ATLAS · LIVE
ATLAS INDEX
Δ 24H
ACTIVE SOURCES20
HOTSPOTS20
TIME21:12:54 UTC
The Atlas Intelligence Brief

Daily briefs from across the threat surface.

Curated from twenty intelligence-grade sources. Rewritten in the Atlas voice. One brief published every morning at 06:00 UTC.

AllCyberGeopoliticsPolicyInfrastructureFinancialHealthcare
Today's Lead Brief
HIGHGeopolitics14h ago

Four Landslides Kill Hundreds at Congo Coltan Mines Under M23 Control

Bellingcat verifies deadly mining accidents in DRC's Rubaya region, now held by Rwandan-backed armed group, raising supply chain questions for tech firms.

Source · BellingcatRead →
Recent Briefs
HIGHCyber1d ago

Multi-Year Phishing Campaign Compromises Over 500 Organizations

A sustained phishing operation has breached more than 500 entities across aviation, energy, logistics, and critical infrastructure over several years.

Source · SecurityWeekRead →
HIGHCyber2d ago

JDownloader site compromised to distribute Python RAT malware

Popular download manager's official website served malicious Windows and Linux installers this week, deploying remote access trojan to unsuspecting users.

Source · BleepingComputerRead →
CRITICALCyber3d ago

Linux zero-day grants root access across major distributions

Dirty Frag exploit enables local privilege escalation with a single command, affecting most enterprise Linux deployments currently in production.

Source · BleepingComputerRead →
HIGHCyber4d ago

Iranian intelligence operatives disguise espionage as ransomware attack

MuddyWater APT group deployed Chaos ransomware to mask intrusion tied to Iran's Ministry of Intelligence and Security, incident responders report.

Source · The RecordRead →
HIGHCyber5d ago

DAEMON Tools trojanized in supply chain breach, patched version released

Disc Soft confirms malware was inserted into its popular disc imaging software; users urged to update immediately to clean build.

Source · BleepingComputerRead →
CRITICALCyber6d ago

Palo Alto Networks Confirms Zero-Day Exploit in Firewall Software

CVE-2026-0300 targets the Captive Portal service in PAN-OS, affecting PA and VM series firewalls currently deployed in enterprise networks.

Source · SecurityWeekRead →
HIGHCyberMay 5

China-aligned group exploits Exchange, IIS flaws across Asian governments

Trend Micro tracks Shadow-Earth-053 campaign targeting defense and critical infrastructure sectors with known Microsoft vulnerabilities in ongoing espionage operation.

Source · Industrial CyberRead →
HIGHCyberMay 4

Dubai-Led Operation Arrests 276, Seizes $701M in Crypto Scam Crackdown

International task force dismantles nine fraud centers targeting U.S. investors, marking rare U.S.-China coordination on transnational cybercrime.

Source · The Hacker NewsRead →
CRITICALCyberMay 3

cPanel Vulnerability Exploited in Mass Ransomware Campaign

A newly disclosed critical flaw in cPanel is being actively exploited to breach websites and deploy 'Sorry' ransomware across multiple targets.

Source · BleepingComputerRead →
HIGHCyberMay 2

French authorities detain 15-year-old over state document agency breach

A teenager allegedly sold stolen data from France Titres, the agency managing national identity documents and driver's licenses.

Source · BleepingComputerRead →
CRITICALCyberMay 1

cPanel authentication bypass exploited in wild since February

Critical vulnerability CVE-2026-41940 in cPanel, WHM, and WP Squared is under active exploitation with public proof-of-concept code now available.

Source · BleepingComputerRead →
MODERATEPolicyApr 30

China May Have Quietly Cut Fentanyl Precursor Exports

U.S. overdose deaths fell sharply in 2024, possibly due to Beijing's enforcement—but neither side wants to claim credit publicly.

Source · Foreign AffairsRead →
MODERATECyberApr 29

Ransomware Groups Attack Each Other, Expose Infrastructure

0APT and KryBit leaked operational data during a mutual attack, handing defenders rare visibility into ransomware tradecraft and infrastructure.

Source · Dark ReadingRead →
HIGHCyberApr 28

Chinese National Extradited from Italy on Cyberespionage Charges

A suspected Silk Typhoon operative now faces U.S. prosecution for intelligence operations targeting American networks, marking a rare extradition in state-sponsored cyber cases.

Source · BleepingComputerRead →