Threat Intelligence
Active threats.
Right now.
Real-time data on global cyber threats. Instantly assess your CTI posture based on your sector, region and organization size.
Cyber threats · continuous watch
Actively exploited vulnerabilities (CISA KEV), critical CVEs (NVD), ANSSI CERT-FR alerts and AlienVault OTX pulses, synced every 6 hours. Click a map point to cross-reference these feeds with a zone.
Intelligence feed
CISA KEV · NVD · ANSSI · OTX- ANSSIVulnérabilité dans LibreNMS (12 mai 2026)Tue, 12 May 2026
- ANSSIVulnérabilité dans LibreNMS (11 juin 2026)Thu, 11 Jun 2026
- ANSSIMultiples vulnérabilités dans les produits Cisco (06 août 2026)Thu, 06 Aug 2026
- ANSSIMultiples vulnérabilités dans les produits Wallix (06 août 2026)Thu, 06 Aug 2026
- ANSSIMultiples vulnérabilités dans KeyCloak (06 août 2026)Thu, 06 Aug 2026
- ANSSIMultiples vulnérabilités dans les produits IBM (07 août 2026)Fri, 07 Aug 2026
- ANSSIMultiples vulnérabilités dans Progress Telerik (07 août 2026)Fri, 07 Aug 2026
- ANSSIMultiples vulnérabilités dans le noyau Linux de Debian (07 août 2026)Fri, 07 Aug 2026
Geopolitics & Active Groups
Mapping of major threat actors by geography, updated quarterly.
- Russia / UkraineCRITICALTargets:EnergyDefenseFinanceCritical InfrastructureGovernment
Active hybrid warfare. Coordinated cyber operations alongside kinetic actions on European territory. Sandworm has demonstrated its ability to cut power to the grid.
RecentPhishing campaigns targeting European institutions, Q1 2026 - ChinaHIGHTargets:TelecomTechnologyR&DGovernmentHealthcare
Industrial espionage and strategic pre-positioning in Western critical infrastructure. Volt Typhoon compromises networks to stay dormant.
RecentSalt Typhoon: compromise of 9 US telecom carriers, CISA investigation opened - North KoreaHIGHTargets:FinanceCryptoDefenseAerospaceHealthcare
Regime funding through crypto theft (>$3B in 2024) and targeted military espionage. BlueNoroff specializes in financial institutions.
RecentBybit hack: $1.5B in crypto stolen February 2025, attributed to Lazarus - IranMEDIUMTargets:GovernmentTelecomEnergyDefense
Targeting of dissidents and Western interests. Disinformation and cyber sabotage. Agrius practices destructive wiper attacks.
RecentSpear-phishing campaigns against Franco-European targets, Q4 2025 - PakistanMEDIUMTargets:DefenseGovernmentDiplomacy
Regional espionage centered on the India–Pakistan conflict: targeting of Indian armed forces, diplomacy and government bodies.
RecentCrimson RAT campaigns against the Indian defense sector (2024-2025) - IndiaMEDIUMTargets:GovernmentMaritimeDefense
Regional espionage targeting South Asian governments and the maritime sector, notably Pakistan and China.
RecentSpear-phishing against South Asian government entities (SideWinder) - VietnamMEDIUMTargets:DissidentsMediaPrivate sectorRegional governments
Espionage aligned with state interests: surveillance of opponents, journalists and foreign companies operating in the region.
RecentOceanLotus espionage campaigns against Southeast Asian targets - Organized cybercrimeHIGHTargets:All sectorsSMEs priorityHealthcareEducation
Industrialized Ransomware-as-a-Service. Systematic double extortion. Organizations without formal governance are preferred targets. Slower remediation.
RecentRansomHub: successor to BlackCat, 300+ victims in 2025 - Pro-Russian hacktivismMEDIUMNoName057(16)KillnetTargets:Institutional sitesTransportPublic sectorFinance
Hacktivist collectives aligned with geopolitical agendas. DDoS and defacements against European targets: high media impact, but often limited technical effect.
RecentWaves of DDoS against European infrastructure (2024-2025)
Assess Your CTI Posture
Sector · Region · Size · Frameworks → risk score + active APT groups + recommendations
Threat Intelligence Posture
Choisissez le format de votre diagnostic
Deux niveaux d'approfondissement, même rigueur méthodologique (NIST CSF 2.0, MITRE ATT&CK, ENISA Threat Landscape 2024). Vous pouvez basculer au format complet à tout moment.
Aucune information personnelle n'est requise jusqu'à l'envoi du rapport. Vous restez maître de la donnée.
Cyber threat intelligence, explained
The essentials to read and act on this page, jargon-free. Updated July 01, 2026 · Sources: CISA KEV · NVD (NIST) · ANSSI CERT-FR · AlienVault OTX · MITRE ATT&CK · ENISA Threat Landscape · Verizon DBIR · IBM Cost of a Data Breach · Mandiant M-Trends.
Frequently asked questions
- What is Cyber Threat Intelligence (CTI)?
- CTI is the practice of collecting, correlating and analyzing information about threat actors, their techniques and their targets, so you can anticipate attacks rather than absorb them. In practice it answers three questions: who can attack me, how, and what should I prioritize to defend against it.
- Which APT groups target European organizations?
- The main advanced persistent threats (APTs) targeting Europe are Russian (Sandworm/GRU, APT28, Turla/FSB), Chinese (APT41, Volt Typhoon, Salt Typhoon), North Korean (Lazarus, BlueNoroff, focused on financial and crypto theft) and Iranian (APT35, MuddyWater, Agrius). On top of these, organized cybercrime (ransomware-as-a-service: RansomHub, Cl0p, BlackBasta) hits every sector and preferentially targets under-governed SMEs and mid-caps.
- What is the CISA KEV catalog?
- KEV (Known Exploited Vulnerabilities) is the catalog, maintained by the US agency CISA, of vulnerabilities proven to be actively exploited by attackers. A CVE listed in KEV is no longer theoretical: it is used in the wild and must be patched as an absolute priority. It is one of the most actionable CTI sources available.
- What is the difference between a CVE and an actively exploited vulnerability?
- A CVE (Common Vulnerabilities and Exposures) is a standardized identifier assigned to a known security flaw — tens of thousands are published each year. An actively exploited vulnerability is a much smaller subset: a CVE for which real-world attacks are observed. That subset (CISA KEV) is where remediation should focus first.
- What is MITRE ATT&CK?
- MITRE ATT&CK is a knowledge base that catalogs the tactics (the "why": initial access, persistence, exfiltration…) and techniques (the "how") actually used by attackers, as identifiers such as T1566 (phishing). Mapping your defenses onto ATT&CK shows precisely which attack techniques you cover and which you leave open.
- How do I know if my sector is a priority target?
- Every sector has its own threat profile: finance attracts financially-motivated and North Korean groups, healthcare and industry are top ransomware targets, energy faces state-sponsored pre-positioning on its industrial systems (OT/ICS). The posture assessment above computes your exposure by sector, size and maturity, with a quantified sector benchmark.
- How do you turn intelligence into action?
- Intelligence only has value once it becomes a decision. The approach: (1) patch actively exploited vulnerabilities on your perimeter first, (2) map your defenses against the MITRE ATT&CK techniques of the actors targeting your sector, (3) formalize governance (detection, continuity plan, supplier oversight). The posture assessment returns these priorities, ranked by risk/effort return.
Glossary
- APT
- Advanced Persistent Threat — a sophisticated, durable attacker group, often state-sponsored, able to stay covertly inside a network for months.
- TTP
- Tactics, Techniques and Procedures — how an attacker operates, their operational signature (see MITRE ATT&CK).
- IOC
- Indicator of Compromise — a technical trace of an attack (IP address, file hash, domain) used to detect it.
- CVE
- Common Vulnerabilities and Exposures — a standardized identifier for a known security flaw.
- KEV
- Known Exploited Vulnerabilities — CISA's catalog of CVEs proven to be actively exploited; patch first.
- CVSS
- Common Vulnerability Scoring System — a vulnerability severity score from 0 to 10; ≥ 9 = critical.
- RaaS
- Ransomware-as-a-Service — a criminal model where an operator rents its ransomware to affiliates, industrializing attacks.
- Double extortion
- A technique where the attacker encrypts data AND threatens to leak it, to maximize pressure on the victim.
- Wiper
- Destructive malware designed not to ransom but to irreversibly destroy data and systems.
- C2
- Command and Control — the infrastructure from which an attacker controls compromised machines.
- Pre-positioning
- A dormant access planted in advance by a state actor on critical infrastructure, to be activated during a geopolitical crisis.
- OT / ICS
- Operational Technology / Industrial Control Systems — systems driving physical processes (energy, factories); high-impact targets.
Take action
Presidio structures your CTI response.
Where this report identifies, Presidio organizes the response. NIS2/DORA/ISO/GDPR pre-mapped, assignable action plans, immutable audit trail, automated board reports.