Cyber threat intelligence · updated every hour

Know what is being exploited, who is attacking and what to patch first

We follow every new vulnerability, the vendors' own advisories and the activity of ransomware groups, and turn them into clear, prioritised information for IT teams and management.

400,410Vulnerabilities tracked3,240New vulnerabilities in 7 days244Critical in 7 days1,730Actively exploited (CISA KEV)946Ransomware victims in 30 days78Active groups in 30 days15Victims in Spain in 30 days17News published

Latest news

All news →
New threat group

Endzone, a new extortion group with four claims since September

A previously unknown actor calling itself Endzone began listing victims on its leak site on 18 September 2026 and has posted four claims so far, including telecoms, technology and professional services firms, mostly in the United States.

What you will find

Most active ransomware groups (30 days)

All threats →
  1. The Gentlemen107
  2. Qilin73
  3. Storm66
  4. Killsec346
  5. Akira36
  6. INC Ransom35

Newly exploited this week

How we work

Public, verifiable sources

NVD, CISA KEV, FIRST EPSS, vendor security advisories, MITRE ATT&CK, MISP Galaxy, RansomLook and more than 25 research blogs, official CERTs and specialist press.

Privacy first

A GDPR agent reviews every victim before it is shown: individuals and doubtful cases are anonymised and we never link to leak sites or stolen data.

AI with a second check

Texts are written by AI using only the data provided, and an independent reviewer checks every threat story before it is published.