Skip to main content
Skip to main content
CRUCIBLE
back

TRACEPULSE

CVE and campaign-tied detection query packs — deploy as soon as a new CVE drops or campaign goes active. 10 query packs · 40 queries across KQL · Sigma · XQL · SPL

10 query packs · 40 queries across KQL · Sigma · XQL · SPL

CVE-2026-41940 — cPanel Harvester Toolkit

HIGH

Harvester toolkit targeting cPanel admin panels via unauthenticated API injection. Deploys web shell and exfiltrates hosting credentials.

CVE-2026-41940 2026-04-12
cPanelWHMApache httpdT1190T1505T1059

CVE-2026-41823 — Exchange RCE

CRITICAL

Pre-auth remote code execution in Exchange Server OWA component. Chained SSRF to deserialisation in ECP endpoint.

CVE-2026-41823 2026-02-18
Microsoft Exchange Server 2019Exchange OnlineT1190T1210T1505

CVE-2026-41290 — Log4Shell Variants

CRITICAL

New Log4Shell bypass variants targeting patched 2.17.1+ installations. JNDI LDAP injection via message lookup conversion pattern.

CVE-2026-41290 2026-01-05
Apache Log4j 2.xMultiple vendor appliancesT1190T1211T1068

LockBit 3.0 Ransomware — Active Campaign

HIGH

Active LockBit 3.0 campaign leveraging PsExec lateral movement and custom encryptor. Targets Windows + ESXi environments.

LockBit 3.0 Ransomware LockBit 2026-03-01
Windows ServerVMware ESXiSMB sharesT1486T1490T1047T1021

CLOP MOVEit Exploitation — Ongoing

CRITICAL

Ongoing CLOP ransomware exploitation of MOVEit Transfer SQLi vulnerability. Data exfiltration via HTTPS to known CLOP infrastructure.

CLOP MOVEit Exploitation TA-584 (CLOP) 2026-02-25
Progress MOVEit TransferMOVEit CloudT1190T1211T1489

APT29 — SolarWinds Post-Exploit

CRITICAL

APT29 post-compromise activity on SolarWinds Orion deployments. SAML token forging, Azure AD persistence, and mailbox exfiltration.

SolarWinds Post-Exploit APT29 (Cozy Bear) 2026-01-20
SolarWinds OrionMicrosoft 365Azure ADT1195T1550T1526T1098

BlackCat/ALPHV — Encryptor Deployment

HIGH

ALPHV ransomware encryptor deployment via Rust-based binary. Uses intermittent encryption for speed and AppLocker bypass.

BlackCat/ALPHV Ransomware ALPHV (BlackCat) 2026-03-30
WindowsLinuxVMware ESXiNAS appliancesT1486T1059T1047T1021

Lazarus — Crypto Bridge Heists

HIGH

Lazarus targeting cryptocurrency bridge smart contracts. Social engineering of developers followed by malicious npm packages for persistent access.

Crypto Bridge Heists Lazarus Group (HIDDEN COBRA) 2026-04-05
Web3 bridge contractsNode.jsLinux serversT1190T1204T1059T1071

Scattered Spider — SaaS TTPs

MEDIUM

Scattered Spider social-engineering campaigns targeting SaaS help desks. SIM swapping, MFA fatigue, and impersonation of IT staff.

Scattered Spider SaaS Attacks Scattered Spider (UNC3944) 2026-03-15
OktaMicrosoft 365AWSSalesforceSlackT1078T1556T1528T1566

CVE-2026-40123 — CitrixBleed

CRITICAL

Citrix ADC/Gateway buffer overflow allowing unauthenticated RCE. Mass exploitation by multiple ransomware groups for initial access.

CVE-2026-40123 2026-02-01
Citrix ADCCitrix GatewayNetScalerT1190T1211T1021
crucible·
github·portfolio