SIGNAL FUSION
INFERREDCorrelative events inferred by fusing live threat intelligence with your tracked FedRAMP vendors, CMMC ecosystem, and exposure corpus. The correlation is the signal — each card is a cross-source match, not a raw feed item.
Correlations
12
inferred cross-source events
CVE fusion
4
actor CVEs hitting your stack
Shared infra
5
vendors hosting malicious IPs
Vendor breach
0
tracked entities disclosed
CVE FUSION · ACTOR-LINKED VULNS HITTING YOUR STACK
4 matched
CVE-2026-20245
KEV
Live threat-actor IOC references this CVE — which is correlated to 9 products you track.
▤ AppDynamics GovAPM, Cisco Cloudlock for Government, Cisco Meraki for Government, Cisco SD-WAN for Government, Cisco Umbrella for Government, Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government), Duo Federal, WebEx Contact Center Enterprise for Government (WxCCE-G), Webex for Government
IOC 45.131.66.106 · DE
CVE-2026-0257
KEV
Live threat-actor IOC attributed to Lazarus Group references this CVE — which is correlated to 2 products you track.
▤ GCS-HIGH, Palo Alto Networks Government Cloud Services
IOC 91.132.163.78 · DE
CVE-2026-10520
KEV
Live threat-actor IOC attributed to Lazarus Group references this CVE — which is correlated to 2 products you track.
▤ Ivanti Neurons for ITSM (Formerly Service Manager), Ivanti Neurons for MDM (Formerly MobileIron)
IOC 91.132.163.78 · DE
CVE-2025-14847
KEV
Live threat-actor IOC attributed to Lazarus Group references this CVE — which is correlated to 1 product you track.
▤ MongoDB Atlas for Government
IOC 91.132.163.78 · DE
SHARED INFRASTRUCTURE · YOUR VENDORS HOSTING MALICIOUS IPS
5 vendors
Known-malicious IPs whose hosting network (ASN) belongs to a FedRAMP vendor you track — a shared-responsibility awareness signal, not an accusation against the vendor.
Cloudflare
12 IPs
hosts 12 known-malicious IPs · CA
104.20.24.117104.20.44.100104.21.18.221104.26.2.16104.26.3.16172.66.0.227172.66.135.165172.66.139.132172.66.150.162172.66.169.62
Amazon
9 IPs
hosts 9 known-malicious IPs · CA, US
18.160.156.1918.160.156.2418.160.156.2818.160.156.443.96.91.1450.16.16.21176.76.21.2176.76.21.2276.76.21.98
SEC 8-K · MATERIAL CYBER DISCLOSURES
8 filings · 180d
Public companies filing SEC Form 8-K Item 1.05 (material cybersecurity incident). A filer you track is a direct early warning; the rest are supply-chain / peer signal.
Palo Alto Networks, Inc.
FedRAMP vendor
Filed a material cybersecurity incident 8-K as Alto Ingredients, Inc. (2026-08-07).
Equifax
FedRAMP vendor
Filed a material cybersecurity incident 8-K as EQUIFAX INC (2026-07-21).
Equifax
FedRAMP vendor
Filed a material cybersecurity incident 8-K as EQUIFAX INC (2026-04-21).
RECENT 8-K CYBER FILINGS
sec edgar
| FILER | STATE | FILED | FILING |
|---|---|---|---|
| Alto Ingredients, Inc. | CA | 2026-08-07 | EDGAR ▸ |
| CID Holdco, Inc. | MD | 2026-07-22 | EDGAR ▸ |
| EQUIFAX INC | GA | 2026-07-21 | EDGAR ▸ |
| IPG PHOTONICS CORP | MA | 2026-07-17 | EDGAR ▸ |
| HONEYWELL INTERNATIONAL INC | NC | 2026-04-23 | EDGAR ▸ |
| EQUIFAX INC | GA | 2026-04-21 | EDGAR ▸ |
| Bitcoin Depot Inc. | GA | 2026-04-08 | EDGAR ▸ |
| ARROW FINANCIAL CORP | NY | 2026-02-26 | EDGAR ▸ |
RANSOMWARE LEAK-SITE VICTIMS
200 recent claims
RECENT VICTIM CLAIMS
qilin
Studio BOLDRIN PAOLO
lockbit5
adt.com
qilin
S.E.M.P. s.r.l.
genesis
Hospitality Health ER (Longview)
shinyhunters
CyrusOne, LLC.
qilin
Studio BOLDRIN PAOLO
lockbit5
adt.com
qilin
S.E.M.P. s.r.l.
genesis
Hospitality Health ER (Longview)
shinyhunters
CyrusOne, LLC.
qilin
Tecnici Associati STP
qilin
Euroflora srl
qilin
Studio BOLDRIN PAOLO
lockbit5
adt.com
ransomware groups posting new victim claims (ransomlook) — supply-chain early warning
PIPELINE ESCALATIONS · INTEL-ENGINE CORRELATIONS
500 active
The intel pipeline's own fused correlations — country/source-scoped (a tier above the entity-specific matches above), DEFCON-ranked.
FUSED ESCALATIONS
DEFCON 1
CRITICAL
Nation-State Network Activity · US
Country: US
Distinct threat sources: 4 (cfradar, changedetection, sans, feodo)
Total events: 14
Multi-signal nation-state activity.
cfradarchangedetectionsansfeodo
DEFCON 1
CRITICAL
Nation-State Network Activity · CN
Country: CN
Distinct threat sources: 4 (bindef, c2intel, et, urlhaus)
Total events: 10
Multi-signal nation-state activity.
bindefc2inteleturlhaus
DEFCON 2
CRITICAL
DDoS Origin + Active Threat Feed Signal · US
Cloudflare Radar top DDoS-origin country correlates with ≥5 active threat events from the same country in the last window — indicates concentrated...
sansfeodochangedetectioncfradar
DEFCON 2
CRITICAL
DDoS Origin + Active Threat Feed Signal · CN
Cloudflare Radar top DDoS-origin country correlates with ≥5 active threat events from the same country in the last window — indicates concentrated...
c2intelet
DEFCON 3
HIGH
Bulletproof Hosting Detected
1 ASN(s) flagged across 3+ blocklists:
AS14618 (3 feeds: openphish, feodo, feodo_stored)