources you already check, in one place
- Underground
Leak-site postings and victim claims from tracked ransomware groups, with first-seen timestamps.
- CISA Known Exploited Vulnerabilities
The KEV catalog: vulnerabilities confirmed exploited in the wild, with due-date context.
- NVD CVEs & CISA advisories
National Vulnerability Database CVEs and CISA advisories, synthesized alongside the reporting.
- China Watch
PRC-linked cyber, espionage, and tech-transfer activity across 13 tracked categories.
- DOJ actions & OFAC designations
Cyber indictments and sanctions against threat actors: the enforcement side of the threat picture.
- CVE-2021-23758 — Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- CVE-2015-3246 — Red Hat Libuser Race Condition Vulnerability
- CVE-2015-5287 — Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- CVE-2022-0995 — Linux Kernel Out-of-Bounds Write Vulnerability
- CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- CVE-2019-1068 — Microsoft SQL Server Remote Code Execution Vulnerability
- A Tale of Two SOCs: Insights From Two Red Team Assessments
- Defending Against an Active Threat to Siemens S7 Series PLCs
- #StopRansomware: Gunra Ransomware
- CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
- Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
What CISA is warning about
CISA is currently tracking active threats from multiple nation-state actors, with Russian state-sponsored actors conducting phishing campaigns against Zimbra Collaboration Suite users and targeting poorly secured routers, while pro-Russia hacktivists continue opportunistic attacks against U.S. and global critical infrastructure [AA26-204A, AA26-194A, AA25-343A]. Iran-affiliated actors are actively exploiting programmable logic controllers across U.S. critical infrastructure, and a separate threat is actively targeting Siemens S7 Series PLCs, signaling sustained adversarial focus on operational technology environments [AA26-097A, AA26-231A]. China-nexus actors are leveraging covert networks of compromised devices and conducting broad network compromises to support a global espionage system [AA26-113A, AA25-239A]. Ransomware remains an ongoing concern with Gunra ransomware under active warning, and recent proactive threat hunts and incident response engagements continue to surface foundational cyber hygiene gaps across critical infrastructure sectors [AA26-222A, AA25-212A, AA25-266A].
- Defending Against an Active Threat to Siemens S7 Series PLCs
- #StopRansomware: Gunra Ransomware
- Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
- Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
- Defending Against China-Nexus Covert Networks of Compromised Devices
- Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
- Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure
- CISA Shares Lessons Learned from an Incident Response Engagement
- Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System
- CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization
Each advisory links to the CISA original. The agency’s own findings, distilled. No verdicts.
How a workflow runs
Track an actor or campaign
Watchlist a ransomware group, threat actor, CVE, or your own vendors. Get alerted when a new leak-site posting, advisory, or piece of reporting lands, without refreshing five dashboards.
Prioritize what's real
See which vulnerabilities are confirmed exploited (CISA KEV) alongside the reporting, so you can separate the genuinely urgent from the noise.
Synthesize the picture
Pull a cited briefing across leak sites, advisories, enforcement, and news for an actor or sector. Every claim links to where it came from.
Cross-source, timestamped, and cited. The Nexus shows you what the sources reported and links you straight to them. No hype, no verdicts: you assess the threat.