Threat Intelligence

Active threats.
Right now.

Real-time data on global cyber threats. Instantly assess your CTI posture based on your sector, region and organization size.

Global monitoring

Cyber threats · continuous watch

Actively exploited vulnerabilities (CISA KEV), critical CVEs (NVD), ANSSI CERT-FR alerts and AlienVault OTX pulses, synced every 6 hours. Click a map point to cross-reference these feeds with a zone.

09:59 AMLast synced: just now
Actively exploited CVEs · 7d4Source: CISA KEV
Critical CVEs · 30d8CVSS ≥ 7 · Source: NVD
Sectors under pressure4Out of 5 tracked zones
OTX pulses · 7d0Source: AlienVault OTX
Cyber geopolitics

Geopolitics & Active Groups

Mapping of major threat actors by geography, updated quarterly.

  • Russia / UkraineCRITICAL
    Targets:EnergyDefenseFinanceCritical InfrastructureGovernment

    Active hybrid warfare. Coordinated cyber operations alongside kinetic actions on European territory. Sandworm has demonstrated its ability to cut power to the grid.

    RecentPhishing campaigns targeting European institutions, Q1 2026
  • ChinaHIGH
    Targets:TelecomTechnologyR&DGovernmentHealthcare

    Industrial espionage and strategic pre-positioning in Western critical infrastructure. Volt Typhoon compromises networks to stay dormant.

    RecentSalt Typhoon: compromise of 9 US telecom carriers, CISA investigation opened
  • North KoreaHIGH
    Targets:FinanceCryptoDefenseAerospaceHealthcare

    Regime funding through crypto theft (>$3B in 2024) and targeted military espionage. BlueNoroff specializes in financial institutions.

    RecentBybit hack: $1.5B in crypto stolen February 2025, attributed to Lazarus
  • IranMEDIUM
    Targets:GovernmentTelecomEnergyDefense

    Targeting of dissidents and Western interests. Disinformation and cyber sabotage. Agrius practices destructive wiper attacks.

    RecentSpear-phishing campaigns against Franco-European targets, Q4 2025
  • PakistanMEDIUM
    Targets:DefenseGovernmentDiplomacy

    Regional espionage centered on the India–Pakistan conflict: targeting of Indian armed forces, diplomacy and government bodies.

    RecentCrimson RAT campaigns against the Indian defense sector (2024-2025)
  • IndiaMEDIUM
    Targets:GovernmentMaritimeDefense

    Regional espionage targeting South Asian governments and the maritime sector, notably Pakistan and China.

    RecentSpear-phishing against South Asian government entities (SideWinder)
  • VietnamMEDIUM
    Targets:DissidentsMediaPrivate sectorRegional governments

    Espionage aligned with state interests: surveillance of opponents, journalists and foreign companies operating in the region.

    RecentOceanLotus espionage campaigns against Southeast Asian targets
  • Organized cybercrimeHIGH
    RansomHubAkiraPlayCl0p
    Targets:All sectorsSMEs priorityHealthcareEducation

    Industrialized Ransomware-as-a-Service. Systematic double extortion. Organizations without formal governance are preferred targets. Slower remediation.

    RecentRansomHub: successor to BlackCat, 300+ victims in 2025
  • Pro-Russian hacktivismMEDIUM
    NoName057(16)Killnet
    Targets:Institutional sitesTransportPublic sectorFinance

    Hacktivist collectives aligned with geopolitical agendas. DDoS and defacements against European targets: high media impact, but often limited technical effect.

    RecentWaves of DDoS against European infrastructure (2024-2025)

Assess Your CTI Posture

Sector · Region · Size · Frameworks → risk score + active APT groups + recommendations

Threat Intelligence Posture

Choisissez le format de votre diagnostic

Deux niveaux d'approfondissement, même rigueur méthodologique (NIST CSF 2.0, MITRE ATT&CK, ENISA Threat Landscape 2024). Vous pouvez basculer au format complet à tout moment.

Understanding CTI

Cyber threat intelligence, explained

The essentials to read and act on this page, jargon-free. Updated July 01, 2026 · Sources: CISA KEV · NVD (NIST) · ANSSI CERT-FR · AlienVault OTX · MITRE ATT&CK · ENISA Threat Landscape · Verizon DBIR · IBM Cost of a Data Breach · Mandiant M-Trends.

Frequently asked questions

What is Cyber Threat Intelligence (CTI)?
CTI is the practice of collecting, correlating and analyzing information about threat actors, their techniques and their targets, so you can anticipate attacks rather than absorb them. In practice it answers three questions: who can attack me, how, and what should I prioritize to defend against it.
Which APT groups target European organizations?
The main advanced persistent threats (APTs) targeting Europe are Russian (Sandworm/GRU, APT28, Turla/FSB), Chinese (APT41, Volt Typhoon, Salt Typhoon), North Korean (Lazarus, BlueNoroff, focused on financial and crypto theft) and Iranian (APT35, MuddyWater, Agrius). On top of these, organized cybercrime (ransomware-as-a-service: RansomHub, Cl0p, BlackBasta) hits every sector and preferentially targets under-governed SMEs and mid-caps.
What is the CISA KEV catalog?
KEV (Known Exploited Vulnerabilities) is the catalog, maintained by the US agency CISA, of vulnerabilities proven to be actively exploited by attackers. A CVE listed in KEV is no longer theoretical: it is used in the wild and must be patched as an absolute priority. It is one of the most actionable CTI sources available.
What is the difference between a CVE and an actively exploited vulnerability?
A CVE (Common Vulnerabilities and Exposures) is a standardized identifier assigned to a known security flaw — tens of thousands are published each year. An actively exploited vulnerability is a much smaller subset: a CVE for which real-world attacks are observed. That subset (CISA KEV) is where remediation should focus first.
What is MITRE ATT&CK?
MITRE ATT&CK is a knowledge base that catalogs the tactics (the "why": initial access, persistence, exfiltration…) and techniques (the "how") actually used by attackers, as identifiers such as T1566 (phishing). Mapping your defenses onto ATT&CK shows precisely which attack techniques you cover and which you leave open.
How do I know if my sector is a priority target?
Every sector has its own threat profile: finance attracts financially-motivated and North Korean groups, healthcare and industry are top ransomware targets, energy faces state-sponsored pre-positioning on its industrial systems (OT/ICS). The posture assessment above computes your exposure by sector, size and maturity, with a quantified sector benchmark.
How do you turn intelligence into action?
Intelligence only has value once it becomes a decision. The approach: (1) patch actively exploited vulnerabilities on your perimeter first, (2) map your defenses against the MITRE ATT&CK techniques of the actors targeting your sector, (3) formalize governance (detection, continuity plan, supplier oversight). The posture assessment returns these priorities, ranked by risk/effort return.

Glossary

APT
Advanced Persistent Threat — a sophisticated, durable attacker group, often state-sponsored, able to stay covertly inside a network for months.
TTP
Tactics, Techniques and Procedures — how an attacker operates, their operational signature (see MITRE ATT&CK).
IOC
Indicator of Compromise — a technical trace of an attack (IP address, file hash, domain) used to detect it.
CVE
Common Vulnerabilities and Exposures — a standardized identifier for a known security flaw.
KEV
Known Exploited Vulnerabilities — CISA's catalog of CVEs proven to be actively exploited; patch first.
CVSS
Common Vulnerability Scoring System — a vulnerability severity score from 0 to 10; ≥ 9 = critical.
RaaS
Ransomware-as-a-Service — a criminal model where an operator rents its ransomware to affiliates, industrializing attacks.
Double extortion
A technique where the attacker encrypts data AND threatens to leak it, to maximize pressure on the victim.
Wiper
Destructive malware designed not to ransom but to irreversibly destroy data and systems.
C2
Command and Control — the infrastructure from which an attacker controls compromised machines.
Pre-positioning
A dormant access planted in advance by a state actor on critical infrastructure, to be activated during a geopolitical crisis.
OT / ICS
Operational Technology / Industrial Control Systems — systems driving physical processes (energy, factories); high-impact targets.

Take action

Presidio structures your CTI response.

Where this report identifies, Presidio organizes the response. NIS2/DORA/ISO/GDPR pre-mapped, assignable action plans, immutable audit trail, automated board reports.