Cybersecurity Hub
Rankings are based on sample mock data and do not represent production intelligence rankings. Scores combine CVSS, EPSS, exploit availability and KEV status where applicable.
Top CVEs by combined risk
Full databaseActive threat signals
Threat IntelligenceVoidLock Collective claims new healthcare victims
The ransomware group posted redacted claims against two mock healthcare organizations. Defensive teams should review VPN exposure and phishing controls.
Phantom Crane infrastructure shift detected
Analysts observed Phantom Crane moving C2 infrastructure to new cloud regions. The shift correlates with expanded targeting of telecom providers.
NeonStealer campaign targeting e-commerce payment flows
Phishing kits deploying NeonStealer have increased in volume. The stealer harvests browser credentials and payment data from e-commerce sessions.
SilkGate Broker advertising VPN access to healthcare networks
Mock initial access broker listing claims VPN access to three healthcare organizations. All details are redacted and fictional.
CVE-2026-21954 exploitation observed in ransomware chain
The Windows Kernel privilege escalation vulnerability is being incorporated into post-access ransomware deployment chains by mock threat operators.
Active ransomware groups
Ransomware trackerThreat actor highlights
Actor databaseUnder investigation — infrastructure overlap with multiple campaigns
Initial access brokerage — selling network access to ransomware affiliates
Espionage targeting defense and telecommunications sectors
Financial extortion through data encryption and leak threats