SIGNAL FUSION
INFERREDCorrelative events inferred by fusing live threat intelligence with your tracked FedRAMP vendors, CMMC ecosystem, and exposure corpus. The correlation is the signal — each card is a cross-source match, not a raw feed item.
Correlations
12
inferred cross-source events
CVE fusion
4
actor CVEs hitting your stack
Shared infra
5
vendors hosting malicious IPs
Vendor breach
0
tracked entities disclosed
CVE FUSION · ACTOR-LINKED VULNS HITTING YOUR STACK
4 matched
CVE-2026-20245
KEV
Live threat-actor IOC references this CVE — which is correlated to 9 products you track.
▤ AppDynamics GovAPM, Cisco Cloudlock for Government, Cisco Meraki for Government, Cisco SD-WAN for Government, Cisco Umbrella for Government, Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government), Duo Federal, WebEx Contact Center Enterprise for Government (WxCCE-G), Webex for Government
IOC 45.131.66.106 · DE
CVE-2026-0257
KEV
Live threat-actor IOC attributed to Lazarus Group references this CVE — which is correlated to 2 products you track.
▤ GCS-HIGH, Palo Alto Networks Government Cloud Services
IOC 91.132.163.78 · DE
CVE-2026-10520
KEV
Live threat-actor IOC attributed to Lazarus Group references this CVE — which is correlated to 2 products you track.
▤ Ivanti Neurons for ITSM (Formerly Service Manager), Ivanti Neurons for MDM (Formerly MobileIron)
IOC 91.132.163.78 · DE
CVE-2025-14847
KEV
Live threat-actor IOC attributed to Lazarus Group references this CVE — which is correlated to 1 product you track.
▤ MongoDB Atlas for Government
IOC 91.132.163.78 · DE
SHARED INFRASTRUCTURE · YOUR VENDORS HOSTING MALICIOUS IPS
5 vendors
Known-malicious IPs whose hosting network (ASN) belongs to a FedRAMP vendor you track — a shared-responsibility awareness signal, not an accusation against the vendor.
Cloudflare
12 IPs
hosts 12 known-malicious IPs · CA
104.20.24.117104.20.44.100104.21.18.221104.26.2.16104.26.3.16172.66.0.227172.66.135.165172.66.139.132172.66.150.162172.66.169.62
Amazon
9 IPs
hosts 9 known-malicious IPs · CA, US
18.160.156.1918.160.156.2418.160.156.2818.160.156.443.96.91.1450.16.16.21176.76.21.2176.76.21.2276.76.21.98
SEC 8-K · MATERIAL CYBER DISCLOSURES
8 filings · 180d
Public companies filing SEC Form 8-K Item 1.05 (material cybersecurity incident). A filer you track is a direct early warning; the rest are supply-chain / peer signal.
Palo Alto Networks, Inc.
FedRAMP vendor
Filed a material cybersecurity incident 8-K as Alto Ingredients, Inc. (2026-08-07).
Equifax
FedRAMP vendor
Filed a material cybersecurity incident 8-K as EQUIFAX INC (2026-07-21).
Equifax
FedRAMP vendor
Filed a material cybersecurity incident 8-K as EQUIFAX INC (2026-04-21).
RECENT 8-K CYBER FILINGS
sec edgar
| FILER | STATE | FILED | FILING |
|---|---|---|---|
| Alto Ingredients, Inc. | CA | 2026-08-07 | EDGAR ▸ |
| CID Holdco, Inc. | MD | 2026-07-22 | EDGAR ▸ |
| EQUIFAX INC | GA | 2026-07-21 | EDGAR ▸ |
| IPG PHOTONICS CORP | MA | 2026-07-17 | EDGAR ▸ |
| HONEYWELL INTERNATIONAL INC | NC | 2026-04-23 | EDGAR ▸ |
| EQUIFAX INC | GA | 2026-04-21 | EDGAR ▸ |
| Bitcoin Depot Inc. | GA | 2026-04-08 | EDGAR ▸ |
| ARROW FINANCIAL CORP | NY | 2026-02-26 | EDGAR ▸ |
RANSOMWARE LEAK-SITE VICTIMS
200 recent claims
RECENT VICTIM CLAIMS
interlock
AngMar Companies
dragonforce
QPC Global
qilin
Crown Group
qilin
G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L
leakeddata
R...er
interlock
AngMar Companies
dragonforce
QPC Global
qilin
Crown Group
qilin
G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L
leakeddata
R...er
interlock
AngMar Companies
dragonforce
QPC Global
qilin
Crown Group
qilin
G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L
ransomware groups posting new victim claims (ransomlook) — supply-chain early warning
PIPELINE ESCALATIONS · INTEL-ENGINE CORRELATIONS
500 active
The intel pipeline's own fused correlations — country/source-scoped (a tier above the entity-specific matches above), DEFCON-ranked.
FUSED ESCALATIONS
DEFCON 1
CRITICAL
Nation-State Network Activity · US
Country: US
Distinct threat sources: 4 (changedetection, cfradar, sans, feodo)
Total events: 7
Multi-signal nation-state activity.
changedetectioncfradarsansfeodo
DEFCON 1
CRITICAL
Nation-State Network Activity · CN
Country: CN
Distinct threat sources: 4 (bindef, c2intel, et, urlhaus)
Total events: 11
Multi-signal nation-state activity.
bindefc2inteleturlhaus
DEFCON 2
CRITICAL
DDoS Origin + Active Threat Feed Signal · US
Cloudflare Radar top DDoS-origin country correlates with ≥5 active threat events from the same country in the last window — indicates concentrated...
changedetectioncfradarsansfeodo
DEFCON 2
CRITICAL
DDoS Origin + Active Threat Feed Signal · NL
Cloudflare Radar top DDoS-origin country correlates with ≥5 active threat events from the same country in the last window — indicates concentrated...
ipsumsans
DEFCON 2
CRITICAL
DDoS Origin + Active Threat Feed Signal · CN
Cloudflare Radar top DDoS-origin country correlates with ≥5 active threat events from the same country in the last window — indicates concentrated...
greensnowbindef
DEFCON 3
HIGH
Bulletproof Hosting Detected
1 ASN(s) flagged across 3+ blocklists:
AS14618 (3 feeds: urlscan, feodo, feodo_stored)