THREAT INTELLIGENCE
Regional threat dashboard
Aggregated from client telemetry, honeynet sensors across the GCC, dark-web collection and partner feeds.
Threat level: elevated
AS OF 2026-09-06 19:03 UTC · SENSOR HEALTH 99.94%
THE FIGURES ON THIS PAGE ARE ILLUSTRATIVE PLACEHOLDERS FROM THE DESIGN, NOT LIVE TELEMETRY. THEY ARE SERVED FROM A STORED SNAPSHOT AND ARE NOT UPDATED IN REAL TIME. THIS NOTICE DISAPPEARS AUTOMATICALLY ONCE A REAL SOURCE IS WIRED TO THE SCHEDULED JOB.
EVENTS ANALYSED / 24H
41.6 B
▲ 4.2% vs 7-day avg
THREATS BLOCKED
2.31 M
▲ 11.8%
CRITICAL INCIDENTS
7
▼ 2 vs yesterday
NEW IOCS PUBLISHED
148
▲ 31
CREDENTIALS LEAKED
9,412
▲ 1,208
MEAN TIME TO CONTAIN
4.2 m
▼ 18 s
Detections per hour
LAST 24 H
00:0006:0012:0018:0023:00
Severity distribution
- Critical
- 0.4% · 7
- High
- 6.1% · 312
- Medium
- 28.3% · 1,441
- Informational
- 65.2% · 3,318
Active campaigns tracked
ATTRIBUTION CONFIDENCE PER INTERNAL SCORING| CAMPAIGN | ATTRIBUTED ACTOR | PRIMARY TARGETS | KEY TTP | SEVERITY | CONFIDENCE |
|---|---|---|---|---|---|
| SANDSTORM LEDGER | Financially motivated, unattributed | GCC retail banking | T1566.002 | CRITICAL | High · 0.88 |
| QUIET HARBOUR | Suspected state-aligned | Port & logistics OT | T1190 | CRITICAL | Moderate · 0.64 |
| BRASS TULIP | Initial-access broker cluster | Professional services | T1078 | HIGH | High · 0.91 |
| PALE MERIDIAN | Ransomware affiliate | Healthcare networks | T1486 | HIGH | High · 0.86 |
| COPPER ORBIT | Hacktivist collective | Government portals | T1498 | MEDIUM | Moderate · 0.58 |
| DRY SEASON | Commodity crimeware | SMB, mixed sectors | T1204 | MEDIUM | High · 0.93 |
| LOW TIDE | Unknown | Energy sector recon | T1595 | LOW | Low · 0.41 |
Top malware families — 7 day
- AsyncRAT
- 1,204
- Lumma Stealer
- 986
- Qakbot variant
- 731
- AgentTesla
- 612
- Cobalt Strike beacon
- 419
- XWorm
- 288
Most exploited CVEs
- CVE-2026-1188 · edge VPN
- CVSS 9.8
- CVE-2025-9042 · file transfer
- CVSS 9.4
- CVE-2026-0431 · hypervisor
- CVSS 8.8
- CVE-2025-7761 · web CMS
- CVSS 8.6
- CVE-2026-2210 · mail gateway
- CVSS 8.1
- CVE-2025-5509 · print spooler
- CVSS 7.8
Phishing lure themes
- Payroll / salary revision
- 24%
- Shared document notice
- 19%
- Delivery / customs fee
- 16%
- MFA re-enrolment
- 14%
- Invoice overdue
- 12%
- HR policy acknowledgement
- 9%
Find out what your telemetry is already telling you.
Two-week assessment: we ingest your existing logs, run the Sentinel detection pack, and hand back a prioritised findings report. No agents, no commitment.