Skip to content
COOEY

◄ COMMAND CENTER

SITREP · SITUATIONAL AWARENESS

LIVE

Real-time posture across the intelligence corpus — correlation fires, threat throughput, and active narratives. Windows are 7-day / 30-day, honest to our collector cadence.

Global posture ▸
DEFCON 1
SEVERE · 24 SEVERE (DEFCON-1) escalations active
Correlations / 7D
222
▲ 19% vs prior 7d
Active threats / 7D
231
▲ 38% vs prior 7d
KEV · CVE · advisories
FedRAMP monitored
424
authorized products under CVE watch
SYSTEM VITALS 13 SOURCES LIVE · freshest 5h ago 2,722 ENTITIES 3,926 EVENTS 29,290,488 DEFCON EVENTS LIVE
GLOBAL THREAT MAP // LIVE intel · geo →
85.137.53.71 · NL76.76.21.21 · US104.20.24.117 · CA172.66.150.162 · CA209.182.237.133 · JP185.10.68.127 · RO209.94.90.1 · US · Scattered Spider172.66.0.227 · CA · Play, Scattered Spider45.131.66.106 · DE64.20.53.230 · US185.70.42.45 · CH91.132.163.78 · DE · Lazarus Group142.251.186.191 · US18.160.156.19 · US18.160.156.24 · US18.160.156.28 · US18.160.156.44 · US176.65.139.204 · NL3.96.91.14 · CA83.142.209.214 · DE · Rocke34.117.59.81 · US · Rocke178.236.252.133 · NL · Earth Lusca77.91.123.187 · GE · Earth Lusca96.126.130.126 · JP · Sandworm Team188.208.141.177 · IN · Mustang Panda, RedEcho194.5.97.169 · NL · Mustang Panda, RedEcho104.20.44.100 · CA · Sandworm Team172.66.169.62 · CA · Sandworm Team137.220.156.33 · JP104.26.3.16 · CA · Turla104.26.2.16 · CA · Turla172.67.75.40 · CA · Turla174.138.125.138 · US · Turla172.67.183.105 · CA · Earth Lusca104.21.18.221 · CA · Earth Lusca76.76.21.98 · US · Earth Lusca, Contagious Interview76.76.21.22 · US · Earth Lusca, Contagious Interview140.82.113.3 · US · Earth Lusca, Contagious Interview172.66.135.165 · CA172.66.139.132 · CA
malicious IOC origin 40 geolocated indicators · node graph ▸
THREAT ACTIVITY // 30-DAY exposures →
Correlation throughput 7D 30D GEO · LIVE ▸
07-25 correlation fireshigh-sev events 08-23
Active narratives · story clusters
×2
CVE-2026-48939: A vulnerability in the iCagenda extension for Joomla allows the upload of arbitr
CVE-2026-48939
CRITICAL
×2
CVE-2012-1710: Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in
CVE-2012-1710
CRITICAL
×2
CVE-2021-21972: The vSphere Client (HTML5) contains a remote code execution vulnerability in a v
CVE-2021-21972
CRITICAL
×2
CVE-2021-20021: A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attac
CVE-2021-20021
CRITICAL
×2
CVE-2019-15107: An issue was discovered in Webmin <=1.920. The parameter old in password_change.
CVE-2019-15107
CRITICAL
×2
CVE-2024-55591: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2
CVE-2024-55591
CRITICAL
THREAT_TICKER
CVE-2026-7808 CVE-2026-7808: justhtml before 1.16.0 contains multiple HTML... CVE-2026-8445 CVE-2026-8445: justhtml versions <= 1.11.0 (fixed in 1.12.0)... CVE-2026-5388 CVE-2026-5388: justhtml before 1.15.0 contains multiple... CVE-2026-78050 CVE-2026-78050: A vulnerability was found in Comfast CF-N1-S... CVE-2026-4703 CVE-2026-4703: The WS Form LITE – Drag & Drop Contact Form... CVE-2026-77946 CVE-2026-77946: A vulnerability was determined in TRENDnet... CVE-2026-78003 CVE-2026-78003: The Mailgun for WordPress plugin for... CVE-2026-77776 CVE-2026-77776: Headroom's LLM proxy derives the memory... CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability CVE-2026-69836 Microsoft Entra ID Deserialization of Untrusted Data Vulnerability CVE-2026-77683 CVE-2026-77683: A security flaw has been discovered in... CVE-2026-77086 CVE-2026-77086: SiYuan before v3.7.4 fails to validate the... CVE-2026-20677 CVE-2026-20677: A race condition was addressed with improved... CVE-2023-49060 CVE-2023-49060: An attacker could have accessed internal... CVE-2023-3617 CVE-2023-3617: A vulnerability was found in SourceCodester... CVE-2025-5331 CVE-2025-5331: A vulnerability has been found in PCMan FTP... CVE-2026-7808 CVE-2026-7808: justhtml before 1.16.0 contains multiple HTML... CVE-2026-8445 CVE-2026-8445: justhtml versions <= 1.11.0 (fixed in 1.12.0)... CVE-2026-5388 CVE-2026-5388: justhtml before 1.15.0 contains multiple... CVE-2026-78050 CVE-2026-78050: A vulnerability was found in Comfast CF-N1-S... CVE-2026-4703 CVE-2026-4703: The WS Form LITE – Drag & Drop Contact Form... CVE-2026-77946 CVE-2026-77946: A vulnerability was determined in TRENDnet... CVE-2026-78003 CVE-2026-78003: The Mailgun for WordPress plugin for... CVE-2026-77776 CVE-2026-77776: Headroom's LLM proxy derives the memory... CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability CVE-2026-69836 Microsoft Entra ID Deserialization of Untrusted Data Vulnerability CVE-2026-77683 CVE-2026-77683: A security flaw has been discovered in... CVE-2026-77086 CVE-2026-77086: SiYuan before v3.7.4 fails to validate the... CVE-2026-20677 CVE-2026-20677: A race condition was addressed with improved... CVE-2023-49060 CVE-2023-49060: An attacker could have accessed internal... CVE-2023-3617 CVE-2023-3617: A vulnerability was found in SourceCodester... CVE-2025-5331 CVE-2025-5331: A vulnerability has been found in PCMan FTP...
CORRELATION_FIRES incident vault →
#FIRE-F5D2 08-21 18:20Z
Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
◈ Office 365 Multi-Tenant & Supporting Services, Azure Government (includes Dynamics 365) +2 more
KEVHIGHRCE
#FIRE-316F 08-21 00:20Z
CVE-2026-18249: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain
◈ MaaS360 Enterprise Mobility Management, SmartCloud for Government +3 more
CVEHIGH
#FIRE-C67B 08-21 00:20Z
CVE-2026-61241: Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middlewa
◈ Taleo Cloud - U.S. Government Cloud, Oracle Service Cloud +8 more
CVECRITICAL
#FIRE-5B21 08-21 00:20Z
CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability
◈ Office 365 Multi-Tenant & Supporting Services, Azure Government (includes Dynamics 365) +2 more
CVECRITICAL
#FIRE-2541 08-21 00:20Z
CVE-2026-76311: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unaut
◈ Splunk Cloud Platform for FedRAMP Moderate, Splunk Cloud Platform for FedRAMP High
CVECRITICAL
#FIRE-2D4C 08-21 00:20Z
CVE-2026-54117: Deserialization of untrusted data in SQL Server allows an unauthorized attacker
◈ Azure Commercial Cloud, Microsoft Office 365 GCC High +2 more
CVECRITICAL
#FIRE-987D 08-21 00:20Z
CVE-2026-17101: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary
◈ IBM Cloud for Government, IBM Federal HR Cloud +3 more
CVEHIGH
#FIRE-2F67 08-21 00:20Z
CVE-2026-61001: Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middle
◈ Aconex for Defense, Taleo Cloud - U.S. Government Cloud +8 more
CVECRITICAL
#FIRE-77C9 08-21 00:20Z
CVE-2026-61003: Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middl
◈ Oracle Service Cloud (DOD), Fusion Cloud +8 more
CVECRITICAL
#FIRE-312C 08-21 00:20Z
CVE-2026-61248: Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middlewa
◈ Oracle Enterprise Performance Management (EPM) - Moderate, Fusion Cloud +8 more
CVECRITICAL