Since yesterday stale
CTI status
Joel Traber AG
Last update: · no new data today
Last pipeline run:
Last 7 days stale
Last 7 days
Top threats
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
CVE-2023-45858
Beyond the plain patch information, the alert provides no evidence of active exploitation; the flaw allows reading local files and is fixed in version 23.4.88.1429.
'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
The GRU actor Sandworm is chaining Cisco vulnerabilities to spread an upgraded Cyclops Blink variant and maintain persistent control over compromised network devices.
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
The use of a signed kernel driver as a rootkit shows the group is deliberately bypassing EDR detection on Windows endpoints and servers, not merely exfiltrating data.
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
For the first time, an APT actor is documented systematically using agentic AI tooling (playbooks, exploit automation, payload generation) across the entire post-compromise lifecycle, significantly increasing the speed and scalability of intrusions.
CVE-2023-28148
The report provides no information beyond the patch details about active exploitation or new attack vectors.