DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
CLASSIFIED // NEW HERE
DMZ surfaces threats hiding between the headlines.
We correlate signals across underground forums, security researcher posts on X, vendor disclosures, and CISA advisories — then publish what defenders actually need to know. No noise. No engagement bait. Just the threats that matter.
26 REPORTS TODAY

Why I'm Building DMZ

I served nine years in the Navy as an Aviation Boatswain's Mate before I ever touched a SIEM. A year into my first analyst role, I started building DMZ — the threat intel publication I wish existed when I was sitting at my desk a year ago,…

HIGH

VECT RaaS x BreachForums Partnership — Affiliate Keys Now Active for TeamPCP Victim Pool

We are formalizing our operational partnership with ███████. All 300,000 members of this forum are eligible for a personal affiliate key. ████████████. Together we are ready to deploy ransomware across all affected companies. We will chain…

Added to DMZ2026-08-02
READ →
MEDIUM

FATETRAFFIC 2070 MIX — Infostealer Log Dump [5,777 logs / 2,070 creds]

Releasing 5,777 individual infostealer logs harvested as recently as ████████████. Dataset contains 2,070 unique email/password combos. Distributed via ████████████. Mix includes browser-saved passwords, session cookies, and sensitive…

Added to DMZ2026-08-02
READ →
CRITICAL

SAPPHIRE SLEET

Amazon Web Services Threat Intelligence publicly attributed a sustained npm supply-chain campaign to Sapphire Sleet on July 29, 2026, connecting four previously unlinked package compromises — typo-crypto (Mar 2025), debug and chalk (Sep…

Added to DMZ2026-07-31
READ →
CRITICAL

KIMSUKY

ENKI WhiteHat published a full technical analysis on July 20, 2026, disclosing that Kimsuky spent nearly a year embedded inside at least two South Korean enterprise groupware vendors, deploying two previously unknown Linux backdoors —…

Added to DMZ2026-07-31
READ →