Active exploitation alerts

Exploitation activity watchlist

High-signal exploitation patterns that should drive patching, logging, and incident triage.

Remote access infrastructure

Critical

Ivanti VPN appliances under active exploitation

Patch Ivanti appliances immediately, restrict external management access, and hunt for web shell indicators.

Reference documentation

Cloud identity and enterprise email

High

Credential phishing campaigns targeting Microsoft 365 tenants

Enforce phishing-resistant MFA, revoke suspicious sessions, and review risky sign-ins and OAuth app consent grants.

Reference documentation

Windows servers and enterprise endpoints

High

Ransomware affiliates exploiting exposed RDP services

Disable public RDP exposure, enforce VPN-only access, enable account lockout policies, and monitor brute-force activity.

Reference documentation

Perimeter security appliances

Critical

Active exploitation of edge firewall and gateway devices

Patch internet-facing devices, review administrative logins, rotate credentials, and validate firmware integrity.

Reference documentation

Corporate workstations and user credentials

High

Infostealer malware campaigns targeting browser credentials

Reset compromised credentials, enable endpoint detection, monitor browser credential theft alerts, and enforce MFA.

Reference documentation