CyberSafe LogoCyberSafe

CyberSafe Threat Research

Intelligence that informs action.

Our research function tracks the techniques being used against organisations like yours and turns them into guidance our consultants apply in the field the same week.

Research desk with printed briefings
Featured advisory

Four vulnerabilities now confirmed exploited — patch SharePoint and vCenter first

On 18 August 2026 CISA added four CVEs to its Known Exploited Vulnerabilities catalog: Microsoft IKE (CVE-2026-33824), SharePoint weak authentication (CVE-2026-55040), VMware vCenter path traversal (CVE-2026-59310), and Apple macOS improper authentication (CVE-2026-65400). Internet-facing SharePoint and vCenter are the highest-consequence pair for most organisations. Hunt for compromise before you patch, then close the exposure window the same week.

ID · CS-ADV-0001Published · 18 Aug 2026Severity · High
Printed research reports

2026 Threat Landscape Brief

Field reading of ENISA Threat Landscape 2025: 4,875 incidents (Jul 2024–Jun 2025). Ransomware remains the most damaging threat; phishing is still ~60% of initial access, with vulnerability exploitation at 21.3%.

Read the ENISA report

Threat alert feed

  • CS-ADV-0001AdvisoryCISA KEV: SharePoint, vCenter, macOS, and IKE listed as exploited in the wildHigh
  • CS-ALT-0002Vulnerability alertCVE-2026-55040 — Microsoft SharePoint weak authentication under active exploitationCritical
  • CS-ADV-0003AdvisoryTreat CISA KEV items on internet-facing assets as this week's patch queueMedium
  • CS-RES-0004Research noteENISA ETL 2025: phishing remains ~60% of initial access; PhaaS industrializes campaignsInformational
  • CS-ALT-0005Vulnerability alertCVE-2026-59310 — Broadcom VMware vCenter path traversal added to the KEV catalogHigh
Get advisories by email

Threat landscape

Intelligence only matters if the surface is current.

Advisories and vulnerability alerts are useless without a model of what you actually run. CyberSafe Threat Research feeds this continuous scan picture so findings become scoped work — not unread PDFs.

  • Internet-facing services, identity paths, and cloud defaults mapped as one surface
  • Automated probing tropes — phishing, credential stuffing, unpatched CVEs — ranked by impact
  • A continuous scan model so new exposure is seen before it becomes an incident
Scanning · Cloud
Live threat surface · continuous scan model